Written by | GaryMa, Wu Blockchain

The WuBlockchain summarizes key developments in the blockchain technology space for September:

Bitcoin

Bitcoin Core v32 branched off from master into the 32.x release branch on September 14 and entered its RC testing cycle, with v32.0rc1 released for community testing. The final version remains targeted for October. The release had already reached feature freeze in August and mainly introduces improvements such as parallelized block validation, global transaction rate limiting, and a new mempool-based fee estimator. It does not change Bitcoin consensus rules.

StarkWare said a one-week AI-assisted code optimization competition reduced the estimated GPU computation cost of preparing a quantum-safe Bitcoin transaction from around $320 to $66, while increasing the core search rate from roughly 146 million to 881 million attempts per second. The mechanism uses hash-based protections for eligible BTC and could serve as an emergency migration path under a potential quantum attack without requiring a Bitcoin network upgrade. However, the $66 figure remains a test estimate and has not yet been validated through another real on-chain transaction. The scheme also cannot protect BTC whose public keys have already been exposed.

Bitcoin and Lightning developers proposed PQLN, or Post-Quantum Lightning Network, which aims to introduce post-quantum protection for off-chain Lightning components including node identities, P2P transport, invoices, Offers, and payment onions without waiting for Bitcoin L1 itself to complete a post-quantum migration. The proposal uses standards including ML-DSA and ML-KEM and already has a testable prototype based on rust-lightning. Tests suggest cryptographic computation overhead is relatively low, while the much larger public keys and signatures make network bandwidth the main cost. PQLN remains at the research and prototype stage.

Ethereum

Glamsterdam upgrade: L1 scaling, parallel execution, and MEV architecture redesign. Progress: In September, development continued to converge from DevNet stability testing toward public testnet deployment. Developers confirmed that Glamsterdam will activate on Sepolia on October 6, with client teams required to release compatible software by September 29. Hoodi testing is tentatively scheduled for October 27, with a go/no-go decision expected on October 8. No mainnet activation date has been set. September testing continued to focus on edge cases involving BAL preservation and reconstruction, execution payload propagation, the Engine API, and block building and payload availability under ePBS. Developers also warned that attackers on testnet could exploit free test ETH and repeatedly created Builder identities to win auctions and then withhold payloads, potentially disrupting Sepolia testing without putting mainnet funds at risk.

Hegotá upgrade: censorship resistance, native account abstraction, and post-quantum readiness. Progress: The upgrade scope narrowed significantly in September. The Ethereum Foundation Protocol Cluster ranked 62 candidate EIPs and designated FOCIL (EIP-7805) and Frame Transactions (EIP-8141) as S-tier “Must Ship” proposals, making them the core consensus-layer and execution-layer features respectively. Another 15 EIPs were classified as A-tier and expected to be included, while 28 were explicitly rejected. FOCIL strengthens censorship resistance by having a validator committee provide transaction inclusion lists. Frame Transactions moves account validation, Gas payment, and execution logic further into the protocol layer, creating a foundation for native account abstraction, sponsored Gas, batched operations, and eventual migration toward post-quantum signature schemes. The EF also set a protocol R&D goal of making Ethereum L1 fully post-quantum across its execution, consensus, and data layers by December 2029.

Ethereum co-founder Vitalik Buterin said during the opening speech of Shanghai Blockchain Week 2026 that cryptographic technologies once considered far from practical, including FHE, obfuscation, and iO, are advancing rapidly. He argued that blockchains could evolve from systems primarily determining “who can send which assets” toward systems capable of programming “who can see which information.” Using FOCIL (EIP-7805) as an example, Vitalik said multiple validators could jointly provide transaction inclusion lists to reduce the ability of a single block builder to censor or delay transactions. He also expects more computation to be performed in parallel across user devices, mempools, and block-building infrastructure over the next five years, while Ethereum continues working to reduce finality from roughly 16 minutes today to 8–32 seconds.

The Ethereum community proposed EIP-8411, which would change how execution payloads propagate across the network by splitting full payload data into chunks that can be forwarded before the entire payload has been received. Merkle commitments would be used to verify individual chunks, while requiring relatively limited consensus-layer changes. Simulations without relying on data-center-grade bandwidth showed that propagation of a 1 MiB payload to half the network could fall from around five seconds to under one second.

