ODIN has released its Week 31 development update, reporting 187 code commits and 42 pull requests, making it the project’s busiest development week of the quarter.
The update focuses on infrastructure reliability, security testing, monitoring systems and staking improvements, with several changes aimed at strengthening the platform before wider deployment.
One of the main changes involved the project’s indexing infrastructure. ODIN said both of its indexers now have dedicated health endpoints, allowing the system to verify whether they are functioning correctly before deployments proceed. The event indexer deployment process has been tied to successful health checks, while the staking indexer now uses a watchdog system that separates “alive” and “caught up” status checks. The team also introduced operational monitoring tools, including metrics dashboards, incident routing and a documented runbook for troubleshooting.
The project also disclosed that it conducted an adversarial exploit exercise against its phase-one staking canister before launch. According to the update, the testing identified multiple issues, including findings from the exploit suite, a withdrawal review and a transfer fee accounting problem labelled FEE-1. ODIN said the issue involved a flat 100-satoshi transfer fee that had not been fully accounted for by the canister. The team said all identified issues were resolved before users were affected.
As part of the security changes, production deployments have been restricted to manual approval, and the production environment is now limited to a fixed 27-method allowlist enforced through continuous integration checks.
The update also addressed a SQL injection vulnerability. A temporary escaping patch introduced in the previous week has been replaced with parameter binding, which is generally considered the standard approach for preventing SQL injection attacks. The project said read queries have also been moved to a read replica.
Changes were made to API error handling, with errors now being logged against the originating call rather than a wrapper layer. The update said HTTP responses will now return more accurate status codes instead of defaulting to generic server errors.
ODIN also expanded monitoring across liquidity, withdrawal and transfer operations. The team said incident paging has been limited to production systems, while development and staging environments can no longer trigger operational alerts. No-data alerts have also been adjusted to reduce unnecessary notifications.
Staking duration handling was updated to align with canister timing, with internationalisation support added across the interface. The platform now blocks extension requests once the maximum staking duration has been reached, preventing users from submitting requests that the canister would reject.
The project continues to publish weekly development updates under its “building in public” approach, giving users and developers visibility into engineering progress, operational issues and security work as the platform evolves.
Dear Reader,
Ledger Life is an independent platform dedicated to covering the Internet Computer (ICP) ecosystem and beyond. We focus on real stories, builder updates, project launches, and the quiet innovations that often get missed.
We’re not backed by sponsors. We rely on readers like you.
If you find value in what we publish—whether it’s deep dives into dApps, explainers on decentralised tech, or just keeping track of what’s moving in Web3—please consider making a donation. It helps us cover costs, stay consistent, and remain truly independent.
Your support goes a long way.
🧠 ICP Principal: ins6i-d53ug-zxmgh-qvum3-r3pvl-ufcvu-bdyon-ovzdy-d26k3-lgq2v-3qe
🧾 ICP Address: f8deb966878f8b83204b251d5d799e0345ea72b8e62e8cf9da8d8830e1b3b05f
Every contribution helps keep the lights on, the stories flowing, and the crypto clutter out.
Thank you for reading, sharing, and being part of this experiment in decentralised media.
—Team Ledger Life





Community Discussion