ECHO WITH YOU2026-07-03· 3 min read

Echo With You || What This Week's Work Means For You (and an Apology)

We spent a week hardening EchoForge's security and untangling a naming mix-up in our own smart contracts. Here is the honest, plain-language version of what changed — and why, for almost everyone, the answer is: nothing you need to do.

This is a note for the people who use EchoForge, not the people who build it. No jargon. Just the honest version.

First, an apology

For months, our documentation, our website, and even our own blog told you that EchoCert runs a smart contract called echocert. This week we discovered that the contract actually running on the blockchain was compiled from a different one of our validators, called documint. We had renamed things internally and never noticed that the label and the reality had come apart.

We are sorry. That is a documentation and process failure on our part, and describing your certificates with the wrong contract name — even when the contract itself was sound — is exactly the kind of sloppiness a system built on trust should not have. We have fixed it, written down a full reproducible proof of what happened, and added an automated check so it cannot silently happen again.

Are my certificates safe?

Yes. This matters, so plainly: the mix-up was in the name, not in the security. The contract that has always been running enforces every protection it should — only the issuer can mint, the certificate content is cryptographically locked to the token, and every issuance pays the treasury on-chain. Nothing you hold changed. Every certificate ever issued still verifies exactly as before.

What actually changed for you

Almost nothing you can see. The one visible change: verifying a domain (the step that removes the "Unverified Issuer" watermark and gives you the green badge) now lives in one place — the EchoDash Domain Verification card — instead of being split confusingly across two products. If you have already verified a domain, it stays verified; you do not need to redo anything. If you want to verify a new one, you will find a single, clearer flow.

We also did a broad security review of the whole platform and tightened a number of things behind the scenes. Those are the kind of fixes you should never have to think about — which is the point.

If you are curious what happened

We believe in showing our work. The smart-contract validators, the byte-for-byte proof of the naming mix-up, and the reasoning behind every decision live in our public repository. If the technical story interests you, we genuinely recommend a look — it is all there, in the open, including the parts that were not flattering.

If you do not care about the technical side

Then here is the whole message in one line: your certificates and your identity are safe, there is nothing you need to do, and you can stop reading here. That is not us waving you off — it is the outcome we worked for. The best security work is the kind that never asks anything of you.

Thank you for trusting us with something as long-term as your on-chain identity. We take the weight of that seriously — including on the weeks when the lesson is our own.


Published July 3, 2026 · EchoForge · ECHO WITH YOU Series