Glamsterdam upgrade on Sepolia testnet October 6, Vitalik: the cryptographic world computer, Hegotá upgrade focil-devnet-0 live
Ecosystem
- 🐻❄️ Glamsterdam upgrade on Sepolia testnet activates October 6, 13:53:36 UTC
- Glamsterdam security vulnerabilities (specs, EIPs & specific client releases) in scope for bug bounty program
- Vitalik: transforming Ethereum into the cryptographic world computer by 2030 using recursive STARKs, automated formal verification, optimized consensus algorithms & quantum safe cryptography
- Ethlabs: Chainlink CCIP 2.0 integrated fast confirmation rule, transactions confirmed in 12-24 seconds rather than 13 minutes
- Ethereum Foundation:
- Will Corcoran Protocol cluster monthly update: Glamsterdam upgrade (faster benchmarking, devnets, testnets & security), Hegotá upgrade (headliner devnets) and research (post quantum roadmap, fast block propagation & autoresearch)
- Yukon sig.golf: autoresearch challenge for stateless hash based post quantum signatures, reduce signature bytes x verification cycles
- ETHGlobal Tokyo hackathon finalists from 254 projects
- ETHTaipei videos
- ETH metrics:
- Gas (gwei): 0.6 average, 0 - 14.5 (13.5 for zero net issuance)
- ETH supply: 122.1M, 20k net issuance
- ETHUSD: $2,637 - $2,768 (all time high $4,946, August 24, 2025)
- ETHBTC: 0.032 (0.165 for the Flippening)
Sponsor: MetaMask
Understanding Basic Functionality in MetaMask
We’re always working to make your wallet more secure and easier to use, while giving you control over your privacy and data. As part of that, we’re bringing MetaMask’s profile and privacy settings together under one unified setting, Basic Functionality, so every user can benefit from the best security protections by default.
Basic Functionality in MetaMask
Enterprise
- Open Standard Open USD (OUSD consortium stablecoin) live, includes mainnet & Base
- Citi x Coinbase: Coinbase Virtual Accounts will automatically convert fiat to stablecoins & Spring by Citi enables stablecoin payments at checkout (converted to fiat)
- Baillie Gifford enhanced yield fund (BAGEY): native UK regulated tokenized fund, token is investor holding (not a wrapper), open for investment
Applications
- Aave: Coinbase tokenized stocks live on V4, not available in US
- EF x Open Anonymity Project zkAPI: private usage credits for paid APIs, live on mainnet
- zk.money on Aztec Network, send/receive privately, reserve/buy tag (ENS name)
- Fairblock confidential USD (CUSD) live on Arbitrum, built on PYUSDx
- Balancer winding down, pools withdrawal only from October 30
- Chainlink CCIP 2.0 live, adds user attestations, additive security, built in compliance functionality & configurable finality speeds
- Stuckfunds: check address for unclaimed bridge withdrawals
- Punk to bricks: generate instructions & parts list to build Lego bust of CryptoPunk
Developers
- Argot Collective Fe 26.4 (language): experimental native executables, access Solidity storage layouts, helpers for external calls & tokens, deterministic deployment, full precision arithmetic, Merkle proof support and text formatting
- Foundry (dev framework):
- Foundry v1.8.4: script recovery, native Base support, VS Code & Zed language server clients, external compiler adapter support and expanded block access list support
- forge-std v1.17.0 (helpers): adds secp256k1 helpers, expanded cheatcode interface, state gas reporting, more reliable stdStorage & load chain config without RPC
- Remix v2.6.4 (IDE): adds x402 endpoints to select a Solodit security checklist & run a review, QuickDapp multi contract support and transaction history with replay
- Nethereum 7.0.0 (.NET SDK & node toolkit): unified EVM engine (node, simulation & zkVM guest) with Glamsterdam support, DevP2P networking with snap sync, beacon light client and account abstraction adds passkeys, social recovery & in process bundler
- L2Beat privacy treasure hunt: trace funds sent via privacy protocols back to source, solutions revealed next week
- Application layer standards (ERCs):
Security
- Payy exploit postmortem, ~$1.9M unauthorized withdrawals, invalid burn proof accepted by deployed verifier
- Cantina Security Apex Flash-1: open weights model for security research, reinforcement learning fine tune of GLM-5.3-Flash
