- Web3 on Fire
- Posts
- 🔥 Ethereum upgrades: Quantum safe keys and gas without ETH
🔥 Ethereum upgrades: Quantum safe keys and gas without ETH
Also: Ambire puts Safe Multisig in your pocket 🤯

GM, frens! ☕️
If this week has given you another reason to wonder why you’re still doing any of this, good morning especially to you.
Persistence sometimes means having a grand plan, but more often it’s deciding that yesterday didn’t get the final word. You try again, adjust what didn’t work and carry on. Do that enough times and eventually you become very difficult to get rid of.
So wherever this Friday finds you, keep at it. Being stubborn has its uses 💜
Here’s what we’re looking at this week:
⛽️ Ethereum upgrades: Quantum safe keys and gas without ETH
📱 Ambire puts Safe Multisig in your pocket
🙄 Solana: routing Nvidia through a fart joke
💻️ Hunter Biden’s shitcoin escapades
🔐 Hardware wallets keep finding new ways to scare their owners
+ Other worthy reads
Come say hello in our Discord 🗣️

Ethereum upgrades: Quantum safe keys and gas without ETH
Anything designed to hold money for decades eventually has to prepare for threats that are still stuck inside laboratories. Waiting for the threat to become real is a bad plan when replacing the locks could take years 👨🔬
The Ethereum Foundation has now given itself until December 2029 to make Ethereum resistant to quantum attacks across transactions, validators and data storage. The date is based on the possibility that a computer powerful enough to break today’s cryptography could arrive as early as 2030 🧠
The current plan includes new signature systems, a public key registry, new protection for validators and an emergency mode that could keep Ethereum running with reduced guarantees if quantum computing develops faster than expected 👇️
The 2027 Hegotá upgrade is meant to prepare the account system and keep the later upgrades on schedule. Ethereum expects to fit five hard forks between Glamsterdam and the end of 2029, which leaves an average of roughly 7.2 months for each one 🪚
In the meantime, also, Ethereum wants to solve one of the most annoying problems in crypto: having plenty of tokens but no ETH to pay for gas (officially, finally) 🤭
EIP-8141, known as Frame Transactions, splits a transaction into separate parts. One part checks the user’s approval, another decides who pays the fee and the remaining parts carry out the actual transaction.
That means an app could cover gas for its users or accept a stablecoin while paying Ethereum in ETH behind the scenes. The user would not need to keep ETH around just to send another asset. Several actions could also be placed inside one transaction so they all succeed or fail together 🤷♂️
Frames would bring these features to regular Ethereum accounts without forcing users to create a new smart account or transfer everything to another address.
It would also let accounts replace their current authorization method, which connects the gas improvement directly to the work on quantum safe keys 🔑
Btw 🤠 Ambire users can already skip the ETH hunt through the Gas Tank. They can preload supported assets such as USDC, USDT, DAI, WBTC, ETH and WALLET, then use that balance to cover fees across supported networks. Gas tank has successfully worked for years.
It works through Ambire’s wallet infrastructure rather than Ethereum itself, but the practical result is already there: you can transact without keeping a little pile of every network’s native token 👇️

Ambire: Safe Multisig in your pocket
Multisig has one of crypto’s oldest sales problems. The idea makes perfect sense because one key should not be able to ruin you, but using it can feel like unpaid work sometimes. Ambire’s latest demo shows how Safe multisig can become something normal people actually use.
The demo 👆️ shows creating a basic Safe, importing it into Ambire and turns it from a 1 of 1 account into a 2 of 3 multisig. It then uses the Safe for an approval and swap through LlamaSwap, while Ambire handles queued transactions and keeps their nonces in order 🧠
The best part is the extension and mobile setup 📱
One signer can stay in the browser while another lives on the phone, giving the account an extra approval point across two devices. The Safe rules remain the same, but using them feels much closer to a normal wallet 🤏
The demo also introduces the Ambire Vault concept before wrapping up.
Wider mobile access should start rolling out soon, and W3OF may have a few invite codes to share as early as next week 👀

