<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="4.3.2">Jekyll</generator><link href="https://firo.org/feed.xml" rel="self" type="application/atom+xml" /><link href="https://firo.org/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-09-26T07:45:05+00:00</updated><id>https://firo.org/feed.xml</id><title type="html">Firo</title><subtitle>Firo is a cryptocurrency that focuses on privacy and fungibility.</subtitle><entry><title type="html">Firo Reference v0.14.18.1: Redesigned Wallet, Better Performance</title><link href="https://firo.org/2026/09/26/firo-v014181-release.html" rel="alternate" type="text/html" title="Firo Reference v0.14.18.1: Redesigned Wallet, Better Performance" /><published>2026-09-26T00:00:00+00:00</published><updated>2026-09-26T00:00:00+00:00</updated><id>https://firo.org/2026/09/26/firo-v014181-release</id><content type="html" xml:base="https://firo.org/2026/09/26/firo-v014181-release.html"><![CDATA[<p>Firo v0.14.18.1 puts the desktop wallet front and center, with a refreshed interface, smoother interactions, and major memory savings for full nodes.</p>

<h2 id="a-new-look-and-smoother-experience">A New Look and Smoother Experience</h2>

<p>The <a href="https://github.com/firoorg/firo/pull/1914">Firo Core redesign</a> refreshes the Overview, Send, Receive, transaction history, and masternode screens. It adds a collapsible sidebar, switchable light and dark themes, and a dedicated Spark Names page. <a href="https://github.com/firoorg/firo/pull/1924">Responsiveness improvements</a> also make the interface smoother to use during everyday wallet activity.</p>

<p><img src="/blog/assets/v014181/newqtdark1.jpg" alt="Dark mode1" /></p>

<p><img src="/blog/assets/v014181/newqtdark2.jpg" alt="Dark mode2" /></p>

<p><img src="/blog/assets/v014181/newqtlight3.jpg" alt="Light mode3" /></p>

<p><img src="/blog/assets/v014181/newqtlight4.jpg" alt="Light mode4" /></p>

<h2 id="major-memory-savings">Major Memory Savings</h2>

<p>Firo Core now keeps block privacy data in memory <a href="https://github.com/firoorg/firo/pull/1884">only when it is needed</a>. Previously, even blocks without that data reserved space for it. This reduces unnecessary memory use and gives full-node and masternode operators more headroom on their existing machines.</p>

<p>Back up your wallet before updating, then get v0.14.18.1 from the <a href="https://github.com/firoorg/firo/releases">official Firo releases page</a>.</p>]]></content><author><name>Augustus Jong</name></author><category term="community" /><category term="news" /><summary type="html"><![CDATA[Firo v0.14.18.1 puts the desktop wallet front and center, with a refreshed interface, smoother interactions, and major memory savings for full nodes.]]></summary></entry><entry><title type="html">You’ve Heard About Zcash. Let Me Tell You About Firo.</title><link href="https://firo.org/2026/09/20/firo-10-years-in-the-making.html" rel="alternate" type="text/html" title="You’ve Heard About Zcash. Let Me Tell You About Firo." /><published>2026-09-20T00:00:00+00:00</published><updated>2026-09-20T00:00:00+00:00</updated><id>https://firo.org/2026/09/20/firo-10-years-in-the-making</id><content type="html" xml:base="https://firo.org/2026/09/20/firo-10-years-in-the-making.html"><![CDATA[<p><em>By Reuben Yap, Co-Founder of Firo</em></p>

<p>I’ve been happy to see the renewed interest in Zcash. Financial privacy needs more people paying attention, and Zcash has done a great deal to bring people into this space. Its researchers have made important contributions to zero-knowledge cryptography, including Halo and the work that removed the need for a trusted setup in its newer shielded transaction system. That work deserves recognition.</p>

<p>It has also made me want to tell a little more of Firo’s story.</p>

<p>I’ve spent much of the past decade helping build this project. Naturally, I care about it. But what keeps me interested is more than the time I’ve put in. It’s the research we’ve contributed, the things people can already do with Firo, and the people who have kept showing up to make it better.</p>