The Ethereum community is advancing EIP-8198, known as “Quick Slots.” The proposal would remove compile-time assumptions that Ethereum slots are fixed at 12 seconds and make slot duration a runtime parameter. The initial goal under discussion is to reduce L1 slot time from 12 seconds to 10 seconds, with further reductions possible depending on network behavior and client bottlenecks. The proposal aims to narrow arbitrage windows, reduce LVR, improve DEX pricing efficiency, and provide faster transaction confirmation. Combined with FOCIL, it could also preserve transaction inclusion and censorship resistance while reducing slot duration. The proposal remains in the engineering and discussion stage.

Researchers from the Ethereum Foundation, Theta Labs, StarkWare, and other organizations published work using AI coding agents to optimize the core operations of Shor’s algorithm. Their work reduced the estimated resources required for a potential quantum attack against secp256k1, used by Bitcoin and Ethereum, by more than 50% compared with Google’s March benchmark. The logical qubit requirement was reduced to 1,151 and later to 813 in a subsequent version. Current quantum hardware remains far from being able to break major public blockchains, but the study shows that algorithmic optimization continues to lower the theoretical attack threshold and strengthens the case for early post-quantum migration planning.

Vitalik Buterin introduced EIP-8288, the “Recursive STARK Mempool,” and said he hopes it can be included in the I* fork following Hegotá. The proposal aggregates transaction dependencies inside the mempool and generates recursive STARK proofs, aiming to reduce the cost of post-quantum signatures and private transactions. It could also support new signing and proof schemes such as Falcon and ML-DSA without modifying the EVM, while enabling private account abstraction. Vitalik estimated that the design would generate around 100–300 kB of STARK data per time period, with on-chain overhead consisting of one STARK plus 96 bytes per proof statement. RISC-V is currently being considered as the language for recursive STARK statements.

Ethereum L2s

Optimism advanced OP Stack Upgrade 20 in September and completed its targeted mainnet deployment on September 24. The upgrade does not introduce a new L2 hard fork. Instead, it modifies L1 contracts and the Fault Proof system, moving dispute proofs from single-chain Output Root Dispute Games toward Super Root Dispute Games, which can represent multi-chain state, while also upgrading OPCM to v8. Upgrade 20 is a prerequisite for future OP Stack Interop. Individual chains still run separate dispute games today, but future cross-chain messaging will depend on the states of multiple chains over the same time period, and Super Roots provide the foundation for validating those cross-chain dependencies together.

Scroll completed its OpenVM v2.0.0 mainnet upgrade on September 22, upgrading its zkVM prover stack from OpenVM v1.6 to v2.0, switching the underlying proof system to SWIRL, and deploying a new on-chain verifier contract. The upgrade also incorporated multiple security fixes from OpenVM v1.7, including verification issues affecting MemoryMerkleAir and the Halo2 Verifier. Because both the proof system and circuits changed, the upgrade is a breaking change at the ZK layer, but it does not alter Scroll’s EVM, fee model, RPC interface, or user-facing behavior.

Solana

Solana core developer Anza announced that the Alpenglow consensus upgrade has been activated on Devnet, following its Testnet transition on September 24. Alpenglow is designed to replace the existing PoH + TowerBFT consensus path by having validators exchange votes directly and reach deterministic consensus after one or two voting rounds. Its target is to reduce finality from roughly 12.8 seconds to around 150 milliseconds. The 150ms figure remains a design and simulation target and has not yet been validated under real mainnet market conditions. No mainnet activation date has been announced.

Solana continued the phased slot-time reduction under SIMD-0525 in September, with the mainnet target slot time reduced further to 250ms. Official data shows that as the network moved from 400ms to 350ms, 300ms, and then 250ms, skipped-slot rates remained broadly stable while downtime caused by consecutive skipped slots declined. However, shorter slots place greater networking demands on geographically distributed validators, with voting latency increasing most notably for nodes in Asia and South America. Further movement toward the eventual 200ms target will therefore require continued monitoring of network propagation and validator geographic distribution.