- Arbitrum security program: projects building on Arbitrum can apply for subsidized security review
All core devs (main protocol calls)
All core devs - consensus (ACDC) #188
- Hegotá upgrade (targeting 2027):
- Non headliner scoping used EIPs by average client rating
- 2 EIPs Considered for Inclusion (CFI):
- EIP8365 disallow new 0x00 validators
- EIP8198 quick slots, Barnabé Monnot (Ethlabs) presentation, post quantum impact & testing concerns
- 2 EIPs Withdrawn:
- 1 EIP Declined for Inclusion (DFI):
- EIP8379 top up sync
All core devs - testing (ACDT) #98 + consensus layer breakout
- Glamsterdam upgrade (targeting 2026):
- Maria Inês Silva (EF): 200M gas limit deemed safe on execution time
- Fast confirmation rule (FCR): new confirmed block tag requested rather than reusing safe tag
Layer 1
- Glamsterdam upgrade (targeting 2026):
- Sepolia testnet shadow fork live
- Chase Wright (EF): ENRScout (crawler) Sepolia testnet readiness
- Feel Your Protocol: EIP2780 resource based intrinsic transaction gas interactive explainer
- Hegotá upgrade (targeting 2027):
- EIP8363 tapered issuance burn withdrawn, needs dedicated process for broad consensus on issuance policy, forums/workshops proposed
- focil-devnet-0 live
- FOCIL breakout #43
- I* upgrade (targeting 2027/2028):
- Francesco (Ethlabs) proposal for decoupled consensus formally verified
- banteg trace-interop: tests & compatibility reports for standardizing trace APIs
- Daisugi 0.2 (post quantum testnet): adds Frame transaction support
- Ethereum improvement proposals (EIPs):
Staking
- MetaMask investigating security incident affecting part of their infrastructure, exiting affected validators as a precaution, no indication so far that MetaMask wallets or customer funds affected
- Client diversity:
- Consensus layer: Lighthouse ~53% (data may not be accurate)
- Staking market share: Lido 21.9% [Note: dual governance]
- Validators: 876k active (target 128k), 23k accumulating (0x02 withdrawal credentials)
- beaconcha.in consolidations dashboard: adds staking provider leaderboard
- Client releases:
- Consensus layer:
- ChainSafe Lodestar v1.49.0 (recommended): Glamsterdam on Sepolia, deduplicates archived execution payloads by default
- Consensys Teku 26.9.1 (recommended): Glamsterdam on Sepolia, default 60M gas limit
- Grandine 3.0.0-rc.0 (testnet only): Glamsterdam on Sepolia
- Offchain Prysm v7.2.0: Glamsterdam on Sepolia, default 60M gas limit
- Sigma Prime Lighthouse v8.2.3 (medium): security fixes; Lighthouse v8.3.0-rc.0: Glamsterdam on Sepolia
- Status Nimbus v26.9.0 (medium): Glamsterdam on Sepolia; Nimbus v26.9.1 (medium): validator client allows mixed beacon node configurations
- Execution layer:
- Besu 26.9.0 (upgrade promptly): security fixes, Glamsterdam on Sepolia, exits on out of memory
- Erigon v3.7.1 (recommended): Caplin ready for Glamsterdam on Sepolia & fixes
- EF Geth v1.17.7: Ubuntu PPA publishing fix, choose history pruning point
- Lambda ethrex v28.0.0: Glamsterdam on Sepolia, adds EIP8189 snap/2
- Nethermind v2.1.0 (required for Sepolia): Glamsterdam on Sepolia
- Paradigm Reth v2.7.0: Glamsterdam on Sepolia & fixes
- Consensus layer:
Research
- George Kadianakis & Kev Wedderburn (EF): trusted computing base of a client, options for end to end formal verification
Layer 2
- Base Cobalt upgrade live, adds validity transactions (valid when user specified criteria met) & B20 token enhancements (combine allow/block lists, schedule multiplier updates & seize with onchain memo)
- GIWA Chain mainnet not launched yet, 766 ETH stolen via fake RPC & bridge
Regulation
- US SEC:
- Crypto custody rules for investment advisers & funds proposal
- Staff crypto FAQs: liquid staking tokens may be commodities, token buybacks not investment contract where system is functional with no central party
- Hester Peirce resigned as commissioner
General
- Vitalik finished writing Snowmoon, decentralized governance scifi
- Security Alliance (SEAL) Intel: social engineering attacks via fake Google support call to compromise inbox, then fake wallet/exchange email & call to steal crypto
Editor: @abcoathup
Permalink: ethereal.news/ethereal-news-weekly-41/
Markdown: ethereal.news/ethereal-news-weekly-41.md