RIADeFi

OP Labs discloses and patches a kona fault-proof soundness bug

The Ledger · · Ketju Research

ConfirmedConfirmed evidence

Affects: Optimism canonical bridge (bridge)

What happened

OP Labs published a required kona-client release disclosing a fault-proof soundness bug in post-Jovian BLOBBASEFEE handling.

What changed

A patched client became available and was designated as required for Upgrade 19, which is intended to promote kona-client to the primary fault-proof program.

What did not change

The release does not establish that affected code was active on OP Mainnet, that it was exploited, that an invalid withdrawal finalized, that funds were lost, or that Upgrade 19 deployed in June.

Confirmed

  • The official release labels v1.6.0 a critical security fix and required update.
  • The defect could make proof execution diverge from the canonical chain.
  • The patch pins the post-Jovian blob-fee inputs to canonical-client values.
  • The release states that v1.6.0 is required for Upgrade 19.

Still open

  • Whether vulnerable code was active for OP Mainnet.
  • Whether the defect was triggered or exploitable in a live dispute game.
  • Upgrade 19 approval, deployment, activation, and patched-program adoption.

What it means for an advisor

  • Review the bridge memo's fault-proof dependency before treating Upgrade 19 as operative.
  • Verify deployed program versions and governance execution; the release alone does not establish client loss or justify a restriction.

Sources

  1. kona-client v1.6.0 · OP Labs ·

Version 1, published . We check this event again on . Educational research, not investment advice.