0
Teams
0
GitHub Links
Link Types:GitHubInternal (roadmap.vac.dev)ExternalTask ID

IFT-TS 2026/08/17

top highlights

  • P2P team released nim-libp2p v2.3.0, v2.2.2, and v2.1.6.
  • SEC team contained and remediated a DPRK-linked supply-chain compromise across three vacp2p repositories.
  • WEB team published the Past Present Future experience with analytics, production media fixes, and anchored navigation.

team highlights

  • DST: Completed the 1,000-node Kubernetes matrix for nim-libp2p v2.3.0 and verified two Kademlia bootstrap fixes.
  • DST: Confirmed RLN proof generation is CPU-frequency-bound and added verification panels.
  • DST: Deployed a dedicated VacLab NTP server and updated the DST dashboard.
  • DST: Advanced service-discovery analysis across redeployed StatefulSets.
  • NIM: Added local and global package-refresh flows to Nimble.
  • NIM: Landed nim-taskpools v0.2.1 integrations and fixed a scheduling race that caused hangs.
  • NIM: Advanced JSON-RPC cancellation, error propagation, and v0.7.0 release work.
  • NIM: Reworked nim-web3 error handling with checked raises.
  • NIM: Completed follow-up documentation for protobuf editions and enums.
  • P2P: Released nim-libp2p v2.3.0, v2.2.2, and v2.1.6.
  • P2P: Completed the Logos Core node-management UI with settings, validation, DHT improvements, and traffic metrics.
  • P2P: Improved Kademlia routing-table resilience, admission probing, address classification, and stream reuse.
  • P2P: Stabilized the nim-ffi event, lifecycle, header, ingress, and payload contracts.
  • P2P: Implemented the address-manager verifier and ownership model.
  • P2P: Created the repositories needed to build a Logos Core Mix/RLN module.
  • QA: Expanded Logos Basecamp persistence, unload, and failure-path coverage.
  • QA: Extended nim-lsquic coverage and reported transport-parameter, ALPN, and stream-credit issues.
  • QA: Added AutoTLS retry, broker, issuance, and renewal coverage.
  • QA: Expanded Status Desktop benchmark support for pull requests and releases.
  • QA: Added Status Desktop Keycard simulator coverage for login, management, and re-authentication.
  • QA: Ported channel-delivery tests and advanced sharding-suite and nightly E2E recovery.
  • SEC: Contained a DPRK-linked supply-chain compromise and remediated affected repository histories and credentials.
  • SEC: Surfaced seven new internal-audit findings across Logos Messaging, Logos modules, and Logos Execution Zone.
  • SEC: Reported a high-severity Logos Execution Zone block-production finding.
  • SEC: Reviewed and merged Logos Storage security fixes.
  • TKE: Wrote the Logos token-unit precision specification with the Blockchain team.
  • TKE: Corrected the block-rewards formula and wrote a new specification.
  • TKE: Completed an SNT incentives impact analysis.
  • TKE: Continued XPrize reviews and planned KPI-based prizes.
  • TKE: Advanced wrapped-assets research, case studies, and bridge RFP support.
  • WEB: Published the Build the Parallel landing page with Umami analytics.
  • WEB: Published the Past Present Future experience with analytics, production media fixes, and anchored navigation.
  • WEB: Published the final Logos roadmap design.
  • WEB: Advanced the Logos CRM MVP with a specification, demo, and preview deployment.
  • WEB: Protected newsletter unsubscribes with signed links and POST-only handling.
  • WEB: Added per-account persistence for Status Wallet Extension dApp connections.

ift-ts:dst:

ift-ts:nim:

ift-ts:p2p:

ift-ts:qa:

ift-ts:sec:

  • ift:2026q3-vulma-and-ir:incident-response-and-bounty-triage
    • Contained a DPRK-linked supply-chain compromise in universal-connectivity caused by hidden zero-parent orphan commits carrying an implant.
    • Restored affected histories in universal-connectivity, p2p-pm-report, and research.logos.co.
    • Traced the incident to npm malware and a stolen HTTPS token, revoked sessions and credentials, collected forensics, and enabled commit-signing enforcement on main branches.
  • ift:2026q3-cicd-security-review:code-review-activities
    • Completed post-merge security reviews of Status Go account derivation and Status App Keycard simulator changes.
    • Reviewed security-relevant messaging, SDS, transaction logging, biometrics, wallet-token, and browser-download changes.
    • Reviewed open Status Go and Status App carry-overs and continued triage of the Keycard EIP-7702 dispatch gap.
    • Queued the merged status-keycard#126 Schnorr key-tweaking change for a post-merge pass.
  • ift:2026q3-vulma-and-ir:alert-triage-and-remediation
  • ift:2026q3-internal-audits:logos-and-keycard-followup
    • Surfaced seven new internal-audit findings: three in Logos Messaging, three in Logos modules, and one in Logos Execution Zone.
    • Continued follow-up on critical, high, and medium findings and coordinated Logos Execution Zone remediation ownership.
  • ift:2026q3-cicd-security-review:keycard-audit-follow-up
    • Continued validating open Keycard findings covering non-constant-time math and recomputed Schnorr keys.
    • Synchronized with the Keycard team on the remaining items.
  • ift:2026q3-secure-treasury-management:operational-continuity-management
    • Continued runbook definitions and updates based on the first live secure-multisig-signer signing.
    • The master-wallet-index reconciliation remained blocked because the repository was inaccessible through the API and signatory removal was unconfirmed.
    • The Finance Safe multiviewer repository remained inaccessible, blocking review of its E2EE Matrix integration.
    • Continued backup-signatory selection with the investment team.
  • ift:2026q3-policy-and-process:access-and-policy-management
    • Reviewed pending PAT requests and iterated on the security checklist and Copilot policy.
    • Performed access-review and revocation sweeps tied to the DPRK incident response.
  • ift:2026q3-threat-intelligence:supply-chain-attack-research
    • Continued monitoring npm, OAuth, and CI-tool supply-chain campaigns and incorporated indicators into IFT defensive recommendations.
    • Continued DPRK campaign analysis and documented it in Notion and GitHub.
  • ift:2026q3-finance-automation-bug fixing & support
    • Monitored Finance executions daily and provided support and bug fixes.
  • ift:2026q3-security-automation:refine -app-catalogue-update-from-expensify
    • Monitored duplicate-data scenarios daily.
  • ift:2026q3-security-admin
    • Prepared a handover and discussed date corrections.
  • ift:2026q3-internal-audit:logos-storage-security-review
  • ift:2026q3-internal-audit:logos-execution-zone-security-review
  • ift:2026q3-internal-audit:logos-testnet-security-review
    • Reviewed the Coldcard article for Status and documented the review in Discord.
    • Continued threat modeling Cryptarchia consensus, Mantle execution, P2P, Blend, Logos Execution Zone, Logos Storage, and Logos Messaging.
  • ift:2026q3-internal-audit:logos-liblogos-security-review
    • Reported two libp2p-mix findings, one Logos RLN module finding, and two nim-sds findings.
    • Followed up through pull requests #48 and #49.

ift-ts:tke:

  • vac:tke:ift:logos-token:token-unit-precision
    • Wrote the specification and discussed it with the Blockchain team.
  • vac:tke:blockchain:pow:new-rewards
    • Fixed the block-rewards formula and wrote a new specification.
  • vac:tke:keycard:incentives:snt
    • Collected data and performed an impact analysis.
  • vac:tke:ift:ecodev:market-validation
    • Continued helping EcoDev reach out to projects.
  • vac:tke:ift:ecodev:xprize
    • Continued reviewing submissions and discussed new and KPI-based prizes.
  • vac:tke:ift:ecodev:wrapped-assets
    • Researched wrapped assets, prepared a swap proving-and-relay case study, and supported the bridge RFP.
    • Continued prize research and support.
  • other notes
    • Reviewed communications event plans and their Lambda Prize elements and began drafting new prizes.

ift-ts:web: