A security release fixes denial-of-service vulnerabilities in peer-to-peer and JSON-RPC handlers that become exploitable after Amsterdam activates on mainnet, correcting opcode caching and account handling.
A formal assurance framework for smart contracts uses multiple proof and testing tools together to catch mutations and regressions in deployed bytecode.
A draft extension adds post-quantum cryptography to Ethereum's stealth address standard, protecting private key recovery against future quantum attacks.
Research on rational concurrent proposers models how much sybil attacks cost to censor transactions in protocols with multiple block builders.
The Ethereum Foundation released a privacy tool that lets users prepay for APIs and APIs, then spend via zero-knowledge proofs so usage cannot be tied back to them.
More: openanonymity.ai · The Block · ETH Daily · Unchained · Bankless · The Defiant · Decrypt
Japanese banks gain a private blockchain infrastructure for issuing, settling, and tokenizing digital assets on zkSync, expanding institutional adoption in Asia.
More: The Defiant
The Security Alliance Radar tracked incident trends and losses across threat categories over the past week.
A misconfigured deposit-token whitelist allowed redemptions that emptied a vault, draining liquidity and moving assets back to mainnet.
Spark activates segregated savings vaults for spUSDC across two networks as part of its institutional stablecoin infrastructure expansion.
MetaMask's staking service withdrew validators from Lido following a security incident at its infrastructure provider, but users' wallets and funds remain unaffected.
More: Lido Research · The Defiant · Decrypt · The Defiant · Lido
The self-custodial privacy wallet hides transactions on Aztec Network while deposits from Ethereum remain visible, restoring privacy tooling for the ecosystem.
More: CoinDesk · The Block · @zk_money on X · Unchained · ETH Daily
Teams can test private balances and transfers on Safe accounts with Bermuda, a Gnosis-backed compliant privacy solution in early access.
More: Safe
Ethereum's consensus client Lighthouse released a medium-priority security patch affecting all mainnet validators, underscoring ongoing vigilance in client stability.
FOCIL is a proposed Ethereum change meant to stop block builders from censoring transactions, and this call found client teams close to a first test network but missing a piece of data validators need.
More: Ethereum Magicians
A Polygon zkEVM proving system patch addresses soundness vulnerabilities in BLAKE2, BLAKE3, and JumpDest logic that could affect proof validity.
Earlier on CROPS
October 2026 · 1 story
September 2026 · 35 stories
- SEAL warns of Gmail compromise and fake support call social engineering pattern
- SEAL logs 67 incidents and higher losses in a week, seed phrase theft and bridge exploits lead
- Fake GIWA Layer 2 bridge drained of 766 ETH, DYORSWAP reimbursement offer 40%
- Payy bridge drained $1.92M in two withdrawals to same address, no key compromise
- Magic Eden legacy approvals expose $5.7M in NFTs to exploit, whitehat rescues 23,155 tokens
- Bitget resumes Bitcoin withdrawals as hacker swaps stolen ether via THORChain
world ·
15d ago · 6 sources
- Kelp DAO sues LayerZero and CEO over $292M rsETH bridge exploit
- Ethereum's TCB Part 1 explores formal verification for client security
- Aave Stable Vaults architecture guide published by community researcher
- LambdaClass PropAMM Router ships audited mainnet version after Least Authority review
- SEAL logs 62 incidents and $18.3M lost in a week, seed phrase theft remains largest attack vector
- Etheorem executable consensus specs in Lean 4 pass all pyspec vectors
- Gateway.fm AS post-mortem: two August incidents, no slashing or stake risk
- Encrypted Mempools via Threshold IBE without batch decryption proposed
- OpenVM v2.1.0-rc.1 updates certified verifier to Lean4 v4.34.0
- Flashbots Priority Update Registry V1 critical vulnerability, storage aliasing lets unauthorized price publishes
- SEAL logs 61 security incidents and $18.1M lost in a week, with seed phrase compromises the largest category at $9.4M
- rsETH drained from Safe via over-permissioned module, bot front-runs attacker for $7.8 million
- 0x flags 54% of analyzed Uniswap v4 hooks as malicious, disputes hook safety model
- FOCIL Breakout #42: devnet-0 needs 2 EL and 2 CL clients, EIP-8369 sets two VOPS eligibility profiles
- Zama launches confidential Morpho vaults on Ethereum, first vault exceeds $40 million
- EU cyber rules mandate 24-hour vulnerability reporting for wallet providers, up to 17.3M euro fines
- SizzLean: Lean 4 SSZ library with formal verification of codec correctness
- EIP-8182 (Private ETH and ERC-20 Transfers) Declined for Hegota
- EIP-8288 proposes mempool redesign to cheapen quantum-safe signatures and private transactions
- FOCIL Breakout #42 scheduled for September 15, agenda posted
- Ethrex testnet ships frame transactions and keyed nonces for privacy
- Ethereum Foundation targets 2029 quantum resistance deadline, narrows Hegotá to FOCIL and Frame Transactions
- Formal verification scope expands from contracts to ERC standard implementations
- Ethereal weekly #38: Sepolia Glamsterdam targeting October 6, Privacy Boost V2 live, BuidlGuidl Ethereum 101
general · 36d ago
- Curve DAO appoints yRisk as risk manager for crvUSD with 536.9M votes
- Sky Governance Portal vote-tally amplification flaw patched after June bounty report
- Eth R&D forum discussion proposes formal verification requirement for client hard fork upgrades
- Polygon Open Money Stack passes SOC 2 Type 1 audit
- Flashbots research examines client disruption prevention in anonymous broadcast protocols
August 2026 · 47 stories
- Balancer warns V1 LPs of pool-draining bug, $234k drained via fixed-point rounding flaw
- FOCIL Breakout #41 scheduled for September 1, agenda posted
- Tacet encrypted mempool prototype for OP Stack seeks community feedback
- Homomorphic tally research specifies proof boundaries for token-weighted voting
- Moonwell lending market on Base suffers $8.7 million exploit via MAMO collateral manipulation
- Flashbots hosts MEV research talks at Science of Blockchain Conference
- Tornado Cash developer Roman Storm's retrial scheduled for April 2027
world ·
45d ago · 2 sources
- Polygon ships Private Mempool to hide transactions from MEV until confirmation
- Arbitrum DAO roundup, August 24: security program evolution, voting snapshot
- Term Finance suffers $8.5 million governance exploit despite veto controls
apps ·
47d ago · 3 sources
- ZeroStyl final report ships privacy toolkit for Arbitrum Stylus smart contracts
- EIP-8387 proposes stateless accounts to enable privacy flows
- Technical Scope for Sky Parallelized Allocation System module published
- Vitalik Buterin publishes Obfuscation Part III on local mixing for privacy
- Ethereal weekly #36: Glamsterdam upgrade proposed for public testnet in September-October, focil-devnet-0 targets August 31
general · 50d ago
- Ethereum Foundation launches better.codes autoresearch challenge for hash-based SNARK soundness
- ENS Governor Nexus governance implementation shipped and open for audit feedback
- Independent verification review of Arbitrum checks 17 onchain metrics
- Revoke.cash grant milestone shipped, History tab tracks approval-triggered transfers
- ZisK v1.1.0-alpha released for security and correctness audits
- Ethereum Foundation Q2 2026 allocation update supports ZK proofs, client diversity, formal verification
- Hegotá priorities ranked from 66 EIPs, censorship resistance and account abstraction lead
- Ethereum developers target privacy changes in Hegota upgrade, enabling fee payment from privacy pools
- [ARFC] Sunset the Aptos Bug Bounty program and Cantina as a provider
- FOCIL Breakout #39 agenda posted, call August 18 to discuss development and spec updates
- ERC draft proposes private NFT-to-NFT reference commitments
- DMQ Framework deploys on-chain penalty execution for MEV attack mitigation on Sepolia
- Arbitrum Security Program continues with 12-month rolling audit and oversight evolution
- ENS publishes RFC for stealth address resolution via privacy-preserving names
- EVM gas accounting and censorship resistance in EIP-7999 multidimensional fee market
- Panetière anonymous broadcast protocol draft posted by Flashbots
- Aave V3 security program expands to AI-assisted reviews alongside manual audits and contests
- TDX Security Update 2026.08.11: Flashbots assesses Intel vulnerabilities
- ACDC #185 agenda posted, call August 20 to discuss Glamsterdam and Hegotá upgrades
- Arbitrum DAO governance roundup, August 11: Security Council election process improvements and proposals
- Zama privacy token listed on Revolut for 70 million EEA users
- Vitalik Buterin prioritizes privacy and quantum resistance in Ethereum roadmap refresh
- Aztec V5 Alpha proving system vulnerability identified and fixed for V6
- Ethereal weekly #34: EIP-8363 issuance burns, Dark Forest Aztec, MetaMask Agent Wallet
general · 64d ago
- EIP-8369 VOPS Profiles for FOCIL Eligibility posted
- ERC-8366 Zero-Knowledge Spending Policies standard proposed
- Dark Forest Aztec game launches with private gameplay on Aztec
- Optimism forum discusses DAO governance vulnerabilities and treasury security
- Arcanum privacy-first compiler layer proposed for source code protection
- Encrypt The Mempool #8 agenda posted, call August 12
- FOCIL Breakout #39 agenda posted, call August 4
- Arbitrum DAO August 3 roundup: Security Council election updates and active votes
July 2026 · 34 stories