Skip to content

Releases: firoorg/firo

Firo v0.14.18.0

Choose a tag to compare

@justanwar justanwar released this 27 Aug 10:13
4f0c771

Instructions

This is a mandatory hard fork release that restores normal multi-input Spark spending following the temporary mitigation introduced in v0.14.17.2.

Wallet users, full-node and masternode operators, miners, exchanges, and service providers should upgrade to v0.14.18.0 before block 1,371,000 (approximately 4 September 2026, 10:00 UTC).

Please back up your wallet before updating.

Important Spark changes

v0.14.18.0 introduces a new versioned Spark spend format containing the fix for the multi-input Spark vulnerability disclosed in August 2026.

Until block 1,371,000, the temporary single-input Spark restrictions introduced in v0.14.17.2 remain in effect. Wallets may continue to split larger payments across multiple single-input transactions where necessary.

From block 1,371,000, the new Spark spend format activates and normal multi-input Spark transactions are restored automatically. Existing Spark coins and balances remain valid and do not need to be migrated or reminted.

Users who do not need to move Spark funds before activation are still encouraged to wait until the hard fork before spending, as the temporary single-input mode can reveal correlations between transaction amounts.

Credits to Carter Annandale (@carter-0) and Giap Vu for their responsible disclosures, and to Cypher Stack and HashCloak for their assistance in reviewing the fix.

Changelog

  • Restore multi-input Spark spending through the new versioned Chaum V2 proof and transaction format, while preserving validation of historical Spark transactions and the temporary single-input rules until hard-fork activation #1913
  • Harden Spark consensus and wallet validation, including canonical proof context binding, bounded payload and cover-set handling, Spark coin-type validation, duplicate mint protection, minted-coin state synchronization, group ID handling, reorg handling, and fail-closed batch proof verification #1913 #1902 #1910 #1901 #1863 #1907 #1894 #1895
  • Fix a deadlock between walletpassphrase and the wallet relock timer, harden concurrent relock scheduling, and validate wallet unlock timeout bounds #1889
  • Limit LLMQ signing sessions per peer to reduce P2P resource exhaustion risks #1918
  • Keep precomputed transaction validation data alive for the required validation lifetime #1917
  • Fix truncated fee information in the Make Funds Private dialog #1915
  • Improve rate-limit logging and release/debug build and test infrastructure #1919 #1920 #1921

Full Changelog: v0.14.17.2...v0.14.18.0

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: f8d8fe9e60f3ed438d201293ad599e6b38caea8d4a9ae100b682c25c16ff8c16
    • Linux: b4b57108b66ee3ff9ec1b03dd7c24fe79acecf1110fe132f347758ae99555276
    • macOS: b16268e84efd7c658f401e4a8fa0e376c02fdd3d4970809409e293e63450be3b
    • macOS arm64: f04bc6361255700e95c3b4845a6a8e77d222d7ee9e074ce806ed7d5b06ccd04a
    • macOS tar.gz: 4a9b71c5bed003f9e4389494ab31143631b3b01f0caf0af0c90e809132db54bb
    • Windows Installer: f99687dd0d5374395c6ad65a2ab43c7bef22186b54ee33719d73b3410d0d84e9
    • Windows zip: e2f60b6e701845c9280aeabae9f6971c1e99a04272b868b8612c631f44876400
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.17.2

Choose a tag to compare

@justanwar justanwar released this 13 Aug 04:43
daf3f0c

Instructions

This is a mandatory release containing important security, stability, and wallet fixes. Wallet users, full-node and masternode operators, miners, exchanges, and service providers should upgrade as soon as possible.

Please back up your wallet before updating.

Important Spark changes

This release temporarily restricts each Spark spend transaction to a single Spark coin. Spark minting and existing Spark balances remain available. A follow-up release is planned to restore multi-input Spark spends.

If a payment does not fit within one Spark coin, Firo Core can split it into several transactions. Each transaction pays its own fee.

Credits to @carter-0 for the responsible disclosure.

Temporary limitations:

  • Spark Coin Control supports at most one manually selected coin. Clear the selection to let the wallet split the payment automatically.
  • Fee subtraction is unavailable when a Spark payment needs multiple transactions.
  • RPC users can use spendsparksplit to opt into split payments. It always returns an array of transaction IDs.

