- Web3 on Fire
- Posts
- 🔥 Ethereum’s new roadmap starts planning beyond the EVM
🔥 Ethereum’s new roadmap starts planning beyond the EVM
Ambire’s next big feature may be private transfers 👀

GM, frens! ☕️
Everyone looks good before they’re tested. Conviction is easy when you’re winning, patience is easy when there’s nothing to worry about and principles are easy when they cost you nothing.
Then eventually something puts a bit of weight on all of that, and you get to find out how much of it was real. That’s the useful part of being tested: whatever the answer is, at least now you know.
Here’s what we’re looking at this week:
🧙 Ethereum’s new roadmap starts planning beyond the EVM
✉️ Ambire’s next big feature may be private transfers
🔨 Adapt or disappear: crypto’s 2026 cull
🪙 Vendor fights and dice guides take over the BTC community
🤦♂️ Degens argued about plumbers and minted another “1000X” shitcoin
Got thoughts? Bring em to our Discord 🤠

Ethereum’s new roadmap starts planning beyond the EVM
Ethereum’s roadmap once fit into six memorable labels: the Merge, Surge, Scourge, Verge, Purge and Splurge. It sounded straightforward enough to print on a shirt, which was always strange for a plan involving years of cryptography, distributed systems research and thousands of devs who regularly disagree with each other.
Vitalik Buterin has now compared that older 2023 plan with Ethereum’s current Strawmap and marked where the priorities moved 👀
Though, this is not one giant upgrade waiting to be installed. The Strawmap is a draft maintained by Ethereum Foundation Architecture, and the Foundation has already warned that dates assigned to forks beyond 2026 looked more certain than they really are 👇️
Much of the original direction remains, but several assumptions have changed.
Quantum safety has moved higher. Verifiable delay functions and some planned EVM improvements have fallen lower. Verkle trees gave way to unified binary trees and then another proposed structure called PBT, while state expiry is being replaced by new state types 🔒️
The biggest additions are ideas that were either immature or absent three years ago. Buterin’s updated comparison puts native privacy, post-quantum scaling, formal verification, gas and blob futures, native rollups and possible alternatives beneath the EVM into Ethereum’s longer plan.
Privacy receives the clearest promotion. Ethereum has generally relied on wallets, apps and separate protocols to hide user information, while the base layer makes almost everything easy to inspect 🔍️
The new work includes keyed nonces, recent roots, lean privacy pools, wormholes and parts of FOCIL, a proposal that would make it harder for block builders to exclude valid transactions.
The names are dense, but the goal is simple enough. Ethereum wants users to reveal less about themselves by default, while also making censorship harder.
Keyed nonces could reduce the ability to connect transactions from the same account. Recent roots could let private apps prove they used a valid recent state without exposing an entire history. Privacy is moving from something users bolt on afterward toward something the protocol must actively support.
Quantum security has also been promoted from a distant concern to an active design constraint. Today’s signatures could eventually become vulnerable to a sufficiently capable quantum computer. Nobody has such a machine ready to empty Ethereum wallets tomorrow, but replacing cryptography across a global network takes years, so waiting for the alarm to start flashing would be spectacularly stupid 🤷♂️
The roadmap looks at hash based leanSPHINCS signatures, signature aggregation and zkzk frames. Post-quantum signatures are much larger than Ethereum’s current ones, which creates another scaling problem. Zkzk frames would let many signatures and proofs be compressed into recursive proofs so the network does not drown in the extra data needed to protect itself.
Ethereum also wants a leaner specification that can be formally verified, meaning critical parts of the protocol could be mathematically checked against the rules they are supposed to follow. Buterin argues that modern AI tools make full protocol verification more realistic 🤖
Native rollups may be the most important addition for Ethereum’s current scaling model. Rollups now operate as separate systems with their own proving arrangements and contracts. A native rollup would use verification built more directly into Ethereum itself. Advances in SNARKs and STARKs have made that credible in a way they were not in 2023 🤓
Then there is the EVM, the execution engine that runs Ethereum smart contracts and became a standard across much of crypto.
The new roadmap does not abolish it, but it does question whether the EVM must remain permanently embedded at the deepest level of the protocol. LeanISA and RISC-V are being discussed as simpler instruction sets underneath it, with the EVM potentially becoming an intermediate compatibility layer on top 🤔
That possibility is still so early that Vitalik said it may be premature even for the Strawmap but it’s important anyway because Ethereum has built an enormous industry around EVM compatibility, then started asking whether its most successful standard should remain untouchable forever. Most platforms turn compatibility into an excuse never to clean that “basement”. Ethereum is at least willing to inspect the foundations while the building is occupied. If that comparison makes sense 🙄
The downside of all this is complexity. Ethereum already changes several connected layers at once, and every new proof system, state structure or execution path creates more work more places for an implementation to go wrong.
Still, the roadmap shows one of Ethereum’s better habits. It does not treat a diagram from 2023 as scripture just because everyone learned the rhyming names. The plan changed because the technology changed. And that makes a lot of sense 🤏

