A Kasplex KRC-20 indexer exploit on September 20 moved 186.4 million ZEAL and 54.4 billion NACHO tokens by accepting a public key without valid signature verification, though Kaspa L1 itself was not compromised. The incident prompted API suspension and renewed focus on KCC-20 as a native covenant-based token standard, while Kaspa ecosystem developments include SilverScript v1.0 smart contract language, x402 micropayment protocol, and ongoing DAGKnight improvements.