<p>Some of that is easy to miss from outside our community. You might recognise the name without knowing much about what we’ve built. You might remember us as Zcoin and not have looked at the project for years.</p>

<p>So this is an invitation to take another look. There is room to appreciate Zcash and be interested in Firo too.</p>

<h2 id="nearly-ten-years-of-figuring-things-out">Nearly Ten Years of Figuring Things Out</h2>

<p>We launched as Zcoin in 2016, implementing the Zerocoin privacy protocol. The original academic work wasn’t ours, and its researchers deserve that credit. Our contribution began with putting it into practice and then working through its limitations.</p>

<p>One of those limitations was the trusted setup. In July 2019, we deployed Sigma, helping pioneer the practical use of zero-knowledge privacy without a trusted setup in a live cryptocurrency. Lelantus followed, moving beyond fixed denominations to allow arbitrary amounts and partial redemptions. Each step addressed something that had made private money harder to use.</p>

<p>Lelantus Spark brought that work together with sender, receiver and amount privacy for Spark-to-Spark transactions, reusable private addresses and view keys for selective disclosure. It retains the no-trusted-setup approach, using a modular collection of purpose-built proofs. Spark went live in January 2024 after years of development and independent cryptographic and implementation reviews.</p>

<p>Those protocol names represent a lot of patient work. Looking back, I’m proud that we forged our own path. We kept asking what needed to improve and were willing to do the research to get there.</p>

<p>It has been especially rewarding to see that research become useful elsewhere. Beam’s Lelantus-MW adapts Lelantus to its Mimblewimble design. The Seraphis research developed for Monero also drew on Spark’s membership-proof construction and security argument. These are independent projects with their own contributions, but there is a connection to work done at Firo.</p>

<p>For a relatively small project, that means a lot to us. It means the work has value beyond the people who happen to hold our coin.</p>

<h2 id="what-that-work-looks-like-when-you-use-it">What That Work Looks Like When You Use It</h2>

<p>Most people shouldn’t need to understand a proof system to make a payment. They want to send money, know that it has arrived and avoid exposing their financial life in the process.</p>

<p>That is why we have spent time on the things around the privacy protocol too.</p>

<p>Firo’s hybrid security model combines proof-of-work mining with collateralised masternode quorums adopted and modified from Dash. Since 2021, ChainLocks has provided near-instant finality once a newly mined block receives its quorum signature. InstantSend handles the earlier part of the payment, locking transactions within seconds before the next block arrives. Together, they make private payments much more practical.</p>

<p>We benefited from Dash’s work on these technologies, and its developers deserve credit. Over the years, I’ve also kept sharing what we were building with Joel Valenzuela. Seeing Firo combine strong privacy with instant payments helped encourage his push for Dash to take privacy more seriously.</p>

<p>I’m glad the influence has gone both ways. Those relationships matter, and I would rather see good ideas travel between projects than have every development become a competition.</p>

<p>Spark Names address another everyday frustration: long payment addresses. You can share a readable name that resolves to a private Spark address without giving people a searchable record of your payments or balance. A payment name can be public without making your finances public.</p>

<p>We were the first project to go live with Dandelion++, which works behind the scenes, making it harder for network observers to trace a transaction’s broadcast back to its originating node. It complements the information protected on-chain by Spark.</p>

<p>We have also taken accessible mining seriously. For most of Firo’s block-reward distribution to date, mining has remained free of known ASICs. That gave people a way to participate as the currency was being distributed without needing access to specialised mining machines. FiroPoW continues that effort with a design optimised for commodity GPUs and resistance to ASICs and FPGAs. We even recently <a href="https://firo.org/2026/09/18/firominer-140-release.html">updated our reference FiroPoW miner</a>, giving the community a competitive and open source miner with no dev fee.</p>

<p>For me, these choices belong together. Privacy matters, but so does whether a payment is convenient, whether it settles quickly and whether ordinary people can participate in the network.</p>

<h2 id="the-people-who-have-kept-us-here">The People Who Have Kept Us Here</h2>

<p>When I think about why Firo is still here, I think about people as much as protocols.</p>

<p>We had early angel investors, including Roger Ver, who helped get the project started. But we have not depended on institutional venture-capital funding. Development has been sustained primarily through a share of the block reward and donations from people who believe financial privacy is worth supporting.</p>

<p>First of all I want to thank Poramin, the guy who started it all with a crazy idea and trusted me to steward the project all these years while quietly supporting us behind the scenes.</p>

<p>I also want to thank our team, who have worked tirelessly to get us here. I’m often the person talking publicly about Firo, but the work I get to talk about comes from people who have spent years researching, building, testing and solving problems most users will never see. They deserve more recognition than they get. I’m grateful for the care they put into this project, and proud to work alongside them.</p>

<p>We have also been fortunate to have the support of <strong>Cypher Stack, Power Up Privacy and Arcadia</strong>. Their support has helped keep us running and allowed important work to continue through difficult periods. I don’t take any of that for granted.</p>

<p>Most importantly, thank you to our community.</p>

<p>That includes the people who have donated, but also those who contribute code, test releases, run infrastructure, community chats, help someone with their wallet or explain Firo to a friend. It includes people who have been patient with us, and people who have pushed us to do better. A project needs both.</p>

<p>Our <a href="https://funding.firo.org/">Community Funding System</a> is a good example of that participation. Recent funded projects include developer tools, the Spark Sync Monitor, a Spark Names directory and Sal &amp; Mark’s livestream sponsorship. Spark Name fees also support the independently overseen Community Fund. It is encouraging to see people finding useful ways to contribute and getting support to pursue them, without everything having to originate with the core team.</p>

<h2 id="making-sure-people-can-reach-firo">Making Sure People Can Reach Firo</h2>

<p>One of the harder lessons in this space is that good privacy technology does not guarantee people will be able to reach it. A currency can work as intended and still depend heavily on a few businesses for buying, selling and liquidity.</p>

<p>Exchange Addresses were one response. Firo pioneered a transparent-deposit approach to meet Binance and regulator requirements while keeping private transactions available elsewhere on the network. Our approach helped establish a path for other privacy projects, including Zcash with its related TEX address format. But meeting an exchange’s requirements still leaves you dependent on its future decisions.</p>

<p>That is why we were working towards Rosen Bridge well before this launch. We <a href="https://firo.org/2026/03/19/firo-rosen-bridge-opinion-piece.html">publicly set out the reasoning in March 2026</a>: Firo needed more routes to market that the community could help build itself.</p>

<p>Our <a href="https://firo.org/2026/09/15/rsfiro-live.html">Rosen integration is now live</a>, allowing people to bridge FIRO into rsFIRO and redeem it back again, with markets on Ethereum, BNB Chain and Ergo. People can create pools and contribute liquidity on permissionless exchanges without waiting for a native FIRO listing.</p>

<p>In the volume snapshot we were tracking on <strong>19 September 2026</strong>, rsFIRO was at approximately <strong>US$86,000</strong>, compared with <strong>US$275,000</strong> in reported native FIRO volume on centralised exchanges. That is almost one-third as much trading volume, just days after launch.</p>

<p>There are trade-offs: rsFIRO is transparent and introduces bridge and Guard-federation dependencies. Native FIRO and Spark remain the route for private transactions.</p>

<p>This is why Rosen is one part of a broader effort. We also want to pursue native-asset liquidity opportunities through projects such as SeraiDEX and THORChain, rather than rely on any single route. Those remain goals, not promised integrations.</p>

<p>I’m grateful to the Rosen team and everyone who helped with testing, integration and the first markets. This gives our community something useful to build on.</p>

<h2 id="why-im-still-excited">Why I’m Still Excited</h2>

<p>Our research is continuing too, including work towards a <a href="https://forum.firo.org/t/firo-post-quantum/2935">post-quantum privacy protocol</a>.</p>

<p>The challenge is to make that security practical: transactions people can afford, wallets they can run and a migration path they can use safely. Those are the kinds of questions that have kept us working all these years. I still find them interesting, and I still think the answers matter.</p>

<p>There is plenty else to do. We need to make Firo easier to use, help developers build with it, grow liquidity and explain ourselves better. Research and longevity do not automatically bring adoption.</p>

<p>But I do think there is a substantial project here that more people would appreciate if they got to know it.</p>

<p>We have a body of research that has helped others, a working private-payment system and people contributing useful things around it. Now we are seeing the beginnings of a broader market for FIRO that our community can help sustain.</p>

<p>That is what makes this moment interesting to me. Work that has taken years is becoming something more people can use.</p>

<p>For those discovering financial privacy through Zcash, I hope that interest leads you to explore the wider community too. You don’t need to choose a side to appreciate the different approaches people are taking.</p>

<p>And for those who have been here with us: thank you. A lot of what I’ve described exists because you helped make it possible.</p>

<p>After nearly ten years, I’m still excited about where Firo can go. I would love to see more people become part of it.</p>]]></content><author><name>Reuben Yap</name></author><category term="community" /><summary type="html"><![CDATA[By Reuben Yap, Co-Founder of Firo]]></summary></entry><entry><title type="html">Firominer 1.4.0 Brings Firo’s Reference Miner Back Up to Speed</title><link href="https://firo.org/2026/09/18/firominer-140-release.html" rel="alternate" type="text/html" title="Firominer 1.4.0 Brings Firo’s Reference Miner Back Up to Speed" /><published>2026-09-18T00:00:00+00:00</published><updated>2026-09-18T00:00:00+00:00</updated><id>https://firo.org/2026/09/18/firominer-140-release</id><content type="html" xml:base="https://firo.org/2026/09/18/firominer-140-release.html"><![CDATA[<p>Firominer 1.4.0 is out. It’s our open source FiroPoW miner, and it now mines Firo on both NVIDIA and AMD GPUs within roughly 1% of the performance of popular closed-source miners. It has no developer fee, supports solo mining directly from your own Firo node, and all of its code is on GitHub under the GPL-3.0 license meaning anyone using or modifying this code similarly has to open source their modifications and improvements.</p>

<p>Download it from the <a href="https://github.com/firoorg/firominer/releases">v1.4.0 release page</a>.</p>

<h2 id="why-we-updated-the-reference-miner">Why We Updated the Reference Miner</h2>

<p>Firominer was always meant to be a reference miner: a working, open implementation of FiroPoW that others could take, improve and maintain as their own miners.</p>

<p>Instead, the network ended up relying on a set of closed-source miners. Several of these are no longer maintained. Others still charge fees of up to 2%, even though their FiroPoW support has seen little development, in some cases for years. Miner developers are entitled to charge for their work. Still, it left Firo miners with few options that were both up to date and free to use.</p>

<p>So we took the initiative and brought the reference miner up to date ourselves. We made it competitive on performance and added support for current GPUs and drivers.</p>

<p>In our own testing of 1.4.0 on real hardware, and in reports from community miners, Firominer now comes within about 1% of closed-source alternatives on both NVIDIA (CUDA) and AMD (OpenCL) cards. Those miners charge developer fees of up to 2% of hashing time, while Firominer charges nothing. Once fees are counted, the difference in what reaches your wallet is small, and against the higher-fee miners Firominer comes out ahead.</p>

<h2 id="why-open-source-miners-matter">Why Open Source Miners Matter</h2>

<h3 id="you-can-check-what-runs-on-your-rig">You Can Check What Runs on Your Rig</h3>

<p>A miner runs for days at a time with direct access to your hardware, often on the same machine as your wallet. With Firominer, anyone can read the code, build it from source and confirm it does what it says. Each release also ships with a combined <em>SHA256SUMS.txt</em> file, so you can check that the archive you downloaded is the one we published.</p>

<h3 id="solo-mining-keeps-firo-decentralized">Solo Mining Keeps Firo Decentralized</h3>

<p>Firo’s network difficulty is low enough that solo mining is a realistic option. Every block you find pays the full reward straight to your own address. Most closed-source FiroPoW miners only support pool mining. With those miners you pay a pool fee on top of the miner’s fee, and your hashrate adds to what large pools already control.</p>

<p>Firominer connects directly to your own Firo node and mines on its block template, with no pool in between. Every solo miner adds another independent operator building blocks, which spreads block production more widely. Solo payouts arrive less regularly than pool payouts, but you keep all of each reward. You can also sign the blocks you find with a custom message by applying a small companion patch to the Firo daemon.</p>

<h3 id="anyone-can-carry-it-forward">Anyone Can Carry It Forward</h3>

<p>Open code doesn’t depend on any one team, including ours. Anyone can fork Firominer, improve it and release their own miner under its GPL-3.0 license. That is what a reference miner is for, and we’d welcome other developers building on it.</p>

<h3 id="it-fits-how-firo-is-built">It Fits How Firo Is Built</h3>

<p>Firo develops its privacy technology in the open, because privacy claims only mean something when people can verify them. A competitive open source miner applies the same approach to the software that secures the network.</p>

<h2 id="whats-changed-since-110">What’s Changed Since 1.1.0</h2>

<p>If you last used Firominer at 1.1.0, these are the changes that matter most:</p>

<ul>
  <li><strong>AMD support is back.</strong> Version 1.1.0 shipped without an AMD build because its OpenCL performance wasn’t competitive. 1.4.0 includes an OpenCL package with a reworked OpenCL path that brings AMD cards close to other miners.</li>
  <li><strong>Current NVIDIA GPUs and drivers.</strong> The CUDA package is built on CUDA 12.9 Update 2, with improved work scheduling. The runtime libraries are included, so you don’t need a separate CUDA install. Older Maxwell, Pascal and Volta cards still work on R575 or R580 drivers.</li>
  <li><strong>Better GPU detection.</strong> An updated OpenCL loader detects current AMD and NVIDIA drivers on Windows. On Linux, more OpenCL runtimes are recognized, including Mesa Rusticl.</li>
  <li><strong>More reliable pool and solo mining.</strong> Stratum and getwork handling have been hardened, with better reconnection and device recovery. You can also choose between mainnet, testnet, devnet and regtest.</li>
  <li><strong>Updated, verifiable packages.</strong> Dependencies are current, including OpenSSL 3.5 LTS. Linux and Windows packages come with checksums and list their dependency versions and licenses.</li>
  <li><strong>Easier start on Windows.</strong> Windows packages include a mine_firo.bat launcher. Edit it with your pool and wallet details, then run it to start mining.</li>
</ul>

<p>The full list is in the <a href="https://github.com/firoorg/firominer/blob/main/CHANGELOG.md">changelog</a>.</p>

<h2 id="getting-started">Getting Started</h2>

<p>Download Firominer 1.4.0 from the <a href="https://github.com/firoorg/firominer/releases/tag/v1.4.0">release page</a>. Our <a href="https://firo.org/guide/how-to-mine-firo.html">mining guide</a> explains how to set it up for pool or solo mining.</p>

<h2 id="thank-you">Thank You</h2>

<p>A big thanks to Zed, Centaurea, Flow666, Kgiggles and lolliedb for helping us test Firominer 1.4.0. Your feedback and reports were invaluable for this release.</p>

<h2 id="help-us-improve-it">Help Us Improve It</h2>

<p>Run Firominer on your own cards, compare it with what you use now, and tell us how it goes. Benchmarks, bug reports and pull requests are all welcome on <a href="https://github.com/firoorg/firominer">GitHub</a>. If you run a pool, please consider adding Firominer to your setup guides.</p>]]></content><author><name>Reuben Yap</name></author><category term="community" /><summary type="html"><![CDATA[Firominer 1.4.0 is out. It’s our open source FiroPoW miner, and it now mines Firo on both NVIDIA and AMD GPUs within roughly 1% of the performance of popular closed-source miners. It has no developer fee, supports solo mining directly from your own Firo node, and all of its code is on GitHub under the GPL-3.0 license meaning anyone using or modifying this code similarly has to open source their modifications and improvements.]]></summary></entry><entry><title type="html">FIRO Goes Multichain: rsFIRO Is Live on Rosen Bridge</title><link href="https://firo.org/2026/09/15/rsfiro-live.html" rel="alternate" type="text/html" title="FIRO Goes Multichain: rsFIRO Is Live on Rosen Bridge" /><published>2026-09-15T00:00:00+00:00</published><updated>2026-09-15T00:00:00+00:00</updated><id>https://firo.org/2026/09/15/rsfiro-live</id><content type="html" xml:base="https://firo.org/2026/09/15/rsfiro-live.html"><![CDATA[<p>FIRO is now live on Rosen Bridge. You can move native FIRO to other supported blockchains as <a href="https://www.coingecko.com/en/coins/rsfiro">rsFIRO</a>, trade it there, and redeem it back to native FIRO. Trading pools are already available on <a href="https://app.uniswap.org/explore/pools/ethereum/0x385CD0e67CEae18d38c415BB01Df62BacE0C25BA">Uniswap on Ethereum</a>, <a href="https://pancakeswap.finance/liquidity/pool/bsc/0x24EBd6F2b918437E0353DBB825bf82832b3cad27?chain=bsc">PancakeSwap on BNB Chain</a> and <a href="https://dex.mewfinance.com/ergo/liquidity/d86f6508c6b665bf4ba0bd3b56f7090404665b0cef26e5202d91127ed538f47c">Mew Finance on Ergo</a>.</p>

<p>We have been <a href="https://firo.org/2026/03/19/firo-rosen-bridge-opinion-piece.html">working towards this</a> because people need ways to acquire and trade FIRO that do not depend on a handful of exchanges continuing to list it. Watch the video on this rationale <a href="https://www.youtube.com/watch?v=Ki5HIZn34F4">here</a>.</p>

<p>Rosen Bridge gives us another option. It also gives the Firo community a more direct role in building the markets people use.</p>

<h2 id="building-liquidity-without-waiting-for-a-listing">Building Liquidity Without Waiting for a Listing</h2>

<p>On Ethereum, rsFIRO works as a standard ERC-20 token. That makes it usable on the most popular decentralized exchanges without each platform having to integrate the Firo blockchain and its wallet software.</p>

<p>On permissionless exchanges such as Uniswap, anyone can create a pool or contribute liquidity. There is no listing application to submit or exchange approval to wait for.</p>

<p>For example, a community member can contribute rsFIRO and ETH to a pool. Other users can then trade against that pool without the liquidity provider needing to be online to accept each trade or run a trading bot. Providers can earn a share of trading fees, although providing liquidity carries risks, including losses compared with simply holding the assets.</p>

<p>A separate rsFIRO pair is not necessarily needed for every token someone wants to trade. Where suitable pools and routing support exist, a swap can pass through an intermediate asset - for example, rsFIRO to ETH, then ETH to another token. The available liquidity and fees still determine whether that trade offers a reasonable price.</p>

<p>The bridge makes these markets possible. Growing their liquidity will take participation from holders, traders and builders.</p>

<p>Today there are already <a href="https://app.uniswap.org/explore/tokens/ethereum/0x2744eA5Ac9b11CB5E3CD63D3a88E858336aEddC2">live Uniswap pools on Ethereum</a>, <a href="https://pancakeswap.finance/liquidity/pool/bsc/0x24EBd6F2b918437E0353DBB825bf82832b3cad27?chain=bsc">PancakeSwap on BNB Chain</a> and also <a href="https://dex.mewfinance.com/ergo/liquidity/d86f6508c6b665bf4ba0bd3b56f7090404665b0cef26e5202d91127ed538f47c">MewFinance on Ergo</a> allowing you to immediately swap and/or provide liquidity today!</p>

<p><img src="/blog/assets/rsfiro-live/uniswap.png" alt="uniswap" /></p>

<h2 id="how-rosen-bridge-works">How Rosen Bridge Works</h2>

<p>Rosen Bridge coordinates transfers through the Ergo blockchain using two groups of participants. <strong>Watchers</strong> monitor the connected chains and report bridge transactions. <strong>Guards</strong> independently verify those reports and collectively authorize the corresponding transfers. This two-stage verification adds protection against fabricated or mistaken reports: Guards check the source-chain transaction themselves rather than simply trusting the Watchers before authorizing a transfer.</p>

<p>When you bridge FIRO out, native FIRO is held in the bridge’s reserves and you receive rsFIRO on the destination chain, after applicable fees. Bridging back redeems rsFIRO for native FIRO.</p>