Ambire’s next big feature may be private transfers
Ambire team member Jordan Enev just dropped a not-so-subtle tease: private transfers right inside Ambire may be closer than we think.
The team later confirmed it has already pulled them off internally, so this is no longer just an idea sitting somewhere on a roadmap 🤯
At the simplest level, private transfers let people send crypto without giving every observer a clear path back to their wallet balance and full transaction history. Proof of Innocence adds a way to show that funds are not tied to flagged sources without exposing everything else.
Ambire broke down the idea here 👇️
The details are still private, appropriately enough, and there is no release date yet. Still, if the tech is already working internally, private transfers inside Ambire may be getting much closer to actual wallets 👀

Adapt or disappear: crypto’s 2026 cull
Survival was always a proof that some projects deserved to exist in our space. At least that’s the way most understood it. If the token still traded, the website loaded and somebody posted something on twitter every few days, the business was apparently alive.
The 2026 market has started applying a less forgiving test: does anyone actually need this thing enough to pay for it?
The answer has been.. unpleasant 😐️
More than a 100 big crypto projects have shut down, filed for bankruptcy or gone permanently dark this year, according to RootData. Exchanges, wallets, lending protocols, NFT marketplaces, blockchains and the tools built around them have all been hit. Four sizable names, including BitMEX, BitMart, Movement Labs and Storj Labs, announced closures or filings within one week in July ☠️
The easy explanation is that prices fell 💰️
Many altcoins lost between 70% and 90%, which destroyed treasuries held almost entirely in the projects’ own tokens.
Teams paid salaries, security costs and liquidity incentives with an asset whose value depended on the market continuing to believe the team could keep paying salaries, security costs and liquidity incentives with it.
That works beautifully until the circle notices it is a circle 🤷♂️
Several closures show that usage alone was not enough.
Tally provided governance tools to more than 500 organizations, processed over $1 billion in payments and helped secure systems holding as much as $80 billion. Its co founder still concluded that a venture backed business in DAO governance tooling does not exist yet.
Similar story to POAP that we’ve covered last week. Plenty of people used the product, but not enough customers paid enough money to support the company behind it 💵
Security has become part of the cull 🗝️
TRM Labs counted 207 hacks and $972 million stolen during the first half of the year, the highest number of incidents it has recorded in any six month period. Most were smaller smart contract attacks, while a few infrastructure compromises caused most of the financial damage. A single bad permission, stolen key or compromised employee, as always, can kill a project whose treasury already lost most of its value.
Even shutting down properly can be difficult when the product is onchain ⛓️
For example, Moonbeam stopped producing blocks on July 31, leaving some assets inaccessible. Stream Finance disappeared in 2025, yet code connected to it was blamed for a $6 million exploit at Lazy Summer Protocol eight months later. So some examples are basically the digital equivalent of an abandoned factory that keeps operating its machinery after everyone responsible has left the building.
Some compare it to dot com moment, although it has become a comforting cliché for every industry that wants to believe its bankruptcies are the beginning of Amazon. The internet crash did not prove every failed website had been secretly valuable. It proved that the underlying technology could matter enormously while most of the businesses built during the rush were still bad businesses 🤪
Losing that amount of projects is not pleasant. Good teams will disappear alongside pointless chains, useful open source tools will struggle because nobody worked out who should fund them and users will lose access to products they genuinely valued 🪙
But the “test” itself is older than crypto by several thousand years. Credit and accounting were already developing in Mesopotamia around 3300 BCE, when people began recording goods and debts on clay tablets. Bronze Age merchants had financing, contracts and angry customers. They also had the same basic problem as a token founder in 2026: yesterday’s demand did not guarantee tomorrow’s business 📜
Finance has been wiping out people who mistake a favorable period for a permanent rule since humans first learned to write down who owed whom goat skins. The tools change from clay tablets to smart contracts, but the requirement does not. A business adapts to new risks and new environments or something else takes its place.
Crypto is being tested hard, but this is not the first test and it will not be the last.

Vendor fights and dice guides take over the BTC community
The Bitcoin community is currently arguing over dice, hardware wallet licenses, deleted X posts and whether its favorite security slogan was ever applied to the products everyone trusted.
This is not another conflict between L1s and exchange owners telling them to hand over their keys. It is happening inside the self custody camp, among people who already agreed that holding your own bitcoin was the goal. What they no longer agree on is how an ordinary person is supposed to do that safely and reasonably or who deserves to be trusted along the way 🥸
It all started because of Coldcard.
The hardware wallet was near the top of serious security recommendations, particularly for users who wanted an air gapped, BTC-only device. Then a firmware bug allowed affected wallets to generate seeds with dangerously weak randomness. Attackers could reconstruct the keys remotely and losses climbed beyond $100 million 💸
Once the immediate warnings went out, the community did what it usually does after a disaster: it began ripping through years of old arguments, recommendations and personal grudges to work out who had failed first.
Some in the community focused on Coinkite moving Coldcard away from a fully open source license in 2020 and using a more restrictive source available model. Critics argued that readable code was treated as though it had been widely tested, while restrictions gave other wallet devs less reason to build with it and encounter problems 🔧
A widely shared community response summed it up neatly: Bitcoiners had preached verification, then assumed one of their favorite devices had already been verified by someone else 🫥
The opposing point was that the code remained visible and the eventual bug sat in a difficult interaction between separate software components. Simply changing the license would not have summoned a competent auditor to inspect the exact seed generation path 🌱
The dispute quickly reopened the old fight between Coinkite and Foundation, maker of the Passport wallet.
Foundation CEO Zach Herbert resurfaced earlier criticism of Coldcard’s reproducible builds and pointed to posts in which Coinkite co founder Rodolfo Novak had attacked WalletScrutiny after it reported difficulty reproducing some releases. Novak had also called competing products clones and questioned their security 🤐
That history became especially sus once it surfaced that Novak was deleting some older X posts.
Other hardware wallet makers and custody companies naturally entered the discussion, some offering useful explanations and others discovering that a competitor’s catastrophe makes wonderful marketing material. Coldcard defenders accused rivals of scavenging.
Thus, a security failure had turned into the Bitcoin hardware wallet industry’s family argument, except the family was fighting beside a hole worth more than $100 million 👜
Ordinary holders were caught between those camps asking a much simpler question: where should the coins go now?
Community forums filled with users comparing Trezor, Passport, SeedSigner, Jade, BitBox and multisig services. Every recommendation immediately attracted somebody explaining why that device, secure element, license, backup method or supply chain also required trust.
People who came looking for one replacement wallet instead received a graduate seminar on entropy and several accusations that the speaker’s preferred manufacturer was compromised.
That is how throwing dice went from an advanced option to one of the community’s largest conversations of the week 🎲
Coldcard let users add their own ‘dice rolls’ when generating a seed. Those who supplied at least 50 fair, private rolls were protected from this particular bug because their keys did not rely entirely on the device’s failed random number generation. After the exploit, guides for dice generated seeds spread across X, Reddit and Bitcoin forums, while some users began checking old documentation to see whether they had added enough physical randomness years earlier 🙄
The dice discussion soon produced its own argument.
Supporters saw a source of randomness that could be understood without trusting a hardware maker. Others warned that users could record the rolls, use biased dice, follow the conversion incorrectly or download a malicious worksheet.
One group had just watched a machine fail and wanted more human control. The other had watched humans lose seed phrases for years and did not fancy giving them 100 manual steps 💀
Then the BTCPay Server exploit made it impossible to contain the argument to Coldcard.
Attackers exploited a separate flaw to obtain LND macaroon credentials from vulnerable BTCPay deployments 🤔
Those credentials could control Lightning nodes, allowing funds to be moved and channels closed. Foundation and Bitcoin publication Citadel21 both reported drained nodes.
Coldcard had hurt people storing BTC for the long term. BTCPay hit people operating Bitcoin payment infrastructure. Two unrelated incidents landed close enough together to turn anxiety about one company into anxiety about the software surrounding Bitcoin more broadly.
Sixteen members of the volunteer Bitcoin Red Team responded by pointing AI tools at wallets, cryptographic libraries and other Bitcoin projects. In a little more than a day, they submitted 7,962 findings across 501 projects, including 1200 labeled high severity 🤯
That caused yet another argument. Some Bitcoiners praised the effort as exactly the sort of aggressive review the ecosystem needed. Maintainers found themselves buried under reports of mixed quality, while the team admitted it was still separating real problems from machine generated garbage 🤖
The result is not one unified response but a community pulling in several directions at once. Some users are moving toward dice and multisig. Others are switching hardware brands or considering professional custody 🫠
Open source advocates are treating the exploit as proof that licenses and reproducible builds are the most important. Vendor loyalists are defending the products they already trusted. Security devs are auditing everything they can reach, while maintainers are asking them to stop dropping thousands of unsorted findings at the door 🎁