Solana Transaction V1 (SIMD-0385 / SIMD-0296) activated on mainnet on September 15, increasing the maximum V1 transaction size from 1,232 bytes to 4,096 bytes, or roughly 3.3x. The larger transaction envelope allows some ZK proofs, large multisigs, BLS signatures, and complex batched operations to be executed within a single atomic transaction. Legacy and v0 transaction formats remain supported. Because blocks can now contain V1 transactions, RPC providers, indexers, and wallets that only declare v0 support may fail to correctly read some blocks or transactions and will need compatibility upgrades.

Anza said Solana mainnet activated the first phase of SIMD-0437, reducing the storage rent unit cost from 6,960 lamports per byte to 6,333 lamports. The proposal consists of five stages and aims to gradually reduce the figure to 696 lamports, representing a 90% decline from the original level, subject to state-growth conditions. SIMD-0438 can restore the previous rate if state growth becomes problematic.

BNB Chain

Following the Pasteur Hard Fork in August, BNB Smart Chain began evaluating the mainnet scaling impact of BEP-675 / BidBlock V2 in September. BNB Chain said BidBlock V2 was used in around 98% of blocks by mid-September and, by removing one redundant EVM execution step before block packaging, allowed blocks to carry around 28% more Gas on average than Bid V1 under real mainnet traffic. Validators then began raising the Gas Limit from 55M toward 70M, with plans to evaluate 80M and 90M based on finality, missed-block rates, cross-region latency, node import times, and builder concentration. The team is also advancing gRPC/RLP block transport, eth/70, BAL, and related technologies to support larger block capacity.

Hyperliquid

Hyperliquid plans to reduce the perpetual futures funding-rate cap from 4% per hour to 0.5% in its next network upgrade, while further expanding deployment capacity for HIP-4 Outcome markets. The maximum number of simultaneously active Outcomes per deployer is set to rise from 100 to 200, while the daily deployment cap will increase from 500 to 1,000. The project had also previously planned to reduce the minimum Outcome order notional from $10 to $1 and add deployment-quota query interfaces, indicating that HIP-4 has moved into a phase focused on capacity and trading-experience optimization following the introduction of permissionless deployment in August.

Celestia

Celestia activated v10 on the Mocha-5 testnet on September 24, bringing Fibre into a live network environment and allowing bonded validators to launch and register Fibre Servers. Fibre is a new data availability path in which the chain primarily records Blob Commitments, while actual Blob Payloads are erasure-coded, propagated, and stored through a validator-operated network. This is intended to bypass throughput bottlenecks in the traditional block-data propagation path. v10 is a breaking network upgrade and is currently being tested on Mocha. No Mainnet Beta activation date has been announced.

Security

Liquid Network suffered a consensus-level exploit on September 6. The attacker exploited ambiguous encoding in the cache key used for Elements Rangeproof verification, causing nodes to incorrectly accept a transaction whose output value was not backed by legitimate inputs. This enabled the unbacked issuance of roughly 4,000 L-BTC, which was then converted into Bitcoin mainnet BTC through the normal peg-out process. Blockstream later disclosed that around 3,400 BTC had been returned by the attacker, while roughly 602 BTC remained unrecovered at the time of reporting. The vulnerability was fixed in Elements v23.3.4 by introducing length-prefixed serialization for Rangeproof and Surjection Proof cache keys, preventing different parameter combinations from generating the same cache key. The incident demonstrates that validation caches themselves can form part of the consensus security boundary.

SlowMist warned that MemTensor’s AI memory tooling had been compromised. The open-source long-term memory library MemoryOS on PyPI and the official memtensor/memos-cloud-openclaw-plugin npm package used with the OpenClaw runtime were found to contain a cross-platform Go binary that executed when the packages were loaded or imported. Affected versions include MemoryOS 2.0.34 on PyPI and npm plugin versions 0.1.21, 0.1.23, and 0.1.25. The affected npm plugin may also leak user prompt content. SlowMist recommended uninstalling or downgrading to known-safe versions, terminating related processes, reviewing network activity, and rotating credentials exposed in affected environments.

