ZODL has submitted an updated retroactive grant application covering work completed January through June 2026. This grant request includes protocol vulnerability remediation work, including the successful remediation of the Orchard vulnerability. This application supersedes our earlier Q1-only application; GitHub issue #33 has been updated in place.
This grant is more than justified by the security responses alone. Being on the bug-reporting side myself, and seeing the kinds of bugs that LLMs became capable of finding practically overnight, I can’t imagine what it was like to get hit with that firehose of security bug reports. To be able to triage and handle all of those reports while still being able to stay focused and quickly ship correct patches is unimaginable to me, totally a world-class effort. Like, what happened at ZODL and ZF through that period should be studied by academics or something… it was that good.
I noticed that both the Swift wallet SDK and the Android wallet SDK has been modified from a permissive MIT license to a fairly restrictive AGPL + commercial license required for distribution.
While it does look like this change was done in Q3, I do feel like that’s a fairly significant change that should be disclosed.
As you already mentioned, those changes were made in Q3 while our grant proposal only covers Q1 and Q2. Additionally, our grant application deliberately only includes work on the core protocol, not our Zodl mobile wallet. The SDK licensing changes mentioned only apply to our wallet which is funded separately (not grant-related).