Changelog

  • Added temporary single-input Spark security hardening, preserved verification of historical Spark transactions, and added wallet and RPC support for splitting larger payments into separate single-input transactions. #1899
  • Closed a headers-only validation gap by rejecting malformed FiroPoW headers whose serialized height does not match the height derived from the parent block. #1898
  • Added the amount-based Make Private workflow, allowing users to move an exact amount or their maximum eligible transparent balance into Spark. #1891
  • Added Spark address and Spark Name message signing and verification to the desktop wallet, with stricter handling of malformed and non-canonical ownership proofs. #1877
  • Added support for pasting Firo payment URIs into the recipient field and displaying Rosen Bridge payment metadata. #1874
  • Improved wallet responsiveness by preventing GUI stalls during block updates, transaction preparation, proof generation, and sending. #1883
  • Substantially improved startup and balance-processing performance for wallets with large Spark histories, with visible wallet-loading progress. #1885, #1886
  • Hardened Spark wallet concurrency, memo decoding, proof handling, quorum message parsing, and Spark Name validation. #1879, #1868, #1873
  • Improved early reindex performance and prevented macOS App Nap from throttling Firo Core while it is out of focus. #1864, #1867
  • Updated the bundled Tor client to 0.4.9.11 and modernized node logging with improved categories, levels, and diagnostics. #1876, #1875
  • Included further build-system, dependency, CI, and macOS packaging maintenance. #1872, #1881, #1862, #1861, #1882

Full changelog: v0.14.16.1...v0.14.17.2

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: b8ef8e070a7ca0bd94525fd45bf1b1a4cf6e40b75350d7ac28467ab93d77244a
    • Linux: 153d165de6f0c0fdc20f68561711d05ac6925df143fbc2d0212b9f27e9aaabec
    • macOS: d1182ab833277b01b7c20ee280486311e94065165b11c3e0679db24952da76e4
    • macOS arm64: 1a32acaca7fa47a12e8ceef58cb28462432c10a9fe9a60de092af31d2c84c99e
    • macOS tar.gz: 4c8c3511f998b8e3ff3610d56b22990e5ef71211767e22b2130913c63a2c5e5d
    • Windows Installer: cc81a14d53441488c05ed6a1e365bf128bf1963ff350237b1afe82de19e3e9ff
    • Windows zip: 8e709e1e9bfa6817be9cb4e2c7ada5c642c414914d6be952367ea90ea7a595b8
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.16.1

Choose a tag to compare

@justanwar justanwar released this 03 Jun 16:27
2fade3d

INSTRUCTIONS

This mandatory release introduces the ability to extend your Spark Name's validity.

You must update to this release even if you have updated to v0.14.16.0 before.

Please update your wallet, nodes, and masternodes to v0.14.16.1 prior to block 1,329,000 (approximately 22 June 2026).

Please backup your wallet prior to updating for safety.

CHANGELOG

  • Spark name overflow fix #1851
  • Update Github Actions #1853
  • Sync with upstream Flathub #1855
  • Fix Receive request model handling #1838
  • Lelantus strip #1805
  • Refresh Spark address book acfter activation height skips #1831
  • Fix minor Spark Name vulnerability #1858

Full Changelog: v0.14.16.0...v0.14.16.1

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: c9a4a268d9569ccf13bb388229b57655aaeab42c39dca0f4291f737f0bf955a6
    • Linux: f2b7dba9adfbfebaf4812ca96c39f4f94fdb03ea7e1a7e5c346f8d2f626594e0
    • macOS: d03b3a8663282ad290d5f71c70572e710dfcbc90799e23f5ecab9e681db57a73
    • macOS arm64: 3b74f86161c65889c321d81b569aae3e7afeb481d13f50d1f93ab3aba66291f3
    • macOS tar.gz: 1f74f4843f09db56997dc63cab4c46d57d5507231be9e103a56b8ed7dd65f145
    • Windows Installer: ea5c5a885bce58f563e4307a754bf59d9e16105a3568593d64474b6f1e279bfb
    • Windows zip: 29140f64713f8cfc406ef3926748419701537880d8e8ce5c27b26b5cdd6e296c
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.16.0

Choose a tag to compare

@justanwar justanwar released this 15 May 11:04
ffb16cb

INSTRUCTIONS

This mandatory release introduces the ability to extend your Spark Name's validity.

Please update your wallet, nodes, and masternodes to v0.14.16.0 prior to block 1,329,000 (approximately 22 June 2026).

Please backup your wallet prior to updating for safety.

