A note on our testing program

kev_larFounder & Lead Developer

⚠️ Not financial advice. This post is for informational and educational purposes only. Forecasts and commentary are model outputs and opinions, may be inaccurate, and are not a recommendation to buy or sell any security or asset. Do your own research. AI-assisted: this article was drafted with AI and reviewed by a human before publishing.

A security guard in a pristine laboratory holds a clipboard while two identical # A note on our testing program

We have ended two testing-program accounts for breaching the program's disclosure terms.

Our testing program gives a small number of people authorized access to look for weaknesses in the platform before anyone else finds them. It is a good arrangement and it works. It rests on one term above all the others: anything you find, you tell us promptly. In this case, findings were held for roughly 24 hours before they reached us. That is a breach of the terms the access was granted under, and both accounts have been removed.

What this was, and what it was not

We want to be precise here, because "we removed two accounts" reads worse than what happened.

The individuals involved were authorized testers doing work we asked them to do. They were looking for problems because we invited them to look for problems. They found some. The issue is the delay in telling us, not the looking, and not the finding.

Specifically:

  • No member account was accessed. No balances, no personal data, no private research.
  • No KVL moved. The token, the treasury and the liquidity pool were untouched throughout.
  • Nothing was exploited against the platform or against a member.
  • The findings reached us and have been addressed.

There is no action for you to take. No password to reset, nothing to check.

Their own tokens are their own

Removing an account does not give us a claim on what that account holds. Both individuals had bought KVL on the open market and brought it onto the platform, and that is their property. They were free to withdraw it in full, and they did.

We think this is worth stating plainly rather than leaving it to be assumed. Ending someone's access over a breach of terms is a decision about access. It is not a licence to keep their money, and a platform that blurs those two things is not one anybody should hold a token on.

Why a day matters

Twenty-four hours is not a long time, and we know that. Plenty of security work runs on far longer clocks; coordinated disclosure between researchers and large vendors is often measured in months.

But our program is not coordinated disclosure with a stranger. It is a standing grant of authorized access on the understanding that findings come to us as they are found. The window between a weakness being known and being fixed is the only window in which it can be used, and the whole point of the arrangement is to keep that window as close to zero as we can make it. A day is a long time to hold something that is significant enough to matter, when the people who can fix it are one message away.

We are not making a claim about anyone's intent. We do not know what the delay was for and we are not going to speculate about it in public. The term exists so that we do not have to.

The program continues

This has not changed our view of the testing program, which has been worth every bit of access it costs. Finding problems before they find our members is exactly the work, and we would rather run the program with clear terms and enforce them than run it with vague ones and hope.

If you test for us: keep doing it, and tell us the moment you have something. That is the whole deal, and it is the part we will be strict about.


Market commentary from the K3vl4r desk — not personalized investment advice. More posts →