BTC $80,805.11 +4.52%
ETH $2,517.81 +3.24%
BNB $715.95 +2.14%
XRP $1.52 +2.64%
SOL $101.52 +7.67%
TRX $0.3462 +0.87%
DOGE $0.0922 +0.59%
ADA $0.2274 +3.44%
BCH $278.98 +2.76%
LINK $11.83 +3.39%
HYPE $80.72 -0.10%
AAVE $134.69 -3.09%
SUI $0.8256 -0.53%
XLM $0.1988 +2.31%
ZEC $856.96 +2.15%
BTC $80,805.11 +4.52%
ETH $2,517.81 +3.24%
BNB $715.95 +2.14%
XRP $1.52 +2.64%
SOL $101.52 +7.67%
TRX $0.3462 +0.87%
DOGE $0.0922 +0.59%
ADA $0.2274 +3.44%
BCH $278.98 +2.76%
LINK $11.83 +3.39%
HYPE $80.72 -0.10%
AAVE $134.69 -3.09%
SUI $0.8256 -0.53%
XLM $0.1988 +2.31%
ZEC $856.96 +2.15%

upgrade

All
Article
Flash

Researchers disclose Solana PoH clock attack vulnerability: Transition risks remain unresolved before Alpenglow upgrade

According to CryptoSlate, researchers from USENIX Security have publicly disclosed a clock attack vulnerability targeting Solana's Proof of History (PoH) mechanism, which was privately reported to the Solana development team back in December 2025. The research shows that a malicious scheduler leader can manipulate the PoH logical clock by "re-anchoring," slowing down the advancement of logical time, thus gaining a longer transaction selection window in physical time, and isolating honest leader blocks using the TowerBFT fork choice mechanism, with the required staking ratio for the attacker being less than 33%.The Alpenglow security competition with a reward of 50,000 SOL under Anza concluded on August 19, but the vulnerability was excluded from the review scope due to the competition rules that state "actions that can only be triggered when Alpenglow is not activated." The Solana development team stated that they are aware of the related behavior, believe that the probability of the most severe scenario occurring under current conditions is low, and expect that the Alpenglow upgrade will fundamentally eliminate the prerequisites for the attack. Currently, the Alpenglow code has been included in the Agave 4.2 client but has not yet been activated on the mainnet, and is expected to go live with Agave 4.3. Until then, the transitional risk of this vulnerability has not been publicly analyzed or addressed at the implementation level.

GoPlus DeepScan has been fully upgraded, launching an AI intelligent contract security full lifecycle protection system

According to official news, GoPlus announced a comprehensive upgrade of DeepScan, launching an AI-based smart contract security solution. GoPlus stated that as hackers begin to leverage AI to dig deeper into contract vulnerabilities, the traditional "one-time audit, go live and it's done" security model is struggling to cope with the continuously evolving attack risks.DeepScan constructs a complete security closed loop around the entire lifecycle of smart contracts, consisting of AI contract auditing, continuous security monitoring, and Token security self-checks, providing ongoing security assurance for developers, project parties, and trading platforms. Among them, AI contract auditing can analyze contract source code, permission management, and business logic based on AI deep analysis, identifying security risks such as syntax vulnerabilities and business logic vulnerabilities, and outputting a structured audit report that includes security scores, key findings, problem details, and remediation suggestions. Continuous security monitoring targets contracts that are already live and have completed audits, tracking newly disclosed vulnerabilities, on-chain attack events, and changes in external dependencies such as oracles and cross-chain bridges in real-time, and using AI to determine whether the project is affected, conducting timely reviews and alerts. Token security self-checks are aimed at projects that are about to be launched or applying for listing, quickly detecting risks such as P2P pools/honeypots, malicious issuance permissions, blacklist mechanisms, abnormal transaction taxes, Owner permissions, and transaction restrictions.In addition, the GoPlus DeepScan team also released an open-source Benchmark dataset built on real smart contract attack events, used to assess AI's actual capabilities in vulnerability identification, attack path understanding, contextual reasoning, and audit stability. Currently, it has included nearly a hundred typical attack events since May 2025 and continues to be updated. GoPlus stated that DeepScan can be used for low-cost security scanning by developers, security reviews before project launches, and continuous monitoring during operations, while also serving as a supplement to security assessments before listing on trading platforms, helping all parties to more promptly identify new vulnerabilities and attack risks.

first_img The Ethereum Foundation has launched the Platåberget testnet for early testing of the Glamsterdam upgrade

The Ethereum Foundation's DevOps team announced the launch of the Platåberget testnet as an early public testing environment for the Glamsterdam (Gloas + Amsterdam) upgrade. This testnet is open to the community and is planned to run for several months, providing developers with a stable experimental platform to identify and fix issues before the upgrade is deployed to long-term testnets like Sepolia and Hoodi. The Glamsterdam hard fork is scheduled to activate on August 20 on this testnet.The Glamsterdam upgrade includes several significant changes to both the consensus layer and execution layer, including built-in proposer-builder separation (ePBS), block-level access lists (BALs), gas repricing targeting approximately 200 million gas, an increase in the maximum contract deployment size from 24KiB to 64KiB, an increase in the initcode limit from 48KiB to 128KiB, and forward-compatible consensus data structures. Relevant EIPs are summarized in meta EIP-7773. Gas repricing will affect wallets, indexers, and gas estimation tools, and any tools with hard-coded maximum gas limits will need to be updated; EIP-8037 also introduces an independent state gas dimension, where new accounts or writing to new storage slots will be charged by state bytes.The Platåberget validator set is small and allows public participation, supporting deposits from validators or builders submitted through the Dora browser. The testnet provides one-click resources to add networks, faucets, and client images. The community can provide feedback on issues in the Ethereum R&D Discord and related specification repositories.

The next Ethereum upgrade "Hegotá" has entered the planning stage, with 66 EIPs competing for a spot in the 2027 hard fork

Ethereum developer Toni Wahrstätter posted on the X platform that Ethereum core developers are planning the next annual upgrade "Hegotá," with 66 Ethereum Improvement Proposals (EIPs) currently on the candidate list. Future core developer meetings will screen these proposals to finalize the upgrade content that can be implemented, tested on the development network, deployed on the test network, and has the potential to go live in 2027. Proposals that do not make it into Hegotá will be postponed until the next hard fork, making the current screening process significantly impactful for Ethereum's future development direction.Currently, FOCIL (Fork-Choice Enforced Inclusion Lists) has been identified as one of the important upgrade contents for Hegotá. Developers believe that combining framework transactions (EIP-8141), keying Nonce (EIP-8250), and root references (EIP-8272) will help build native privacy capabilities, allowing privacy applications to operate without relying on third-party intermediaries. Additionally, enhancing scalability is also a crucial direction for Hegotá. Developers propose that it is necessary to prepare for a future increase in the Gas limit to 600 million by repricing data resources (EIP-8131, EIP-8279) and state growth costs (EIP-8368). Although these improvements are not as intuitive as privacy features, they are considered key work to promote Ethereum's scalability in the short term.Other candidate upgrades include shorter block times (EIP-8198), adjustments to the issuance mechanism (EIP-8363), anti-correlation penalty mechanisms (EIP-7716), EVM optimization and simplification, as well as discussions on the first EIPs related to zkEVM and quantum-resistant cryptography. It is reported that Hegotá cannot incorporate all the features the community expects, and the core team needs to make trade-offs between "future vision" and "near-term deliverable upgrades," with most candidate EIPs likely not making it into this upgrade. Currently, it has been 256 days since the launch of the current Glamsterdam upgrade, with the goal of completing deployment by the end of this year. Hegotá is planned to go live in 2027, and in the coming months, core developers and the community will discuss the priorities of various EIPs. Community opinions will still play a role in the screening process, and participants who support or oppose a certain EIP entering Hegotá can present their views to the core development team through public discussions.
app_icon
ChainCatcher Building the Web3 world with innovations.