SlowMist CISO 23pds issued a security warning urging iOS users to update their systems. He said underground attackers had begun reusing the leaked “DarkSword” full-chain iOS exploit kit, combining malicious webpages, WebKit/JSC memory corruption, PAC bypass, WebContent sandbox escape, and kernel privilege escalation to obtain root privileges and potentially steal Keychain and crypto wallet data. The attack chain poses a direct threat to mobile self-custody wallets.

Bitcoin developer Niklas Gögge said recent incidents involving Coldcard, BTCPay Server, Liquid Network, and other projects show that LLMs have significantly reduced the cost of vulnerability discovery. Project Loupe, Bitcoin Red Team, and multiple developers have already used LLMs to scan open-source projects such as Bitcoin Core, producing more than 1,000 reports. Most were false positives or internal API issues, and Bitcoin Core has not identified any high or critical-severity vulnerability through these efforts so far. Gögge argued that longer-term security should focus on fuzzing, property testing, and automated testing rather than relying on one-off LLM scans.

Ethereum Classic experienced a social-engineering incident involving the Core-Geth client. An unreviewed ethereumclassic/core-geth v1.13.0 release was published on September 14 and promoted as a “security update” through @ETC_Network, CoinMarketCap community posts, and email, encouraging node operators to migrate. A small number of mining-pool nodes briefly switched to the release before returning to the long-maintained etclabscore/core-geth v1.12.23. No blocks were lost and no chain reorganization, fund loss, or service interruption occurred. However, the unreviewed release modified critical logic including chain selection and node discovery, creating a potential risk of network fragmentation.

Google released a Chrome Stable Channel security update fixing 12 vulnerabilities, including the high-severity V8 JavaScript engine type-confusion vulnerability CVE-2026–85046. Google confirmed that the vulnerability had been exploited in the wild but did not disclose attack methods or targets. Because browsers remain the primary runtime environment for many wallet extensions and Web3 front ends, affected users should update promptly.

Others

Zcash developer Sean Bowe said Zcash ecosystem development organizations and engineering teams have agreed on the scope and timing of the next network upgrade, NU7. The upgrade will reduce block intervals to 25 seconds, retire v4 transactions, and integrate NSM, without introducing a new transaction format. Testnet activation is expected on October 6, followed by mainnet activation on November 5. The upgrade is not expected to materially affect wallets, but full nodes, indexers, and block explorers may require advance preparation.

Cardano continued work on the Dijkstra Era and Ouroboros Leios implementation in September. Developers rewrote Leios data-download logic to limit time and memory consumption, added caching for recent Endorser Block transactions, and integrated Leios protocol parameters into the Dijkstra Era. The team also completed a batched validation path for Nested Transactions, allowing Plutus Scripts inside child transactions to execute while counting their execution budgets toward block and fee limits. Hydra received security fixes and completed a performance milestone. These efforts remain part of the engineering implementation and performance-validation phase ahead of Dijkstra / Leios mainnet deployment.

Decentralized privacy-computing network Nillion published a seven-stage roadmap for Encrypted Markets. The first phase, Dusk, launched on the Ethereum Sepolia testnet in August and is scheduled to reach Ethereum mainnet in the first week of October, while the first Covenants-based application is already available for testing. Later stages will expand to additional EVM chains, add cross-chain execution and user-defined conditions, introduce a dedicated programming language and virtual machine, and further improve post-quantum security and performance.

a16z crypto released the open-source zkVM Lattice Jolt, replacing the elliptic-curve-based Dory polynomial commitment with Akita, which is based on the Module-SIS lattice assumption. The design provides 128-bit post-quantum security while improving prover and verifier performance by around 2–3x and reducing proof size to below 100 KB. On the same MacBook, its CPU implementation can process more than two million RISC-V cycles per second, while Apple Metal GPU acceleration pushes throughput beyond 10 million cycles per second. Prover memory usage has also been reduced. The team plans to add zero-knowledge functionality and continue developing a hash-based version of Jolt.

Follow us

Twitter: https://twitter.com/WuBlockchain

Telegram: https://t.me/wublockchainenglish