Skip to content

Firo v0.14.18.0

Latest

Choose a tag to compare

@justanwar justanwar released this 27 Aug 10:13
4f0c771

Instructions

This is a mandatory hard fork release that restores normal multi-input Spark spending following the temporary mitigation introduced in v0.14.17.2.

Wallet users, full-node and masternode operators, miners, exchanges, and service providers should upgrade to v0.14.18.0 before block 1,371,000 (approximately 4 September 2026, 10:00 UTC).

Please back up your wallet before updating.

Important Spark changes

v0.14.18.0 introduces a new versioned Spark spend format containing the fix for the multi-input Spark vulnerability disclosed in August 2026.

Until block 1,371,000, the temporary single-input Spark restrictions introduced in v0.14.17.2 remain in effect. Wallets may continue to split larger payments across multiple single-input transactions where necessary.

From block 1,371,000, the new Spark spend format activates and normal multi-input Spark transactions are restored automatically. Existing Spark coins and balances remain valid and do not need to be migrated or reminted.

Users who do not need to move Spark funds before activation are still encouraged to wait until the hard fork before spending, as the temporary single-input mode can reveal correlations between transaction amounts.

Credits to Carter Annandale (@carter-0) and Giap Vu for their responsible disclosures, and to Cypher Stack and HashCloak for their assistance in reviewing the fix.

Changelog

  • Restore multi-input Spark spending through the new versioned Chaum V2 proof and transaction format, while preserving validation of historical Spark transactions and the temporary single-input rules until hard-fork activation #1913
  • Harden Spark consensus and wallet validation, including canonical proof context binding, bounded payload and cover-set handling, Spark coin-type validation, duplicate mint protection, minted-coin state synchronization, group ID handling, reorg handling, and fail-closed batch proof verification #1913 #1902 #1910 #1901 #1863 #1907 #1894 #1895
  • Fix a deadlock between walletpassphrase and the wallet relock timer, harden concurrent relock scheduling, and validate wallet unlock timeout bounds #1889
  • Limit LLMQ signing sessions per peer to reduce P2P resource exhaustion risks #1918
  • Keep precomputed transaction validation data alive for the required validation lifetime #1917
  • Fix truncated fee information in the Make Funds Private dialog #1915
  • Improve rate-limit logging and release/debug build and test infrastructure #1919 #1920 #1921

Full Changelog: v0.14.17.2...v0.14.18.0

BINARIES

  • SHA256 Hashes:
    • Linux aarch64: f8d8fe9e60f3ed438d201293ad599e6b38caea8d4a9ae100b682c25c16ff8c16
    • Linux: b4b57108b66ee3ff9ec1b03dd7c24fe79acecf1110fe132f347758ae99555276
    • macOS: b16268e84efd7c658f401e4a8fa0e376c02fdd3d4970809409e293e63450be3b
    • macOS arm64: f04bc6361255700e95c3b4845a6a8e77d222d7ee9e074ce806ed7d5b06ccd04a
    • macOS tar.gz: 4a9b71c5bed003f9e4389494ab31143631b3b01f0caf0af0c90e809132db54bb
    • Windows Installer: f99687dd0d5374395c6ad65a2ab43c7bef22186b54ee33719d73b3410d0d84e9
    • Windows zip: e2f60b6e701845c9280aeabae9f6971c1e99a04272b868b8612c631f44876400
  • The signatures can be verified using reuben.asc found in root of this repository or on https://firo.org/reuben.asc