Update: Action Plan Progress & v1.7.19-rc4 Deployment

To the Klever Community,

Here is the latest update on our continued action plan and network security enhancements.

1. v1.7.19-rc4 Deployment & Continuous Monitoring

As a direct result of our active monitoring efforts and AI-assisted exploit detection, we released version v1.7.19-rc4 this morning.

Our community validators immediately began upgrading their nodes. We want to take a moment to acknowledge this incredible display of agility, commitment, and engagement from our validator network.

Please note that our inspection and threat-detection work is continuous. We are keeping a strict watch on the network, and additional release candidate (RC) versions may be deployed as needed before we finalize the ultimate mainnet release.

2. Unregistered KLV Burn

We have successfully completed the development of the on-chain proposal procedure designed to safely burn the “unregistered” KLV.

We are now initiating the rigorous testing phase for this mechanism. Once all tests are validated, we will launch the proposal at the most opportune moment. As promised, this entire execution will be fully transparent, public, and verifiable on-chain.

3. Buyback Program

We are continuing to meticulously study the market dynamics to determine the most effective strategy for executing the Buyback Program. We will have concrete news to share on this front very soon.

Thank you for your continued trust and for standing alongside us. We will be back with more updates as soon as there are new developments to report.

Best,

Duka

3 Likes

Thanks for the continued updates, Duka — and credit to the validators for upgrading so quickly through each RC.

Two related questions on the security side, since the picture has shifted a bit since the first report:

  1. What does rc-4 specifically address? rc-3 came with a clear description (the split-royalty integer-overflow case), but rc-4 is listed only as “deployed” with no detail on what was fixed. Could you share what changed in rc-4?
  2. On “additional RC versions may be deployed as needed”: the original incident report described rc-2 as “the final fix for this vulnerability,” and since then we’ve had rc-3 and rc-4, with more possibly coming. Could you clarify whether these subsequent patches are addressing the same class of settlement/value-conservation issue (i.e. the rc-2 fix closed the specific attack path but adjacent cases are still being found and hardened), or genuinely unrelated, separate findings? I’m not raising this critically — the ongoing hardening and the move away from “final fix” language is reassuring — I’d just like an accurate read on whether the settlement layer is now considered fully closed or still under active review.

Appreciate the transparency.

Best, Burak

Hello @Burak_Kulaksizoglu sorry for delay…

We’ve just release a final .19 version. You can get all tech details at Release v1.7.19 - Marketplace & SFT Mint Security Release · klever-io/klever-go · GitHub

TY