Weekly Updates
QRL Weekly, 2026-August-14
Weekly Development Snapshot
Status / overview
- August 4th: Audit results published for go-qrllib
- April 3rd: Audit complete of 2 cryptographic libraries
- March 31st: QRL 2.0 Testnet V2 Released
- Audits: 50% completion
QRL 2.0 (Project Zond)
qrvmc
- Fix configure when Hunter is disabled
- Improve packaging and release metadata
- Bumped version into 2.0.0 and re-enabled it’s CI check
- Removed unused CI/CD configs like AppVeyor and Travis CI
- Require C++17 for example VM
qrvmone
- Updated to latest qrvmc submodule
qrysm
- Fix sync committee & aggregate tail signature ordering
- Remove unused AggregatePair helper
- Revert incomplete aggregate HTTP 404 port
- Transaction Batch Size reduced to 20 for minimal E2E transaction load
- Updated testnet script
- Derive Bazel DATE and DATE_UNIX from SOURCE_DATE_EPOCH when provided
qrl-tests
- Simplify CI concurrency key
- Add CI validation for pull request
- Add development network and ABI suite
QRL 1.0
- Added tests for grpc_proxy
- Optimized grpc_proxy to avoid triggering grpc response limit
- Updated requirements.txt to fix flask dependency issue caused by incompatible version of Werkzeug
QRL Weekly, 2026-August-07
Weekly Development Snapshot
Status / overview
- August 4th: Audit results published for go-qrllib
- April 3rd: Audit complete of 2 cryptographic libraries
- March 31st: QRL 2.0 Testnet V2 Released
- Audits: 50% completion
QRL 2.0 (Project Zond)
qrl-web3-wallet
- further security-audit remediation and code-review fixes
- corrected address display and updated documentation
web3.js
- updated CI actions and patched vulnerabilities affecting fast-uri, PostCSS, SVGO and brace-expansion
js-qrl-cryptography
- updated pinned GitHub Actions and the fast-uri dependency
go-qrllib
- updated pinned GitHub Actions and opened further test-related work
qrypto.js
- updated development dependencies, lockfiles and CI actions for mldsa87
qrvmc
- Harden hex parsing, example VMs, and loader
- Tighten gas validation, loader TLS and ABI docs
go-qrl
- –bootnodes flag now override config value
- Go toolchain updated to 1.26.5
- external function values updated to 64-byte address plus a 4-byte selector
- Removed legacy local testnet script (now being moved to new repo qrl-tests)
- Several other bug fixes
qrysm
- Updated tests
- Go toolchain updated to 1.26.5
- Updated QRL dependencies
- Update the staking deposit CLI default to the valid deposit contract address
- Default address aligned with the Qrysm network config
- Fix Zond consensus version descriptor
web3.js
- ICAP and IBAN support removed as those are deprecated
- Added 64 byte topics and 512-bit integers data type
qrl-package
- Changes merged related to 64-byte address
QRL 1.0
dice
- 2018 Python script rewritten as JavaScript application
- session isolation, CI and browser end-to-end tests
- a verifiable single-file offline release
qrllib
- added RNG-regression protection
- modernised Emscripten support
- migrated release processes to GitHub Actions
- added trusted publishing and npm/PyPI deployment
- v1.2.6 released
offline-wallet-generator
- merge of v3 wallet format with stronger encryption and password security
- added reproducible offline builds, CSP tests and a security-focused CI/release pipeline
qrl-wallet
- 7 issues closed
- continued UI refinements
- gated multisig signing on validation and tighter OTS-reuse checks
- applied security hardening and documentation updates
- v1.9.1-beta in pre-release
qrllib-browserify
- updated support to Node.js 22+
- rebuilt the bundle for qrllib 1.2.6 and corrected module export and Browserify interoperability
qrl-cli
- replaced the aes256 dependency with scrypt-derived AES-256-GCM encryption while retaining compatibility with legacy wallet files
QRL Weekly, 2026-July-31
Weekly Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
QRL 2.0
go-qrl
- Added several upstream go-ethereum fixes with tests
QRVMC & QRVMONE
- Both are still being reviewed for bugs, issues and further changes related to 64 bytes word size
qrl-web3-wallet
- 64 byte address changes
- First phase security-audit remediation; code-review fixes; address-display correction; documentation updates;
Other
- Hardhat like tool documented & is currently being tested
QRL Weekly, 2026-July-24
Weekly Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
web3.js
- Audit remediation; keystore cryptography hardening; removal of import cycles; coverage gates; reproducible supply-chain checks; dependency overrides; CI timeout and build-order fixes
- 20 constituent packages released 🎉
rust-qrllib
- Refactored the demo build, aligned documentation with go-qrllib, and updated demo dependencies and TypeScript configuration
QRL Weekly, 2026-July-17
Weekly Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
Qrvmc
- Several bug fixes like VM bounds checks for PUSH and memory expansion, loader config boundary and precompile sweep coverage etc.
