Klever Blockchain Product Update #8: Expanding the Security Scope (Sprint 103 Review & Sprint 104 Planning)

Hello, Klever Community.

We are continuing our bi-weekly commitment to absolute transparency regarding the planning, execution, and strategic pivots of the Klever Blockchain.

As previously communicated, the advancement of our planned 2026 roadmap features remains strictly suspended. Sprint 103 was executed with a total and unrestricted focus on network security, deep monitoring, and infrastructural robustness. This exact same focus is being applied to our current cycle, Sprint 104.

We are giving absolute priority to completing the remediation of the CertiK audit findings and protecting the stability of the blockchain before we expand any product fronts. All our actions are directed toward expanding the robustness and security of the network to prevent any future vulnerabilities.

Important Pivot: We have received an additional report with new findings from CertiK. This has subsequently expanded our scope of work and our security timeline. We currently believe that in approximately 2 to 3 more sprints, we will gradually create the space to resume actions directed at realizing our 2026 roadmap. When that time comes, we will carefully analyze and communicate the impacts this extended security pivot has caused to the overall 2026 timeline.

Important Milestone Achieved: We are proud to announce that one of the primary goals of Sprint 103 was successfully met. The v1.7.21-RC1 (Release Candidate 1) was successfully launched for our validators, containing all the critical remediations developed to date. For Sprint 104, we are planning the release of RC2, which will contain even more corrections, moving us closer to a final version that we believe will cover all CertiK findings identified to date.

It is important to reinforce that all critical corrections found by CertiK have already been patched and deployed to production. We are currently working on findings with a lower security impact, yet we are still giving them absolute priority. We are continuously updating validators via RC versions and will release these to the general public as soon as we close a verified package of resolved findings.

CertiK continues to be fundamental in assisting us with this security work, helping us expand our robustness, and anticipating potential attack scenarios. We are sparing no effort to build an increasingly stronger, more reliable, and robust network in this era of continuous, AI-coordinated attacks.

Here is a transparent breakdown of what we delivered in Sprint 103, and the aggressive hardening we are executing right now in Sprint 104.

:locked_with_key: Epic 1: Proof of Security Audit (The Core Focus)

  • Sprint 103 (Delivered): This epic was the core focus of the sprint, successfully closing 9 complex security tickets. The team delivered highly technical remediations that directly removed risks in some areas. Crucially, to translate these code fixes into operational security, we delivered a comprehensive Hardening Guide for Node Operators, detailing secure configurations for REST/WS exposure, TLS, authentication, and reverse proxies.
  • Sprint 104 (Planned): This epic remains our dominant focus, representing the vast majority of our planned effort with 12 specific CertiK audit bugs targeted. We are focusing on closing out the remaining lower-impact findings. Because these findings vary in severity and correction strategy, we are ensuring strict criteria are met for each fix, including evidence of testing, independent review, and CertiK retesting when applicable. (Note: Specific technical details of these active patches are being withheld until the corrected versions are fully deployed to protect the network).

:shield: Epic 2: Improve Security & Vulnerability Defense

  • Sprint 104 (Planned): We are pushing a high-priority peer-to-peer (P2P) hardening update across the finish line. This sprint, we are imposing strict parameters on node communications and enforcing inbound connection limits. This directly mitigates external stress vectors and prevents the exhaustion of our network resources from malicious actors.

:gear: Epic 3: Core Infrastructure & Maintenance

  • Sprint 103 (Delivered): We executed necessary operational adjustments, including the successful removal of a specific wallet block related to previous hack remediations.

:hammer_and_wrench: Epic 4: Ecosystem Tools & Releases

  • Sprint 103 (Delivered): Most importantly, we successfully delivered and launched the v1.7.21-RC1 release to our validators.
  • Sprint 104 (Planned): Our primary integration milestone for this sprint is validating the v1.7.21-RC2 for a controlled rollout. This RC will consolidate our prioritized remediations and undergo rigorous testing.

:bullseye: Consolidated Closing: Our Commitment to You

Sprint 103 advanced consistently in reducing risk surfaces and delivered a vital Release Candidate, with special merit given to the completed CertiK corrections and the node hardening documentation.

However, our work is not yet finished. Sprint 104 is heavily dedicated to closing out the remaining in-flight security remediations, strengthening validator and P2P reliability, and enforcing marketplace transfer integrity. By prioritizing the v1.7.21-RC2, we are ensuring that these critical fixes are thoroughly tested and verified before a final, public rollout.

While the new CertiK report has extended our security timeline, it has also ensured that the Klever network will emerge stronger than ever. We will continue to prioritize the security and stability of the Klever network above all else.

Thank you for your unwavering trust, your understanding of these necessary security precautions, and for building alongside us.

1 Like