Final Update: Full Ecosystem Restoration, v1.7.20 Release & Closing the Loop

To the Klever Community,

Thanks to our active monitoring, AI-assisted exploit detection, and the fundamental partnership and auditing by CertiK, we have successfully launched the final mainnet version v1.7.20.

Our community validators performed the update immediately, which is an incredible demonstration of agility, commitment, and engagement. All partner exchanges have also been notified and confirmed their upgrades, effectively covering our entire network of validators, node operators, and exchanges.

Because this is our final formal action plan report regarding this specific incident, we want to ensure every open loop is closed, addressing everything we have discussed since Day 1.

1. v1.7.20 Release Details & Continuous Security

  • This release remediates the CertiK protocol audit findings (KLR series) together with seven coordinated-disclosure security advisories.

  • These advisories consist of one Critical and six High severity vulnerabilities.

  • The applied fixes span across consensus signature validation, account permissions, the native marketplace, the KVM execution layer, the REST/WebSocket API, and the indexer.

Please note that our work in inspection and threat detection is continuous. We are actively processing all findings from CertiK, and if any critical issues are identified in the future, we will not hesitate to deploy release candidate (RC) versions prior to final mainnet releases to ensure network integrity.

2. Protocol Security: The “Sanitary Check” Pivot

In previous updates, we discussed implementing a native “Sanitary Check” to automatically revert anomalous transactions. During development and testing, the initial implementation strategy for this specific rollback mechanism did not prove effective.

While we are still designing new ways to protect the network and potentially revert identified anomalies, we have pivoted our engineering strategy. Our primary focus is now on strictly preventing these transactions from occurring in the first place. The hardened validation logic and defense-in-depth measures shipped in v1.7.20 reflect this priority, stopping bad state transitions at the gate rather than trying to clean them up after the fact.

3. Full Ecosystem Restoration

We have successfully re-enabled the KLV → ETH direction of the bridge. With this final step, we are officially registering the complete and functional return of all products within the Klever ecosystem.

4. Supply Reconciliation, Buyback & Voluntary Burns

We made several commitments regarding the network’s supply, and here is how they will be executed together:

  • Unregistered KLV Burn: We have concluded the development of the on-chain proposal procedure designed to permanently burn the “unregistered” KLV without breaking the network’s supply math.

  • Genuine Voluntary Burn: As discussed with the community, we are still fully committed to executing a voluntary burn of an equivalent amount from our own team/treasury reserves, as well as utilizing the accumulated KLV from the genesis validators’ rewards.

  • Buyback Program Status: The token buyback program remains under rigorous legal analysis to avoid legal risks. The process is being evaluated by legal and accounting departments because it involves legal complexities, risks of market manipulation, and the preservation of evidence of crimes related to the previous attack. The program is currently being structured, and no actions will be taken until there is total clarity regarding legal guidelines.

  • Execution Strategy: To ensure maximum market efficiency and transparency, the Unregistered KLV Burn, the Voluntary Burn, and the Buyback Program will all be executed concurrently once legal clearance is granted. Both events will be triggered together, and the process will be entirely public and verifiable on-chain.

5. Criminal Investigations & Frozen Funds

We have not forgotten about accountability. The ~136M KLV we successfully intercepted and froze in the attacker’s wallets remains locked. The funds routed to exchanges (such as the confirmed deposits on KuCoin) also remain frozen. Formal criminal proceedings and our collaboration with exchange security teams (including KYC tracking) remain highly active. These investigations are strictly confidential to protect the legal process, but they are ongoing.

We want to deeply thank you for your trust, patience, and vigilance throughout this recovery process.

As stated, this is the final formal report regarding the immediate response and action plan for this exploit. The remaining actions, specifically the combined buyback and burn execution, as well as any major investigative breakthroughs, will be widely communicated as standalone announcements across all official channels the moment they occur.

3 Likes