- Updated and added new test cases
- Reviewing qrvmc to ensure changes made in Hyperion also align with qrvmc
go-qrl
- Unused ECDSA signatures are removed
- Added Local testnet setup script using kurtosis
- Move typed-data encoding to the QRL 64-byte model
- go-qrl still being reviewed for 64 bytes related changes
web3.js
- Migration to 64-byte QRL addresses and 64-byte VM words; supply-chain and dependency hardening; CI fixes; Turbo and GitHub Actions updates; Node 20 compatibility
- Further audit work underway
js-qrl-cryptography
- Added and exported SHAKE256 with selectable output length, test vectors, packaging tests and documentation
qrypto.js
- Dependency and GitHub Actions updates, including Turbo and Zizmor
qrl-web3-wallet
- Bound dApp signing and transaction requests to the authorised chain, with chain-context revalidation and tests
theqrl.org
- Added llms.txt along content-negotiation to serve content as markdown files for better LLM support
qrl-wallet (QRL 1.0)
- Prevented custom-node connections unless enabled; synchronised mainnet and testnet branches
QRL Weekly, 2026-July-10
Weekly Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
64 byte addresses
- Added 64 bytes address related changes to Hyperion
- go-qrl is still being fixed with changes related to 64 bytes address
P2P Layer
- Falcon-1024 added in go-qrllib
Hyperion/qrvmc
- Added & updated several test cases for Hyperion
- Reviewing qrvmc to ensure changes made in Hyperion also align with qrvmc
QRL Weekly, 2026-July-03
Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
64 byte addresses
- Most of the changes related to 64 bytes address done for Hyperion.
- go-qrl is currently being fixed with some remaining changes related to 64 bytes address.
Tooling
- Hardhat like tool is being developed for the QRL 2.0 along with the documentation.
P2P Layer
- Falcon-1024 PR is still being reviewed.
QRL Weekly, 2026-June-26
Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: 50% completion
64 byte address
- 64 bytes address related changes done for hypc-js, qrl-contracts, go-qrl & qrysm
- changes in progress for hyperion related to 64 bytes address
P2P Layer
- Falcon-1024 PR is still being reviewed
QRL Weekly, 2026-June-19
Weekly Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: Internal and External work ongoing
64 Byte addresses
- 64 bytes address related changes done for qrvmone, qrvmc
- hyperion is being reviewed for 64 bytes address related changes
P2P Layer PQ Implementation
- Falcon-1024 has been implemented and PR is currently being reviewed
Daniel Bernstein’s “Exploiting ML-DSA Bugs” review
The QRL ML-DSA implementation is not broken and is not at risk from any of the three forgery attacks described in the paper. Each attack relies on a specific implementation bug; we checked for all three at the bit/byte level, confirmed each is absent, and corroborated the findings with empirical probes and the existing test suite.
| # | Attack in the paper | Underlying bug it needs | Present in go-qrllib? | Outcome |
|---|---|---|---|---|
| 1 | Secret-key recovery from masks | Duplicated mask coefficients ( AABBCC / A0B0C0 / ABABCDCD ) | No | Not exploitable |
| 2 | Predictable signatures | Secret seed K zeroed/cleared before use | No | Not exploitable |
| 3 | Nonce-reuse forgery | Repeated nonces from a truncated seed hash | No | Not exploitable |
To guard against such bugs being introduced into the codebase in the future, we added specific regression tests.
Additional CVE review (ML-DSA Timing)
We additionally confirmed that the most recently disclosed ML-DSA timing vulnerability (Decompose, CVE-2026-22705) is not present.
QRL Weekly, 2026-June-12
Weekly Development Snapshot
Status / overview
- April 3rd: Audit complete of 2 cryptographic libraries.
- March 31st: QRL 2.0 Testnet V2 Released.
- Audits: Internal and External work ongoing
go-qrllib
- ML-KEM-1024 changes merged
- Dilithium5 removed, with CI enhancements
- Falcon-1024 implementation is in progress
64 bytes address
- Migration to 64-byte addresses merged for go-qrl
- 64-byte word accounting now used across QRVM gas and tracers
- 64-byte address changes merged for go-qrllib qrvmc
Join our mailing list, contact the team or join our vibrant and friendly community of users, developers and enthusiasts on Discord or one of our other social channels