

# QRL Weekly, 2026-September-18

> For the complete documentation index, see [llms.txt](/llms.txt). This markdown page mirrors [the canonical HTML page](/weekly/2026-september-18/).





Published: 2026-09-18
Updated: 2026-09-18



Author: The QRL Core Contributors
















Weekly Development Snapshot Status September 18th: QRL Release Verifier audit complete September 11th: Ledger app audit along with its remediation is complete August 4th: Audit results published for go-qrllib April 3rd: Audit complete of 2 cryptographic libraries March 31st: QRL 2.0 Testnet V2 Released Audits & Remediation: 60% QRL 2.0 Testnet V3 remaining work:
Config parameters Upstream bug fixes Testnet V2 scoped audits complete QRL 2.0 qrysm
EpochsPerSlashingsVector is now 512 - 45 days, 12 hours, 16 minutes fix(builder): raise execution payload response limit to 32 MiB fix(config): reject malformed YAML without partially applying overrides as well as validate values for some config parameters fix(sync): prevent zero polling intervals for one-slot epochs Reject empty signature groups and nil public keys, which was being accepted earlier Remove unbounded ML-DSA public key cache, fixing memory leak Prevent panics on malformed ML-DSA signature batches Reject all-zero-t1 ML-DSA-87 public keys Reject nil inputs and validate fork domain lengths Optimization: avoid redundant sync signature checks in replay and block proposals Wire the keymanager RPC to a beacon client so voluntary exits can sign Optimization: reject invalid gossip before costly attester signature checks Verify gossip signatures independently with bounded workers Bound signature diagnostics and avoid duplicate verification An empty execution payloads doesn’t necessarily mean empty withdrawal More tests added qrl-genesis-generator
Execution voting period updated to 4 web3.js
Removed deprecated RPC APIs Replace Ethereum EC precompile gas with gqrl depositroot and mldsa87Verify costs Set Common initialBaseFee to 100 gwei so genesis fee math matches go-qrl Type FeeHistory.baseFeePerGas as an array because go-qrl returns one value per block qrypto.js
Added weak public-key and invalid secret-key validation for ML-DSA-87, plus bounded signing behaviour and corresponding documentation/tests js-qrl-cryptography
Updated @theqrl/mldsa87 to v2.2.0 to pick up the new validation behaviour web3.js
Updated QRL cryptography/wallet dependencies and raised dependency patch floors for multiple known CVEs and security advisories go-qrllib
Added ML-DSA-87 weak-key rejection and secret-key checks; moved verification toward validated PublicKey objects; expanded lifecycle tests/docs; updated Go security-check CI go-qrl
Updated to go-qrllib 0.9.2 then 0.10.0 and enforced validated ML-DSA-87 public keys in the verification precompile rust-qrllib
Added a validated ML-DSA PublicKey type and weak-key rule actions-mldsa-sign
v2 release: GitHub Action to generate ML-DSA-87 (FIPS 204) post-quantum signatures for files, and a signed manifest binding each artifact to the release it belongs to. QRL v1.0 qrllib
Hardened key-material and entropy handling; improved cross-platform native testing and Go symbol isolation; made XMSS signing allocation-failure safe; fixed XmssFast copy/move state; prepared the v1.3.0 release qrllib-browserify
Updated underlying qrllib from 1.2.7 through 1.3.0 and published the v1.2.0 release qrl-cli
Dependency refresh, principally updating qrllib to 1.2.7 webtools
Updated qrllib/qrllib-browserify dependencies, released v1.1.1 and subsequently moved to qrllib-browserify 1.3.0 with further release preparation offline-wallet-generator
Updated through qrllib-browserify 1.2.0 and 1.3.0; produced the v2.0.2 release changes and subsequent release preparation 