Underneath all of it sits a more personal problem. Bitcoiners have a culture around not trusting banks, governments or exchanges, yet many still placed enormous trust in a handful of “respected people” and products inside their own community 🃏
Not merely some device. Some of those were a recommendation passed between friends, podcasts, meetups and forums. When it failed, people did not only lose coins. Many discovered that advice they had repeated for years was incomplete.

That is what is brewing in the Bitcoin community now - there is plenty of blame, vendor warfare and hindsight, but there is also real work happening. People are checking dice code, testing alternate setups, tracing stolen funds and forcing old claims back into public view.

Degens argued about plumbers and minted another “1000X” shitcoin
Crypto Twitter had a day deciding whether early traders were geniuses or merely beating plumbers. Before anyone settled it, a dev “minted the argument” and it went up more than 10,000% 😶
The plumber business began with a couple of opinion posts about crypto “oldheads” who were trading against “plumbers” 👨🔧
The insult was aimed at the supposedly less sophisticated retail traders on the other side of early crypto trades, people who arrived with regular jobs and found themselves facing professionals who had already learned every trick available in a small market 👇️
This started some discussions, both sides had enough truth to keep the argument alive and enough ego to make ending it impossible 🥱
Then crypto performed its favorite trick. Someone saw the attention to the topic and launched PLUMBER through Pumpfun and turned a social media argument into a tradable object before the people involved had finished replying to each other.
The token climbed from below $1 million to above $5 million in market capitalization on its first day, generated about $14.2 million in trading volume and recorded a gain above 10,000% 🥴
The joke managed to eat itself almost immediately. The original argument was about whether old traders looked smarter because their opponents were less experienced. PLUMBER then offered a fresh test by inviting modern traders to chase a hot garbage exit scam created hours earlier from a post mocking people for being easy to trade against 🤡
Memecoin traders would say that everyone understands the deal. A pumpfun “shitter” does not claim to reinvent finance, it’s a bet on whether the joke keeps attracting buyers, and that in their eyes that’s honest.
But as always with these kind of things, the honesty ends where the supply begins. Analyst Stitch flagged a launch being bundled at near 60%, meaning a large share of the token supply appears connected to coordinated early buying 🤷♂️
Recent examples show how fast this kind of value can evaporate. CASHCAT rose around 4,000% during the week before giving up much of the run. BRIAN climbed from below $1 million to roughly $37 million after Brian Armstrong changed his profile picture, then fell about 90% when he changed it back 👇️
In the end, nobody proved whether the traders of 2017 were masters or happened to be facing easier opponents.
What all this proved is that crypto has not changed much: every generation laughs at the suckers from the previous cycle, then lines up to buy somebody else’s bags. Oldhead or plumber or whatever you choose to call yourself, if you fall for it, you are still exit liquidity 🪠

Other worthy reads
“Why Tokenization Is the Next Chapter in the Evolution of Finance” - Zeus:
“KRW 700 Trillion Abroad: The Market Korea Missed” - Tiger Research:
“Robinhood Chain: Can It Move Robinhood's Bottom Line?” - AJC:

MEMES







That's all for now, frens.
We'll meet in a week! And remember, the market conditions are temporary, but our commitment to building a better Web3 is here to stay. Thanks for joining us, and we look forward to seeing you back next week. Cheers!
Yours, The 🔥 Team
Brought to you by Ambire: The Only Web3 Wallet That You’ll Need!

