Kaspire Wallet just released a new wallet update with many changes. One thing the Kaspa community always asked for: rotating Kaspa receive adresses as Kaspium was the only wallet to support this feature. But not anymore. We added the same feature but also improved the flow.
🔧Rotating Kaspa receive addresses
- Generate fresh receive addresses from the active HD wallet.
- Combine the primary and rotated addresses into one KAS account balance.
- Merge KAS activity and spendable UTXOs across those receive addresses.
- Spend from multiple controlled receive addresses in one locally reviewed transaction.
- Keep KRC20, KRC721, KNS, KCC20 and other asset ownership bound to the address that actually holds each asset.
- Validate every derivation path and address against the encrypted active wallet before signing.
- Zeroize temporary HD signing material after derivation.
- Set names for each change wallet to keep track easier which receive wallet is being used for which.
What is also new?
🔧 Even better Argon2id encryption
Although Kaspire Wallet already had the highest encryption among all Kaspa wallets this has been advanced even further. v3 Argon2id with 64 MiB and 4 iterations are now the new standard for Kaspire. Previous encrypted backups can still be used.
🔧A new theme called Glacier
For everyone who said Kaspire themes are too dark we added Glacier, a bright theme with a subtle aurora background. Uses translucent frost-glass cards, crystal bevels and mint/lavender light veils.
🔧Improved UX
On some parts in the wallet, the UX has been polished further. On Android, Argon2id backups are now saved directly into the dedicated Downloads/Kaspire-Backup directory. Restore a backup during first-run onboarding as well as from Settings. Discover backup files through Android's document provider, allow explicit file selection or pasted backup JSON, and some other polishing.
Update your Android app to 0.11.46. The extension update for 0.5.5 will arrive within the next days in the Google Chrome Store.
Started writing a new type of a Kaspa covenant for a new development. With Argent Studio the covenant was finished within days instead of weeks. Every flaw is being detected thanks to its source editor, interactive structure view, compiler output and local test transactions.
If you're building on $KAS covenants and not using Argent Studio you're missing out.
https://t.co/fungTqsMMp
We open-sourced kaspa-core, a pure TypeScript library for Kaspa transactions. No WASM, no Rust.
Addresses, P2SH multisig, BIP340 signing, KIP-9 mass and fees. Runs in browsers, extensions, Electron, Node and React Native, verified against rusty-kaspa.
Zelcore is switching to it next: an 11.5 MB WASM binary gone, lighter and faster to load.
MIT licensed. Free for anyone building on Kaspa.
https://t.co/FAm3n5D7J3
Future $KCOM holders, we’re getting closer. ⚡️
We’re collecting Kaspa wallet addresses from presale participants as we prepare for launch.
$KCOM will launch natively as a KCC20. The standard is nearing the finish line. KaspaCom Markets is next.
It’s all coming together.
A MESSAGE FROM #KREX TO ALL #KASPA HOLDERS, MINERS, AND DEVS! 🫶😍
We all are waiting for the much-needed #KCC20, but before you trash all #KRC20 memecoins and say they contributed nothing to the ecosystem and "they were never needed", let me kindly remind you of a few fundamental facts: 😉
KRC20 projects were by far the biggest source of fees for Kaspa, generating tens of millions of KAS in fees for miners, and becoming the single largest source of utility in Kaspa's history!
A small token like KREX alone contributed roughly 2 million KAS in network fees to miners over its full lifecycle, with a massive portion generated during the early minting phase.
To put this into perspective: that is more than all other Kaspa protocols that exist today... COMBINED!
Even dead or abandoned memes contributed massively. For instance, only during the first KRC20 peak, when activity skyrocketed, the network handled over 13 million transactions in a day, resulting in miners collecting over 21 million KAS in fees only during that period... without any centralized exchanges... just imagine that. 👀
And what is that utility? Trading.
Memecoins (as tradable tokens), are a magnet for retail investors and traders. Traders bring volume, volume generates fees.
The gateway.
They are also the biggest gateway to bring attention to Kaspa, not CEXs alone as many blindly believe.
A large part of the community discovered Kaspa through memes, not the other way around (as an example: If not memes on Robinhood, bearly anyone would know what Robinhood actually is).
On top of that, they were not only the creative part of Kaspa, but also a major driver behind DeFi on Kaspa.
Why? Because users needed places to trade these assets, devs and builders rushed to build exchanges, marketplaces, trading bots, web wallets, explorers and much more. Because of that, a large part of the ecosystem today exists thanks to memecoins, whether you like it or not.
