
Kasplex released the fixed version of its KRC-20 indexer on 3 October. The indexer is the software that reads KRC-20 token transfers from Kaspa transactions and keeps track of who owns which token. The new version closes the gap an attacker used on 20 September to take ZEAL and NACHO tokens from a bridge (Kasplex, earlier report).
A day earlier, Michael Sutton proposed a way for anyone to check which code is behind a covenant on Kaspa. Sutton has also sent his full answers to the KOB order book questions covered here on 1 October, and the change that lets wallets load their coins in pages was marked ready by its author. Kasshi and KaChat released updates, and the mining reward drops on 5 October.
What the KRC-20 fix changes
The new version, 3.01.260930, is stricter about who sent a token transfer. It counts a transfer only if it is written in the standard form. In that form, Kaspa accepts the transaction only when the owner's signature is real. Transfers written any other way are now ignored (code change, release).
Kasplex asks everyone who runs their own copy of the indexer to stop it, delete its data and start it again. The indexer then reads the whole token history again under the new rules.
The public Kasplex service already runs the new version. It came back online on 1 October, after Kasplex rolled back and rechecked its token records (service status, Kasplex, 1 October). A transfer the attacker forged on 20 September no longer appears in those records (lookup).
The recovery plan is still being worked out
The code fix does not settle the losses. KAT, which runs the bridge the attacker used, said on 1 October that ZEAL and NACHO are the only two tokens affected as far as the bridge is concerned. The bridge stays offline at least until the community approves a recovery plan, and KAT still advises people not to trade KRC-20 tokens until then.
KAT is waiting for a recovery plan from ZealousSwap. According to KAT, NachoNation will hold calls over the next week or so to agree on a plan together, and a decision by Igra's DAO about the funds Igra recovered also has to be part of it (KAT).
ZealousSwap said on 29 September that trades made on Igra and Kasplex L2, two networks built on top of Kaspa, will not be reversed. On Igra, about 88.5 percent of the 1.97 million iKAS taken from the affected trading pools has been returned or is covered by bridge payouts that were held back. About 724,000 iKAS has come back, and a 1 million KAS withdrawal that never reached the attacker is held in escrow. The plan for ZEAL is still being worked on (ZealousSwap).
A way to check a covenant's code
On 2 October, Michael Sutton proposed genesis proofs for Argent, the contract language he is building with IzioDev. A covenant is a set of rules attached to coins on Kaspa, and it is how contracts work on the network. Every covenant has an ID, but the ID alone does not show which code is behind it or how it started.
A genesis proof packs the covenant's code together with the details of how it was launched. Anyone can use it to calculate the ID again and compare the result with the ID their own Kaspa node shows. If the two match, the code and starting values in the proof are the ones the covenant really uses (proposed change).
Sutton wrote that he expects "every stateful covenant deployed on Kaspa to provide such a genesis proof". A stateful covenant is one that keeps data, such as balances, and updates it over time. He compares the idea to Etherscan, where anyone can read the code behind an Ethereum contract, and wants block explorers to show these proofs for every covenant whose creators want public trust ([1], X post).
He named Supertypo's dotk name registry as an early example of a covenant launched with its starting data published (dotk launch data). The proposal is still waiting for review, and Argent has not had its first release yet.
Two shared rulebooks for covenants also moved forward. On 1 October, KCC-1, which sets out basic covenant terms and data layouts, and KCC-2, which sets out how a covenant names who controls it, entered last call, the final review stage (KCC list). KCCs are agreements that apps can follow so they work together. They do not change Kaspa itself.
Sutton answers the KOB questions
Michael Sutton has sent the full answers he promised to Ross Ku, whose team builds KOB, a third-party order book on Kaspa. Ross's questions about building KOB with Argent were covered here on 1 October (answers, earlier coverage).
On the payment problem, Sutton said each app has to make sure one payment cannot count for two orders, as Ross had already done by giving each order its own payment slot. He did not see an easy way for Argent to do this automatically. He also said Argent will be able to handle a changing number of orders in one transaction before its first release, while splitting a large contract into smaller pieces for each action may come later.
Ross said his team would reply in detail within a few days. He also cleared up one point. The browser version of the Argent runtime he had mentioned was one his team built themselves, not part of the Argent project (reply).
Loading wallet coins in pages is almost ready
The Rusty Kaspa change that lets wallets load their coins a page at a time, covered here on 1 October, is ready from its author's side. D-Stacks tested it with the command-line wallet on 3 October. He asked others to try it and review it once more, but said he was happy for it to be added to the node software as it is ([2], proposed change, earlier coverage).
The mining reward drops on 5 October
On 5 October at 03:25 UTC, the reward for each new block drops from about 2.18 KAS to about 2.06 KAS. Kaspa lowers the reward a little every month, so that it halves once a year (schedule). With about ten blocks every second, the network will create about 1.78 million new KAS a day instead of about 1.89 million.
Miners will get about 5.6 percent fewer KAS for the same work. What that means in money depends on the KAS price and the cost of power. On 3 October, DailyKaspa reported that mining income for the same amount of computing power was already slightly below its average for the past 30 days (DailyKaspa).
New in Kasshi and KaChat
Kasshi, a video site where viewers pay creators in KAS, released its biggest update so far on 2 October. Creators can now let viewers watch between 15 seconds and five minutes of a paid video before paying. Channel members get a private space with group chat, polls and pinned posts, and users can send each other private messages. Creators also get a page that lists every payment, and the Kaspire wallet now works for sign-in next to Gmail, KasWare and Kastle. Kasshi says creators keep 95 percent of every payment (Kasshi).
KaChat, an encrypted messaging app where your Kaspa wallet is your identity, released version 5.1 on all platforms on 3 October (KaChat). For version 5.2 it plans .kachat names that are rented for one or two years at a time, not owned forever like dotk names. Renewal costs the same as the first purchase, there is a ten-day grace period, and the fees go to miners. Profile pictures would come from a linked X, Instagram or YouTube profile instead of being stored with the name (plan, dotk).
Kaspa Silver, who builds KaChat, says renting stops people from buying up names and holding them hostage (reason).
Research into private KAS payments
Olaf Weller started an open research project on 2 October. It asks whether people could choose to send KAS privately, without a new token and without giving their coins to someone else to hold. He compares three possible designs and has not picked one (Kas-Smiths post).
Weller says he is not a cryptographer or a Kaspa core developer, and that his role is to organise the work and bring in people who understand each part. He is asking for criticism before anyone writes serious code (project).
Telegram sources link to public messages in the Kaspa Core R&D (public) Telegram channel.