Solana wants to route Nvidia through a fart joke
Every industry eventually has to explain what it is contributing to the world.
Solar researchers can point to a silicon and perovskite cell that reached a certified efficiency of 34.85% (compared to ~8% 20 years ago), factories installed 542,000 industrial robots last year, more than twice the number installed ten years earlier. Defense companies are building crazy AI drones and systems capable of coordinating entire swarms 🤖
Solana leadership has chosen this moment to announce that “your tokenized Nvidia trade” may one day pass through…. Fartcoin 🤡
Solana cofounder Anatoly Yakovenko said he wants to see Jupiter route a trade between tokenized Nvidia and tokenized SpaceX through Fartcoin, with the resulting price eventually influencing US brokers.
Jupiter is a trade router. It searches different pools and picks whatever combination gives the user the best result. If a memecoin has good liquidity, the cheapest path between two assets could pass through it. The router does not care whether the middle asset is dollars, Solana or fartcoin 🤷♂️
The claim about setting the National Best Bid and Offer is far more hopeful. The NBBO currently comes from protected quotations across regulated US trading venues. A Fartcoin pool on a Solana exchange does not suddenly become the price every American broker must follow because somebody posted about it.
Still, the post captures how crypto likes to present itself 🤐
The rest of the world shows off something clever or better. We arrive carrying a coin named after gas escaping someone’s ass and demand to be taken seriously. And that, honestly, is the best we came up with?
The defense is always that the “stupidity is the point” 🙄
People gather around the silly coin it and it pumps, someone pays the rent with the profits and posts the proof. Suddenly buying it is no longer gambling on a joke. It becomes a rebellion against banks, professional investors and everyone who said the buyers were idiots. At least that’s how it played out for the first few times 🤷♂️

That feeling worked for Dogecoin and several generations of animal coins. It also worked for Fartcoin long enough to give it a serious market value. The buyer gets to imagine that purchasing something ridiculous is an “act of freedom” and that every price increase proves the financial establishment wrong.
Worth to mention: Fartcoin now trades roughly 93% below its 2025 peak. In April, analysts also identified a coordinated attempt to manipulate its price that cost a Hyperliquid vault around $1.5 million 💰️
And yes it would be good to remember that people shilling these coins are not providing a public service. Many already own large positions or earn fees and attention from the trading activity. Their success depends on convincing somebody else that the joke still has another run left 🫠
The token may create volume and fees, but it does not create new useful tech or for example, improve Nvidia itself in any sort of way. It rearranges money between traders and gives the earliest ones a better chance of leaving with the later ones’ cash.
The real cost reaches beyond the people holding the bag. Every time somebody presents Fartcoin as crypto’s great answer to Wall Street or whatever, builders working on payments, lending and actual finance have to explain that the entire industry is not one enormous fart joke.

