Bridge Update
Over the past 48 hours, the team has been working around the clock on recovery, remediation, investigation, and the future of the bridge.
With regards to legitimate wALPH and corresponding native ALPH: the exact technical implementation for recovery of funds is still being evaluated and depends on several factors. Regardless of the implementation chosen, the objective remains the same: legitimate holders will be able to recover their ALPH, while assets illegitimately created through the exploit will not benefit from the recovery process.
We continue to work with security and investigation partners to trace the drained assets and assess possible recovery opportunities and we are grateful for their ongoing support.
At the same time, we are initiating coordination with legal counsel, relevant authorities, and law enforcement regarding the incident.
Further updates will be shared throughout the week as work progresses.
March to Mainnet 15/05 🏃
As you may remember from last week’s report, Powfi’s frontend is now considered "feature complete" and thus the frontend devs are taking some well-earned rest after months of serious building.
This week, it is Alphland that has made the most notable progress.
Here is your weekly dev report:
<Powfi>
🔍 Powfi’s smart contracts continue to undergo a thorough internal review process.
🔍 The first of three internal auditors has completed and approved the contracts.
🔍 The second stage of smart contract review is already underway and progressing positively.
<Alphland>
🌐 Added a verification reminder banner on the Sponsor Dashboard for new sponsors pending admin approval.
🌐 Added a red warning banner for banned sponsors and disabled the “New Listing” button for both banned and unverified sponsors.
🌐 Refactored sponsor terminology from “company” to “organization” across the UI (CreateSponsor / EditSponsor).
🌐 Fixed a bug where Create Bounty was returning a 500 error.
🌐 Fixed issues related to Submission Notes.
🌐 Improved transaction hash error handling by adding a dedicated txError state for on-chain verification failures.
🌐 Fixed a bounty status bug where a bounty still showed as “Open” after a sponsor approved a submission and closed it.
🌐 Improved the Republish Bounty flow by replacing a simple date pop-up with a full, pre-filled bounty creation form.
🌐 Added a 404 page with “Go Home” and “Explore” buttons.
🌐 Removed the forced validation requiring users to change system-generated usernames.
🌐 Changed onboarding step one from “Complete username” to “Connect wallet address”.
🌐 Implemented the full Sponsor revision request flow, including revision_requested status and inline editing on the user side.
🌐 Improved UI by replacing browser alert pop-ups with toast notifications.
That’s all for this week!
It goes without saying, but your patience means everything to us as we build the FUTURE of SECURE DEFI ON PoW.
The finish line is in sight 🏁
Some of 2026's nastiest exploits had nothing to do with smart contracts.
The contracts were absolutely fine.
Several attacks were traced back to the off-chain infrastructure that nobody thinks to audit, like:
▶️ RPC nodes
▶️ Relayers
▶️ Indexers
These are all in scope for an attacker, but none of them are in scope for your audit firm.
That's a problem.
Fortunately, @RaduC22 built @linx_labs on @alephium specifically to reduce this surface.
Now, he shares exactly why it matters.
🔗 https://t.co/P757j5AKNL
Wanted to share some insights into what I meant by "new collateral types". Will be a thread.
Most used collaterals in DeFi lending are ETH, BTC and recently more and more RWAs in loops.
On Linx we have the L1 token, $ALPH and bridged $WBTC from Ethereum as the 2 collaterals that can be used to borrow.
/1
🌐 Ecosystem Review 🌐
Welcome to one of two new video series we are launching.
This one is for those who know about our expanding ecosystem (the other is for those who don't) 🤗
First episode, below 👇
Moments ago, the gates to the arena swung open.
The arrivals are anxious to PLAY and PREDICT.
Are you, Citizen?
The hALPHING is now live on @Alephium.
⏳ https://t.co/fZOkIeaXvI ⌛️
🕵🏻♂️ Good afternoon, detectives of @Alephium City.
🔍 Time to put your hats on — Case №2 has just landed on the desk, and it’s ready to be investigated.
📍 We’ll be waiting for you at the bureau: https://t.co/civ4e0XJFr
sUTXO on PoW is the only way to go.
You hold your keys. You hold your assets.
Contract-based tokens like ERC20 turn assets into mutable entries in a global registry,accessible to dApps, bugs, and exploits. That’s not custody, that’s delegation.
We've all seen what has happened in DeFi recently.
Our Head of Marketing, @BigPepGhost, discusses:
🧑💻 the new threat landscape
🛟 how to "make DeFi safe again"
🪓 why this affects fragmentation
👴 the ideal of generational building
Read his column here:
🔗 https://t.co/QyJiIUgSIj
Pushed new copy to https://t.co/YFCU51QkkZ
Cut the generic DeFi marketing and we now show what's actually live and working: 11% APY on stablecoin deposits, 90%+ utilization, zero bad debt.