Stress test.
What is even more important is that these KRC20 tokens brought the first, very-needed, stress test of GIGANTIC proportions to see if Kaspa was actually that good. And all that without any automated scripts.
Thanks to the memes, the entire crypto world had a chance to see, for the first time, that Kaspa's validated scaling tech is an ABSOLUTE MONSTER, handling enormous loads effortlessly, without any breaks or "sweat", while other networks like Solana and Ethereum were often lagging or crashing.
Now, after two years, all of a sudden everyone is saying, "You were never needed", "You are not Kaspa L1", "You never contributed anything", "You are just a shitcoin", and things like that... ;)
How sweet, haha 😄 Anyway, it is what it is, all just wording, definitions and interpretations.
What's next?
Now, KREX is preparing for the next chapter on KCC, with the aim of contributing to the fledgling utility layer on Kaspa as the mining era slowly comes to an end...
And all I can humbly say for now is:
"Watch What Happens Next." 😎😍
Study Kaspa, Be like Kaspa, Follow Krex. 🤜🤛
As announced, Kaspire is getting ready with full KCC20 DEX support directly inside the Android app and google chrome extension. We started with @KaspaRocket and are already working on other Kaspa DEXes. KaspaRocket is now integrated directly into K-Agora in both the Android app and browser extension.
- Browse and search supported KaspaRocket KCC20 tokens.
- Buy and sell tokens using live DEX quotes.
- Display token images, balances, prices, pool liquidity and 24-hour statistics.
- Display both the token covenant ID and pool covenant ID because KCC20 tickers are not unique.
- Show KaspaRocket tokens directly under TN10 assets.
- Display personal KaspaRocket swap activity.
- Present a complete secure review before signing.
- Show a persistent transaction receipt with swap and transaction details after completion.
- Validate available KAS and token balances before preparing a swap.
- Replace technical conflict messages with understandable insufficient-balance errors.
And as security is the most important part in Kaspire:
-Kaspire does not blindly sign transaction plans returned by the DEX.
- KaspaRocket plans use a dedicated testnet-only PSKT security profile.
- Token and liquidity-pool covenant IDs are bound to the reviewed transaction.
- Expected sighashes are independently recalculated and verified.
- Only SIGHASH_ALL is accepted for KaspaRocket swaps.
- Prebuilt signature scripts are restricted to verified KaspaRocket covenant inputs.
- Signature placeholders and offsets are bounds-checked before signing.
- Fee summaries and swap directions are checked for inconsistencies.
- Wallet inputs, wallet outputs, network fees and covenant outputs are shown during review.
- Account, network and reviewed transaction state are checked again immediately before signing.
You can start testing by switching to TN10 at the top right corner in your app or extension. The app update is already live while the extension update will be available within the next days in the google chrome store.
We also hardened the overall security of Kaspire even further. You can see the full release notes on our GitHub. Next in line is support for even more $KAS DEXes. Kaspire is aiming to be the MetaMask of Kaspa. Your All-in-One wallet for everything the Kaspa ecosystem has to offer!
We have added @kaspirewallet to the KasperoPay Widget builder, and it's already deployed for existing users of both KasperoPay (payment processor) and KasperoConnect (logins and identity).
@kasplex You still didn't answer anyone what full revert means. Rewriting history? That's a scam. You can't blame normal users who sold and bought tokens after the exploit for your mess.
Morning. While you were sleeping, @manyfest_ finished the KCC-23 reference implementation, the rulebook for token metadata on a prunable chain. @supertypo_kas patched the DNS seeder so dead nodes stop juicing the node count.
vProgs caught a reorg bug on TN10. Before it mattered. That's the whole point of a testnet.
And Michael Sutton's doing Bitcoin Takeover on October 7. Big mic for the quiet dev.
Covenants aren't the future anymore. They're just Tuesday.
Hello @kasplex , could you please provide an update on the restoration of #KRC20 operations?
It has now been six days since the indexer exploit. The public mainnet API remains unavailable, and affected users and projects in the #Kaspa ecosystem still have no clear timeline for resuming their activities.
According to your latest update, the code fixes were complete, with state rollback verification expected to take 3–5 days.
However, we have not yet found a published fix or a new release in the official go-krc20d repository.
Could you please clarify:
- What has been completed, and what remains?
- When will the corrected source code and new version be published?
- When can users expect the public API and KRC-20 transfers to resume?
A thorough resolution should take priority. But after six days of disruption, clear communication on progress and next steps is a reasonable expectation.
If a reliable ETA is not yet available, please explain the remaining obstacles and let the community know when to expect the next status update.
@IzioDev All good, I accidently confused it with kip 5 which I use for signature requests. Kip 12 is indeed not used but was replaced with walletconnect v2 because kaspa lacked such a standard. I may need some sleep 😅
After further working on Kaspire we also made use of the security audit tool by Cloudflare which is a coding-agent skill that turns your agent into a security auditor. It orchestrates isolated agents through reconnaissance, coverage-led hunting, candidate validation, structured output, independent record verification, and target-neutral reporting. This is the skill that seeded Cloudflare's vulnerability discovery harness.
As AI is getting more and more advanced and finds vulnerabilities in code even humans oversee this is a very important step to do, especially after recent incidents with Coldcard, the Lightning network or Kasplex.
The good news: after an over 4 hour check via Cloudflare Security Audit, the audit result came back mostly with only minor issues with the integration of KCC20 tokens, L2 tokens, and WalletConnect v2. This issues could potentially only lead to errors but no funds were ever at risk.
For full transparency there was however an actual security vulnerability. This is what the report says:
"Website build may accept an APK not authorized by the update-manifest signing key
The website post-build gate decodes the staged Android update envelope and treats the payload's SHA-256 as authority for the staged public APK without verifying the envelope's RSA signature. If an artifact-staging or deployment identity can replace both tracked public files while lacking the Android/update signing keys and while trusted build code remains protected, it could cause the website to publish a matching unauthorized APK for fresh installers. Existing supported installations have an additional Android package-signing-lineage control, and repository source does not establish whether the required lower-trust staging identity or deployment path exists."
This is a potential security issue when an attacker does not possess an Android signing key or an update signing key, but can somehow replace the two files during staging or deployment. This issue is being fixed right now.
The tool we used: https://t.co/63Dt3UGYw3
We encourage other builders to also make use of Security Audit Skill and find potential flaws to fix, before AI grants more attackers with flaws in the code to abuse.
While prototyping KCC-20 I got asked how should token symbols, descriptions, images, and other kind of metadata be defined.
On EVM systems, there is a single SC which represents a token, and holds both its balance state and global state.
On the UTXO model there is no global state, the token is split and held across holders, each one holds his specific token (UTXO/covenant).
This means that adding state fields for metadata would duplicate them across each UTXO, which is wasteful. Things such as representation, name, symbol or image are also not part of the SC logic, and should not be part of it.
A naive approach is to declare such metadata in the payload field of a tx, which is an "empty space" that can be used to write whatever information.
The issue is that Kaspa is prunable. Eventually, the block containing this tx would no longer be available for verification, so at some point the data would need to be trusted by off chain entity.
After drafting a few solutions, we came up with KCC-23, a convention for binding the metadata to the covenant ID itself.
Read more on Kas-Smiths:
https://t.co/H0RQYgPYKo
Or read the KCC draft:
https://t.co/CLgjoXG86U
Tic-tac-toe is live on Kaspa testnet: the first vprog, a verifiable program with real execution and real settlement, running since yesterday.
You can play it here: https://t.co/hd2NsYyhXt
(Requires private key and some testnet funds)
We still need to review and merge a stack of PRs, however this is already a working POC. UI/UX was never a priority; the frontend can be enhanced or built separately
I'm gonna work on mdBook covering the parts of the system I consider meaningful and a workshop on vprogs and building apps on top
For Devs: this is the invitation. Play the game, read the code, build your own vprog.
Game code: https://t.co/xebZK8N20P
vprogs framework: https://t.co/efpVCTErEc
The Kaspire Agora is expanding its gates soon...
Starting today, dotk domains are now integrated directly into the chrome extension of Kaspire Wallet as well, not just the app anymore, giving you a new place to explore and interact with the kaspa:native ecosystem from within your wallet.
And this is only the beginning.
🔹 .k — LIVE
🔹 KNS — coming soon
🔹 NFTs — coming soon
🔹 KCC20 — waiting for finalization of the KCC20 standard
KCC20 will be integrated via direkt DEX swaps fom @KaspaCom, @ZealousSwap, @KaspaRocket and all other DEXes.
Step by step, Kaspire Agora will grow into a unified hub for Kaspa assets, names, tokens and more.
One wallet. One Agora. One ecosystem.
Kaspire — the most advanced Kaspa wallet.
Note: The google chrome extension update is currently under review by the store and will be published within the next 1-3 days!