Hunter Biden’s shitcoin escapades
Celebrity coins usually are all the same - “trust me this one will be different, because… uhmm… It represents a community, also a cause - and of course some deeply personal journey” - while the founders bundle it before launch and dump tokens on new buyers as soon as they can. The trend is extremely washed and tired by now 👴
Hunter Biden managed to squeeze the entire routine into a record 90 minutes.
He announced $LAPTOP as a memecoin built around the computer that haunted his family through two presidential elections. The story was that he was “reclaiming the object and turning it into a symbol of resilience, redemption and recovery” 🤦♂️
He also took aim at Donald Trump’s memecoin, calling it a grift and promising to give part of the LAPTOP supply to people who lost money on it. Yes, the answer to victims of one political shitcoin was to offer them another political shitcoin 😐️
In this case, Biden was honest about wanting money.
Before the launch, he told Tucker Carlson that he believed in crypto but also wanted to make some cash. The planned supply included one billion tokens, with 30% going to Biden and the other founders. Those tokens were supposed to remain locked for six months and become available gradually over two years 💰️
Another 20% was meant for people who lost money on TRUMP, Biden’s Substack readers and subscribers from journalist Andrew Callaghan’s mailing list.
Callaghan’s Channel 5 soon said it had nothing to do with the coin, did not consider crypto a legitimate investment and had pulled its subscriber list from Biden’s team before the emails went out 🔨
Even the places expected to help trade it began backing away. Pump Fun and Kraken posted promotions for the launch, then deleted them after traders tore into the project. Jesse Pollak said Biden’s team had approached Base but that the company stayed out of it because of the politics 🤔
The launch happened on September 9th.
LAPTOP began trading on Aerodrome with an intended starting price of five cents. Sniper bots immediately bought from the low LP pool and sent the quoted price into complete nonsense. Different trackers recorded highs between roughly $200 and $316 before the token collapsed to a few dollars.
A report measured a 98% fall from $199 to $1.36 in only 90 minutes 😬
It looked exactly like a rug to anyone watching. The project says the founder allocation was locked, nobody received secret early access and nobody from the team sold 🙃 (although onchain data says otherwise).
The team blamed bots and a pool that did not contain enough liquidity to handle the attention. It later announced that another four million tokens would be added to encourage liquidity on Aerodrome.
But even if it was true that explanation does not make the launch any less stupid. If a pool is small enough for bots to send a five cent token above $200, the number on the screen is not a real valuation 🤖
Snipers (impossible to tell insiders or independent ones) still made decent money.
Analysts found them collecting profits ranging from around $190,000 to $335,000. Another analysis found a wallet that turned roughly $250,000 into $1.18 million within minutes. Nansen found other buyers sitting on losses of around $118,000 and $199,000 💵
Hunter’s attempt to sell the project as an alternative to Trump’s coin makes the whole thing even funnier. He criticized somebody else for attaching a political name to a token, then attached his own name + his most famous scandal while pulling the rug 🤡
At least Hunter was also a degen in real life before crypto, y’know, not some kid pretending to be ruined for the brand. Drugs, tax fraud, a gun conviction and the presidential pardon all came before he found Base 😏

Also the most useful warning came before the first trade - when platforms deleted their promos and KOLs begged him to cancel or when people connected to the distribution wanted their names removed. Almost everyone close enough to understand the launch stepped backward, so that’s a good clue - when even the casino takes down the poster, perhaps do not rush through the door 😶

Hardware wallets keep finding new ways to scare their owners
People buy a hardware wallet because they want one part of crypto they do not have to worry about every morning. The little box goes into a drawer, the recovery words go somewhere safer and the keys stay away from the internet.
That is the idea, anyway. In practice, owners are now replacing seeds, checking firmware versions, reviewing old token approvals and wondering whether the urgent security email sent from a real company address is itself trying to rob them.
At some point, people are allowed to get sick of this 🥹
We recently talked about the Coldcard situation that made some recovery phrases far more predictable than they should have been. Attackers reportedly drained more than $100 mil and installing the fixed firmware was not enough. Anyone who created an affected seed had to generate a new one and transfer the funds before somebody else found the old keys 🔑
That should have been the big hardware wallet security disaster for a while. Instead, the weeks since then have produced one warning after another.