CHANGELOG

  • Update/extend/transfer Spark name without paying twice for leftover time #1780 #1844
  • Register getspentinfo RPC and clean up stale mempool spent index on tx removal #1791
  • Qt wayland support #1808 #1822 #1829
  • Fix own Spark Name list refresh #1814
  • Refactor #1812 #1813

Full Changelog: v0.14.15.3...v0.14.16.0

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: db9f96076a49245f48950b27395c805da32612ebd3a837b254794381199d3098
    • Linux: b8f6ff5d7481e5a9dd7c5ad71caa62658b7747a8f3512999786229458397c59d
    • macOS: 5fdb4d7e27a579eef415ddc2f95649945ebcc6d301f9660673efd23a0033f301
    • macOS arm64: 941c4df7e44001f56cbb754bcc73ad9665df607f4306c17a58e28645d6ade2cc
    • macOS tar.gz: 2a06ea268051ae3974965cb2e3a8cc39ddafffb0ff266ee54bb2db31d62ed14d
    • Windows Installer: b57c185ca737d6a0d06d922236e679c4d29a611d4517a6c537f53b2629e2c093
    • Windows zip: 7580d3c2816098047e73d24e1c242d25a309c6563c96aad6b1800b91e7d0b840
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.15.3

Choose a tag to compare

@justanwar justanwar released this 10 Mar 18:42
16b611f

INSTRUCTIONS

This is a mandatory update — all users and node operators should upgrade as soon as possible. Please backup your wallet prior to updating for safety.

WHAT'S NEW

Spark Address Message Signing & Verification

This release introduces the ability to sign and verify messages using Spark addresses. This is an important step for proving ownership of a Spark address without revealing any private information or making an on-chain transaction — useful for identity verification, proof-of-ownership, and building trust in peer-to-peer interactions while preserving privacy.

Improved Transaction Rebroadcasting

InstantSend-locked transactions are now periodically rebroadcast. This improves transaction reliability by reducing cases where valid transactions might not propagate fully across the network, particularly in scenarios involving temporary network disruptions or peer disconnections.


Bug Fixes

Tor Connectivity Fix

Resolved an issue where Firo Core (Qt) ignores onlynet=onion option. Users who operate their nodes exclusively over Tor should update.

Spark Names Dialog (Qt6)

Fixed a layout issue with the Spark Names dialog on Qt6-based wallet builds, ensuring the UI renders correctly.


Mobile & Developer Improvements

  • Refactored the getusedcoinstagstxhashes call to use GetSpendsMobile, improving performance and code maintainability for mobile wallet integrations (e.g., Stack Wallet).
  • Enhanced getusedcoinstagstxhashes to handle edge cases more gracefully, improving reliability for light wallet backends.
  • Added Spark-related verbosity to the getblock RPC, giving developers and node operators richer block-level data about Spark transactions.

Housekeeping

Various minor code cleanup and maintenance changes.


CHANGELOG

  • Implementation of signing/verification of message with Spark address #1781
  • Rebroadcast IS-locked transactions periodically #1784
  • Fix onlynet=onion issue #1761
  • Mobile: Refactor getusedcoinstagstxhashes to use GetSpendsMobile #1773
  • Fix Spark Name dialog layout for Qt6 #1776
  • Add Spark getblock verbosity #1778
  • Enhance getusedcoinstagstxhashes to handle edge cases #1775
  • Various housekeeping changes

Full Changelog: v0.14.15.2...v0.14.15.3

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: fb237e94e6e9ae9f5407d322630000002758add2b5614f02ef1bfa51e1048084
    • Linux: df6d0fb6abc8998909ecb3c3f4c5aa0b6bbf00474bb4739349d12079874754fc
    • macOS: 4bff0f6180b6b29ddbb6e9220a5bcbc5275261be8bb7f6538e5ecc1ab59645ba
    • macOS arm64: 7f3ac3c9e356e52ead1ebb1e64cdd9d70c1120d5b61b00527b98618bf44c0945
    • macOS tar.gz: 5c965c52abec08734ddd4c818f95de8553ef247a440d51029a9b6ce1aeba842d
    • Windows Installer: 943b24deb244d65aeef2c59bc0a75416007e4e17b9646011bc2f180eb4441fad
    • Windows zip: c856f29b05b2371830fdbfe8c741a795386030195d73de738feba183631feaa3
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.15.2

Choose a tag to compare

@justanwar justanwar released this 22 Jan 16:34
30256ae

INSTRUCTIONS

This is a maintenance and bug fix release. Tor v3 adds .onion address support, fix for UI missing transaction issue, and coin control tree fix.

A big thanks to @NorseGaud for massive improvements to the Github CI as well as quality of life improvement for macOS installation.

Please backup your wallet prior to updating for safety.

CHANGELOG

Full Changelog: v0.14.15.1...v0.14.15.2

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: 23862b9fc4b58b78dbb2bb887e95a5d8a9484ddfa52b9d7d7333777bc183f467
    • Linux: b1136f058a074a0f1df11a3123457a64f2323f26aa965c3330da070e34949ea3
    • macOS: 3a8b5adcaa57e3e0028d8b6b934562f435133d41d7a774cc8bbfdb43962c7462
    • macOS arm64: 0a4c168084b35885d38a1d7857be3d3d9b7809f784b6edf54c61b909e0c94e32
    • macOS tar.gz: 0a54d946a918da963ace39b5b41b608e27fa2c039e389f5d34abb4d4b296c707
    • Windows Installer: bee87f5275b0682c1039a018176dd00d3c015c0e87b67fb999cfea2f070f45f0
    • Windows zip: f16068364be6db4229bc81b46d36728656f10efc8fda9f953817b94f7323e029
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.15.1

Choose a tag to compare

@justanwar justanwar released this 08 Jan 14:55
044c000

INSTRUCTIONS

This is a maintenance and bug fix release. Big changes include upgrade to Qt 6, C++20 support, improved Spark zero-knowledge proof verification, reduced memory requirements for checking Spark spends, various UI and housekeeping fixes.

Please backup your wallet prior to updating for safety.

CHANGELOG

Full Changelog: v0.14.15.0...v0.14.15.1

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: a2f3d7a138b5e8fbe12adee5faddd31c828f267f575ac526e4d33d53088db769
    • Linux: 0185163895f0dd217fa04d7bb271ee54c00afec4db8baf6c2d8cb0c2bcdc57dd
    • macOS: f2a7159f7b4b297643acfd9905b2cd372f88eef3a1896bba16d0d70ef20b616b
    • macOS arm64: 843e4e0c76a6b2898beca3c5a59d8db986219722ab3fa1cba27917c02ce39a51
    • macOS tar.gz: 3619662d1a87ef9cdbdbcfd482d7eb456f367a30a9237f4e2b11e698af3dbc8c
    • Windows Installer: 7c40a3ef809ce0070d8d6d07fdf835257a260cf7d15c98ee15b9f175e5341936
    • Windows zip: 2265e0861d64176e4b72e31ae06a992687aac717f114dd8e7e21b0e46b23e78d
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.15.0

Choose a tag to compare

@justanwar justanwar released this 20 Oct 07:32
82e0001

INSTRUCTIONS

This mandatory release introduces the ability to transfer registered Spark Names to other Spark addresses, whether your own or third party's. It also reduces the GPU memory consumption, allowing 8 GB graphic cards to mine again. Additionally, Sigma stripping is introduced, Spark spend limits increase, and a new loading screen is introduced.

Please update your wallet, nodes, and masternodes to v0.14.15.0 prior to block 1,205,100 (approximately 19 November 2025).

Please backup your wallet prior to updating for safety.

TROUBLESHOOTING

If you are stuck on block 1205099 after updating, please run reconsiderblock 7d0e653265e840a8a3bd684d5baef5f6e5bbf6094c85a35dca80104afaac6562, clear ban list, and restart firod/Firo Core.

CHANGELOG

  • Spark Name transfer (#1696)
  • Sigma strip (#1677)
  • Increase Spark spend limits to transparent addresses (#1645)
  • Limit FiroPoW GPU memory consumption, lowered maximum DAG size to 6.76 GB (#1648)
  • Change of dev fund address (#1646)
  • Spark spend should now be increased by a factor of 5 instead of 3 (#1653)
  • Add progress text and rotating spinner to splash screen (#1654)
  • GUI freeze fix (#1686)
  • Fix incompatibility with bitcoin for qrencode (#1697)
  • Mobile: getusedcoinstags rpc fixed (#1685)
  • Various housekeeping and bug fixes
    Full Changelog: v0.14.14.3...v0.14.15.0

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: ba018586e2b26ca5886ff97b4e7eece8b2836ce08921c21b9e6d10dca1bbbe72
    • Linux: 6a601e7c1aa0af4aee3b28a7fbd365a1d749d2203e8d042bcccf9f950072ecd9
    • macOS: 0b4cd744be170e641ac813b648398e37f4945127aae191c2e9ce3825369c2d42
    • macOS arm64: e11f532721af3cc660b2438d8d65f005764599ef7e11e8aa1423be9a16a3c7aa
    • macOS tar.gz: 5345385bdc6d3bd87d87dc225333a7a756b49afe733394e07dbcafa4bdf29f8b
    • Windows Installer: 2352ff42b12935b5848e8ee1a3d86c1926ecee7f78be95c67b380dc8d7d89356
    • Windows zip: bd644fcb081b1d6e7fa0c72fcd4757edb079b3a3b407bb70f8a3d88082a1b6ac
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc

Firo v0.14.15.0 Debug

Firo v0.14.15.0 Debug Pre-release
Pre-release

Choose a tag to compare

@justanwar justanwar released this 21 Oct 11:55
82e0001

This release contains files needed for debugging and troubleshooting. It is not meant for regular use.

INSTRUCTIONS

Extract contents (*.dbg) to the same location as existing firod binaries, then run the needed printcrashinfo.

Example:

./firod -printcrashinfo=bvcgc43iinzgc43ijfxgm3ybaacwm2lsn5scaudponuxqictnftw4ylmhiqfgzlhnvsw45dboruw63ramzqxk3dubvl5azaaaaaaaabamxb3ohzhaaapbfzdaaaaaaaa2locaaaaaaaab3tynqaaaaaaadmzy3aaaaaaaaajwjwaaaaaaaah2zbcaaaaaaaa2cjcaaaaaaaabpnvdqaaaaaaacin3qnxd4tqaaca33a3ohzhaaaivbjaaaaaaaaaaa======

Firo v0.14.14.3

Choose a tag to compare

@aleflm aleflm released this 27 Sep 17:09
055a67f

INSTRUCTIONS

This is a release for nodes that do not support glibc-2.32.

If you're already on Firo v0.14.14.2 and not experiencing issues, you do not need to update.

If you're on an earlier version than Firo v0.14.14.2 and your node is stuck, update to this version and follow the instructions below.
Please backup your wallet prior to updating for safety.

Add allowdeepreorg=1 to the firo.conf
restart firod or firo-qt

Execute the following commands in console or firo-cli

removeislock fb5e6efe2d3c633c2176b3dc84cf151fb6a29f5419067992387cc55fa7b3d7cb
removeislock 794d98433d94a8c616856ea7f4f5f87d1d3080ec5737a143a4a16c3b1a359f9d
removeislock 70fd365cfecc4be66586476a9074809887ac9c767c957e38647ec0020c296de0
removeislock a2abd1093d8d8dea46ec25735ba7134cae34baf95c2fe2b1827ca0e06645c2e2
removeislock 654c08867ef9d0755f26d9ee7ef7b1a03a010409794b13d25fecacc4ef936119
removeislock 521ea34b6d326c74fbcae71c4ad5a6ff4d497542cc64d0bcc61727cc83e62184
invalidateblock 6e5c8ca003d5386558fefce1c1dae134e8f9b4770bc6eee74539c0e405344a4f
reconsiderblock bce69b1f20fea873b219c5a63f986498b45d0a678f1ee27a70fd91ebffca7c9a
reconsiderblock a6b78772b21693ea841f8871a260c9c4397f00c5f44db10257925670bf38a69c
clearbanned

After doing this, remove the line allowdeepreorg=1 from the firo.conf and restart firod/firo-qt

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: 36962c79491c6a42bcdd1604380d6add62a53fb789cddea5288affbde2934e32
    • Linux: af0443f5c9de95ec1eb5246718cd274986adb177a512ee2171e1449fab76dc8f
    • macOS: 4d2761cc9092c79de73c9339e5ba4f4108ce4efa0e6d5ef255b8dce904ccd331
    • macOS arm64: 3b77b75d2e4965c444a505d163fea5f4b6363bd451cf05048523bf956e89ab72
    • macOS tar.gz: 52bba1c2d8495bd8bc45a3071656d602529a662fe5d7100a683c9946df34b314
    • Windows Installer: ba37518b356e107e3669ed9c91664c1a93b05c158db044841c1f61b73e801be2
    • Windows zip: 883693acb71649ee4809e74b4f0c66120ad4ed36da219e4c147da85b9795f114
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc