GM, frens! ☕️

Here’s what we’re getting into this week:

  • 🐶 Dogecoin: 13 year path to reach DeFi

    • After nearly 13 years as a simple payment coin, Dogecoin now has an EVM compatible testnet for trading, lending and stablecoins, though its promised miner security remains only a proposal [here]

  • 🌎 Ethereum 2030: What it could look like

    • Vitalik’s 2030 vision turns Ethereum from a network that repeats every calculation into one that verifies proofs, protects more user data and spreads work across many computers, with Glamsterdam preparing the first practical pieces now [here]

  • 🔥 Ambire Mobil is here

    • Ambire Mobile returns to iOS and Android with the extension’s full feature set, plus an exclusive invite code for W3oF readers 👀 [here]

  • 🦊 What happened with MetaMask validators

    • An attacker redirected just 0.36 ETH in tips, but the breach forced MetaMask Staking to exit nearly 17,000 validators holding roughly $1.5 billion because the signing environment could no longer be trusted [here]

  • 🤓 Tokenized stocks get compliance built into Base

    • Base’s Cobalt upgrade adds conditional transactions and compliance tools for tokenized assets, including combined KYC checks, stock split support and issuer controlled transfers [here]

Plus:

  • Other worthy reads: good reads from elsewhere in crypto that deserve a spot this week

  • Memes: OC shitposts and stuff we came across this week 😶

Happy Uptober! Or at least happy October while we wait to see if it actually earns the name. The space has taught us not to celebrate too early, but hoping for a good month is still free 🙃

Do you enjoy reading Web3 On Fire every Friday? You know someone else who would like to get their weekly dose of crypto news and analysis straight to their inbox?

Dogecoin: 13 year path to reach DeFi

Dogecoin was originally built for one simple job. You buy it, send it around or receive it - with the whole point being going around starting discussions whether a meme can become “real money”.

That limited design never stopped DOGE from becoming one of the largest assets in the industry.

It did mean that most of the interesting activity happened somewhere else. Holders could deposit DOGE into an exchange or hand it to a custodian, but the Dogecoin network itself had no lending markets, stablecoins or smart contract apps 🪙

Almost 13 years after Dogecoin launched, somebody is finally trying to change that 👇

DogeOS opened its Chikyū public testnet on September 30. It gives devs an EVM compatible environment where they can build Ethereum style applications and use test DOGE to pay transaction fees.

  • The first batch includes Barkswap for trading, Superposition Finance for lending, Derps for perpetuals and USDoge as a crypto backed stablecoin. There are also prediction markets, launchpads, games and consumer apps being built around it. According to rumors, at least 🤔

  • DogeOS comes from the team behind the MyDoge wallet, which gives it a possible route toward actual Dogecoin users if these apps survive the testnet stage.

  • Underneath, Dogecoin itself remains the same simple payment network. DogeOS runs as a separate zero knowledge rollup, processes its applications away from Dogecoin and then produces proofs showing that the work followed the rules.

The important detail is who checks those proofs.

  • Right now, DogeOS depends on selected validators, protected hardware, a permissioned sequencer and a Security Council. Dogecoin miners do not secure its DeFi apps yet. Users would still be trusting a separate group to order transactions and keep the system working 🤐

  • The longer term plan is to add a new Dogecoin rule called OP_CHECKZKP. It would let Dogecoin nodes verify zero knowledge proofs directly, allowing DogeOS to settle its work back to the original network without relying entirely on selected operators.

  • That proposal has been public since July 2025, but it remains a draft. The implementation is unfinished and Dogecoin Core has not accepted it. Until that changes, talk about Dogecoin miners securing DeFi should be read as the destination rather than the current product 👷

DogeOS has not announced a mainnet date either. For now, people can build, test and find out whether Dogecoin holders actually want to do anything with their coins beyond keeping them in a wallet and waiting for the price to go up.

That brings up the obvious question: does every chain and every coin need its own DeFi market? 🤷‍♂

Probably not. Plenty of chains already have lending protocols and exchanges that barely anybody uses. Copying the same five applications onto another network does not create demand by itself, and Dogecoin does not become more useful merely because somebody deployed a swap button beside it.

Still, this is a better direction than building another exchange or another custodial app. DogeOS at least gives devs a place to try ideas around an asset with a huge community, pretty large liquidity and millions of holders 🐶

Some of those ideas will be pointless. Others will fail because nobody turns up. That is fine. DeFi is one large marketplace of ideas too, and the market is perfectly capable of deciding which ones deserve to survive.

Dogecoin does not need lending markets to remain Dogecoin. But if people want to see what else DOGE can do, an open environment where anyone can build is a much better answer than telling them to deposit everything into another company’s account. Definitely.

Ethereum 2030: What it could look like

Four years from now, using Ethereum may feel very different even if the wallet address still looks the same.

A wallet could check balances without telling an outside server which accounts its owner is watching. A business could use Ethereum without exposing every payment, balance and internal account rule. Large applications could process thousands of actions across different computers, then send Ethereum a compact proof showing that everything was done correctly ✔

Users would not need to trust those computers. They would verify the proof 🥸

That’s what Ethereum Vitalik Buterin described in his latest vision for 2030. He calls it a “cryptographic world computer” although by his own admission it may barely resemble what people currently think of as a blockchain 👓

  • Ethereum currently works by making validators across the network repeat the calculations behind transactions. If somebody swaps tokens, borrows money or interacts with an application, every node checking the chain performs much of the same work again 🤖

  • That repetition makes Ethereum difficult to cheat. It also limits how much work the network can handle. Adding more ‘computers’ does not create a matching increase in capacity when all of them are busy repeating the same calculations.

1: Ethereum in 2030 would work differently

  • One validator could perform a large amount of work and produce a mathematical proof showing that it followed the rules. Other computers could check that proof much faster than they could repeat the original calculation 🤫

  • Instead of every node doing everything, different parts of the network could handle different tasks at the same time. Ethereum would then verify their work and settle anything where the order matters, such as two transactions trying to spend the same funds.

The base network becomes less of a computer doing every job itself and more of a judge checking that everybody else did their jobs correctly.

  • That would also change how apps themselves are built. Devs would be rewarded for separating work into pieces that can be processed and verified in parallel. Only the information needed for ordering or changing shared state would have to reach the final block. Everything else could be calculated, combined and proven beforehand 💻

  • Vitalik expects this to make decentralization useful for performance rather than treating it only as the cost of security. Thousands of computers could store different pieces of data or process separate parts of an application, while cryptographic proofs keep them honest 🔒

Ethereum already began heading in this direction with layer 2 networks and PeerDAS. The 2030 version would take the same idea much further by placing proof verification, parallel computation and privacy much deeper inside Ethereum itself 👇

Privacy would no longer be limited to hiding the amount sent in a payment.

  • Wallets currently depend on outside services to look up balances and transaction history. The service answering those requests can see which addresses somebody is interested in, even if it does not know who owns them.

  • The future system Vitalik describes could hide those requests as well. A person could check an account without revealing the address to the server supplying the data. Wallet permissions and the rules used to approve transactions could also remain private 👛

The network itself would also change.

  • Block production would involve several participants rather than one party controlling the entire process. Proof of stake would become more efficient. Nodes would verify zero knowledge proofs and sample available data instead of downloading and repeating everything.

  • Further ahead, Ethereum is expected to use recursive STARKs, automated formal verification and cryptography designed to survive future quantum computers. Vitalik has described the Lean Ethereum plan as a rebuild comparable in scale to the Merge, arriving through several upgrades rather than one giant event 📚

2: The first steps are much closer than 2030

Glamsterdam is scheduled to activate on the Sepolia testnet on October 6. Mainnet is expected during the final quarter of 2026, although devs have not confirmed the date ⏰

Its two main features begin preparing Ethereum for the kind of parallel work that Vitalik describes:

  • The first is built in proposer and builder separation. Ethereum already separates the validator proposing a block from the specialist builder assembling its contents, but the exchange between them still depends heavily on outside relays. Glamsterdam brings that process into Ethereum’s own rules. It reduces reliance on those middlemen and gives validators more time to check the execution part of a block ♻

  • The second feature is block level access lists. These lists show which accounts and storage locations a block will touch before clients begin processing it.

  • It’s somewhat like giving Ethereum a map of the work before the work starts. Clients can prepare the correct data and process more transactions in parallel instead of discovering each dependency one step at a time.

Glamsterdam also changes gas costs to better reflect the real cost of creating and accessing Ethereum’s growing state. Some older contracts use fixed assumptions about how much gas certain actions require. Those contracts may need updates before the upgrade reaches mainnet ⛽

The next major upgrade is Hegota, now expected in 2027. Vitalik thinks it may be Ethereum’s final “normal” fork, meaning the last upgrade whose technology would still look familiar to somebody working on Ethereum a decade ago 📆

  • Everything after Hegota becomes much more ambitious. That is where proofs, automated verification, improved consensus and protection against quantum attacks become the main story rather than distant research.

3: Not every proposal will survive the trip

EIP 8363 would have burned a growing portion of validator rewards as more ETH became staked. Once roughly half the supply was staked, validators would receive no net issuance reward 🧨

The proposal was removed from consideration for Hegota after criticism over its economic effects and the short amount of time given for such a large monetary change. It remains a draft and could return later, but it is not part of the upgrade 🤔

The fact that there’s debates surrounding these features is a good reminder that Ethereum 2030 is not a finished plan waiting to be installed, but rather a direction. There’s definitely plenty of challenges remaining 🫠

The network could become more complicated internally even as it becomes easier to use. Most people will never know whether their transaction was processed through a recursive proof, several offchain computers or a parallel mempool. And they probably should not need to know, if you think about it 🤨

By 2030, fast and cheap transactions will probably not be special. Every serious network will offer them. Instead, Ethereum is betting that the harder thing to copy will be a neutral place where many different systems can prove their work and settle together without one company controlling the result. And that’s a much stronger future than simply trying to win another speed race 🐌

Ambire Mobile V2 is here

Ambire Mobile V1 was already a great wallet, but the devs eventually turned most of their attention toward building the browser extension. Mobile users carried on asking when it would return with everything Ambire had added since 📱

Good news: it’s back 🔥

Ambire Mobile is now available on iOS and Android, bringing the extension’s full wallet setup to phones. Users can manage their portfolio and DeFi positions, swap and bridge tokens, use Safe multisigs, connect hardware wallets and pay gas through the Ambire Gas Tank ⛽

Existing users can transfer their accounts between the extension and mobile app by scanning an encrypted animated QR code. The information travels directly between the devices without going through a server or cloud backup.

Mobile V2 also includes transaction simulation and clear signing, warnings for suspicious contracts and first time recipients, custom RPC support and separate privacy controls for third party services. The built in browser comes with more than 500 verified apps, while Ledger, Trezor, Keystone, Keycard and imToken hardware wallets are supported through Bluetooth, USB, NFC or animated QR depending on the device 🔒

The Gas Tank works across supported EVM networks and can be topped up with more than 100 tokens. EIP 7702 support also lets users batch several actions and sign once without replacing their existing address.

Access is currently rolling out through invite codes, but W3oF readers have an exclusive one. Enter gmweb3onfire during onboarding to get inside 🤝

What happened with MetaMask validators

Security incidents are often judged by how much money disappeared. But that sometimes can hide the more important questions.

MetaMask disclosed on September 30 that somebody had compromised part of its infrastructure. Its first statement offered little beyond saying that MetaMask wallets faced no immediate threat and that an investigation was underway 🤯

The affected operation was MetaMask Staking, previously known as Consensys Staking, rather than the browser wallet itself. It runs Ethereum validators for Lido, MetaMask’s pooled staking service and other clients 👇

  • MetaMask began exiting validators as a precaution. An onchain investigation by Bitquery counted 16,965 validators that had already exited or entered the queue by the morning of October 1. Together, they held 565,056 ETH worth roughly $1.5 billion at the time. Around 7,191 of those validators were operated for Lido 💰

  • Ethereum validators have separate withdrawal addresses. MetaMask operated the machines and held the signing keys, but the underlying stake could only return to addresses selected by its owners. For Lido validators, that destination is a Lido contract 🔑

The attacker instead reached another part of the setup: the address receiving tips whenever one of MetaMask’s validators produced a block 📦

Bitquery found that 18 blocks sent their tips to an attacker controlled wallet on September 30. The total theft was just 0.36 ETH, worth less than $1,000. The wallet had received its initial funding through Tornado Cash earlier that morning 🥷

The amount was miniscule, of course, but the access behind it is more important 🫥

A validator signs a message telling block builders where to send its tips. Somebody inside MetaMask’s setup either got the validator keys to sign a new address or changed the configuration on the machines responsible for signing those messages ✏

The attacker’s wallet was funded at 10:27 UTC. MetaMask’s first validator exit appeared 19 minutes later. The first diverted block arrived another 85 minutes after the exits had begun.

  • That order suggests MetaMask already knew something was wrong and had started pulling validators out before the attacker successfully redirected any tips. It also means the attacker was still able to interfere with block payments while the emergency response was underway.

  • The overall danger involved the signing keys. An attacker who controls them can make validators sign conflicting messages and trigger slashing 🤏

  • Bitquery calculated that a simultaneous slashing event across the full set could have burned around 22,000 ETH. Nothing close to that happened and no validators were slashed, but the possibility explains why MetaMask could not simply repair a setting and carry on 🤷‍♂

Validator signing keys cannot be rotated. Once there is a serious chance that they have been exposed, the safe response is to exit the validators, withdraw the ETH and create new ones with new keys.

That process takes time. Lido expects the final affected MetaMask validators to complete their exits by October 7. Returning the ETH and staking it again could take up to 45 days because of Ethereum’s queues. The validators will miss rewards during that period 🪙

But that doesn’t clear MM.

Its public updates still do not explain how the attacker entered the infrastructure, whether signing keys were copied or which internal systems were compromised. Saying that wallets were unaffected is good and all, but it does not answer what happened inside a staking business responsible for more than half a million ETH 🤪

And yes the stolen amount makes this incident look almost harmless. But it was not - somebody gained enough control to redirect validator earnings and make thousands of signing keys impossible to trust.

Tokenized stocks get compliance built into Base

Putting traditional assets onchain has always sounded easier than it really is. Creating a token takes minutes. Making it behave like a legally issued stock or fund means dealing with identity checks, sanctions, stock splits, court orders, etc.

Base is now baking those requirements directly into the network:

Its Cobalt upgrade went live on September 30, adding new transaction tools and expanding B20, the token standard Base introduced for stablecoins, stocks and other financial assets 🪙

The biggest change for traders is called Validity Transactions. A user can submit a transaction that becomes eligible only when certain conditions are met.

  • Someone could prepare a swap that executes only if an asset reaches a chosen price before a set block. Base checks the conditions as it builds each block. If they are met, the transaction can be included. If the deadline passes first, nothing happens ⌚

  • These transactions can also remain private until they land onchain. That gives traders a way to prepare orders without immediately showing everybody what they are trying to do 💵

The more interesting part concerns B20 assets:

  • Cobalt lets issuers combine several policies around one token. A fund could require somebody receiving its token to pass KYC, appear on an approved investor list and stay off a sanctions list. If that person later loses one of those approvals, further transfers can be blocked 🙄

  • The policies can be shared across multiple assets. An issuer managing several tokenized funds would not need to update every token separately when an address is added to a sanctions list.

Cobalt also adds scheduled multiplier changes for corporate actions such as stock splits. Instead of minting a new pile of tokens, the issuer changes how many shares each token represents. Wallets and apps then display the adjusted amount 📃

TLDR: a token representing a regulated stock does not suddenly escape sanctions, ownership disputes or court orders because it lives on Base. The company issuing it still has legal duties and will demand the controls needed to satisfy them.

The benefit is giving those assets a shared onchain standard to join wallets, exchanges and DeFi protocols to big players.

Coinbase already uses B20 for tokenized US stocks representing companies including Apple, Nvidia, Meta and Alphabet. They are backed by shares held with a regulated custodian and are available only in eligible countries outside the United States. Minting and redemption remain restricted to approved participants who have passed KYC 👨

Base plans to keep pushing in this direction. Its upcoming work includes reducing block times from two seconds to 200 milliseconds, adding native smart accounts, supporting sponsored gas and transaction batching and adopting parts of newest Ethereum upgrades.

That is less romantic than promising stocks without banks, laws or administrators. It may also be far more useful in real life situations. The real question is whether Base degens accept the trade: more access and composability in exchange for assets that still answer to an issuer when the law comes calling 😬

Other worthy reads

“Why Crypto Options Have Never Taken Off” - domdosu:

The state of tokenization report by Pantera Capial is out:

“How To Trade Prediction Markets Like Memecoins” - blocmates:

MEMES

That’s it for this week, frens.

If you enjoyed this edition, share the newsletter with someone who would enjoy it too. It only takes a few seconds and helps more people discover W3OF without us having to beg an algorithm for attention 💜

We’ll be back next week with another round from this… very normal industry. Until then, take care.

Yours, The 🔥 Team

W3oF is brought to you by Ambire Wallet.