Trezor first disclosed that a breach at shipping company ShipMonk had exposed information connected to 13,689 customers. Then, on September 4, the company revealed that another 67,000 US customers were affected.
The total now sits at roughly 80,000 people. The stolen records included names, email addresses, phone numbers, shipping addresses and order numbers. The devices, private keys and recovery phrases were not compromised, but attackers were handed a large list of people who probably own crypto and the addresses where many of them live 🤦♂️
The extra records came from orders placed between 2019 and 2021. Trezor said it had repeatedly asked ShipMonk to delete that information and had received written confirmation that it was gone.
It was not gone.
This was also not Trezor’s first customer data problem. Another incident affected more than 106,000 customers in 2022, while a compromised support portal exposed as many as 66,000 names and email addresses in 2024.
SafePal joined the list in August. A flaw in an order tracking plugin exposed information belonging to 39,798 customers, including names, delivery addresses, phone numbers and purchase details. The affected period stretched from March 2025 to April 2026, while researchers said possible related scam reports had appeared months before the company disclosed the breach ✉️
Ledger had its own problems around the same time. A flaw in its Ethereum app could allow a malicious application to replace transaction data after the user had already reviewed what appeared on the device screen. Ledger fixed that problem, then released another update for two separate signing flaws that remained in the previous version.
BitBox also released firmware 9.26.5 after finding three vulnerabilities in August. The company said no seeds were exposed and no users were known to have lost funds. Finding and fixing bugs before they are exploited is exactly what a security team should do, but owners still had another update to install and another set of warnings to understand 🤨
Then this week arrived.
On September 9 and 10, Trezor, BitBox and CoinTracking warned users that attackers had compromised mailing infrastructure used by several crypto companies. Customers received phishing emails that looked like real security notices because they came through channels people had been taught to trust 👇️
Trezor users received a message titled “Critical Security Alert: STM32 Entropy Vulnerability.” It told them their wallet security was at risk and directed them toward a malicious link. The subject was well chosen. After Coldcard’s actual entropy disaster, plenty of hardware wallet owners already knew that a faulty source of randomness could destroy everything 🫢
BitBox subscribers received phishing messages as well. The company said several Bitcoin businesses appeared to have been targeted through the same newsletter provider. CoinTracking identified its affected provider as Brevo after customers received fake instructions to refresh their API keys 🔒️
The thing is, hardware wallet customer does not experience security as a neat list of separate systems. The device, companion app, firmware, shipping company, support portal and official email address is none of their problem - they all belong to the same purchase. If one of them tells the owner that the box is broken and asks for the recovery phrase, the attacker has reached the last person standing between the wallet and the funds 🥸
The burden keeps landing on that person.
Let’s just stop and think for a second how you operate a hardware wallet in 2026:
You get email from the company, but the official mail from the official sender may be an exploit. You read the device screen, but a signing bug may make it look like you’re signing your txn but you might be signing a wallet duster. You install updates, but you have to make sure the update warning is not phishing too. Keep the wallet offline, but hope the company that shipped it does not need constant updates, also you have to hope it did not keep your home address for seven years and does not unintentionally send gang members after you 🫠

Hardware wallets didn’t become useless yet. A properly designed and updated device still protects keys from many attacks that would empty a software wallet. Bugs being found and fixed can also show that reviews are working. But.
What the community is rejecting is these companies’ idea that every mishap outside the “secure chip” somehow does not count. Wallet companies chose the shippers, mailing services and support tools.
They collected the customer information and allowed other companies to store it. They cannot sell the whole experience as security, then point at a third party whenever the experience fails, it was carelessness and for a security company that’s the whole point of their existence, isn’t it? 😐️ It’s like you’re baking pies but failing because they taste like shit and you blame the sugar supplier, or something, just give up then.
The question used to be which device had the best chip, firmware or source code. Buyers are now being forced to ask which company collects the least information, deletes it properly and relies on the fewest outsiders.
The next hardware wallet winner may not be the box with the most features. It may be the company that can sell one without building a list of people worth robbing 🤷♂️

Other worthy reads
“Have Fun Staying Poor” - Evanss6:
“5 Onchain Experiments Bringing Crypto Back to Life” - blocmates.:
“Meme leaders are emerging in Robinhood stock tokens” - @JW100x:

MEMES








That's all for now, frens.
We'll meet in a week! And remember, the market conditions are temporary, but our commitment to building a better Web3 is here to stay. Thanks for joining us, and we look forward to seeing you back next week. Cheers!
Yours, The 🔥 Team
Brought to you by Ambire: The Only Web3 Wallet That You’ll Need!