<p>Rosen distributes responsibility across a federation of Guards (current Guard set is 10) rather than putting one operator in charge while anyone with the requisite number of RSN can become a Watcher. Guards and watchers get paid by the bridging fee to continue providing their services.</p>

<h2 id="what-this-means-for-privacy">What This Means for Privacy</h2>

<p><strong>rsFIRO is not a private token.</strong> Its transfers and DEX trades are public, and the bridge itself does not provide Spark privacy.</p>

<p>To make private transactions, return to native FIRO and use Lelantus Spark. Doing so does not erase the public history of earlier bridge transfers or DEX trades.</p>

<p>This launch adds places to use and trade FIRO. It does not replace the privacy features on Firo’s own chain - though we will be posting a guide on how to minimize privacy leakage while using rsFIRO soon!</p>

<h2 id="before-you-bridge-or-trade-rsfiro-eth-or-bsc">Before You Bridge or Trade rsFIRO (ETH or BSC)</h2>

<h3 id="check-the-official-token-address">Check the Official Token Address</h3>

<p>Always verify the contract address before buying rsFIRO or adding it to your wallet. There can be other fake ‘rsFIROs’. A token’s name or symbol alone does not establish that it is genuine - fake tokens can copy both, only the contract address is definitive.</p>

<p><strong>Network:</strong> Ethereum mainnet<br />
<strong>Token:</strong> rsFIRO<br />
<strong>Contract address:</strong> <a href="https://etherscan.io/token/0x2744ea5ac9b11cb5e3cd63d3a88e858336aeddc2">0x2744ea5ac9b11cb5e3cd63d3a88e858336aeddc2</a><br />
<strong>Decimals:</strong> 8</p>

<p><strong>Network:</strong> BNB Chain<br />
<strong>Token:</strong> rsFIRO<br />
<strong>Contract address:</strong> <a href="https://bscscan.com/token/0x13cDb5F7f398F6AF2CC3B34EB04476af3488853f">0x13cDb5F7f398F6AF2CC3B34EB04476af3488853f</a><br />
<strong>Decimals:</strong> 8</p>

<p><strong>These are the token’s contract addresses, not a deposit address. Do not send funds directly to it</strong>. For other supported chains, check the official token identifier for that network rather than assuming the Ethereum address applies.</p>

<p>Note that sites like Coinmarketcap, Coingecko, Etherscan and BSCScan are in the process of validating and updating the token info on their respective sites. We recommend adding the respective tokens directly to your wallet and whitelisting it so you know you’re interacting with the correct rsFIRO.</p>

<h3 id="keep-eth-available-for-transaction-fees">Keep ETH Available for Transaction Fees</h3>

<p>You will need <strong>ETH/BNB in the same wallet on Ethereum/BNB mainnet</strong> to send or swap rsFIRO, provide liquidity, or initiate a bridge transfer back. These network fees are paid in ETH/BNB, not rsFIRO. When providing liquidity, keep some ETH/BNB aside for future transactions rather than committing your entire balance to the pool. You can do so by using a swap service such as <a href="https://wizardswap.io">wizardswap.io</a> or <a href="https://exolix.com">exolix.com</a> to swap some native FIRO to ETH/BNB to your ETH/BNB wallet address.</p>

<h3 id="do-not-send-rsfiro-to-a-native-firo-exchange-deposit-address">Do Not Send rsFIRO to a Native FIRO Exchange Deposit Address</h3>

<p><strong>rsFIRO and native FIRO are different assets on different networks.</strong> An exchange supporting FIRO does not automatically support rsFIRO.</p>

<p>Only send rsFIRO to a centralized exchange if its deposit instructions explicitly support <strong>rsFIRO on the exact network you are using</strong>. Otherwise, redeem it through Rosen Bridge to native FIRO in your own Firo wallet before making a native FIRO exchange deposit. Unsupported deposits may not be credited and may be unrecoverable.</p>

<h2 id="bridging-firo-to-ethereumbnb-chain">Bridging FIRO to Ethereum/BNB Chain</h2>

<p>Head to <a href="https://app.rosen.tech/">app.rosen.tech</a>,  select FIRO as the “Source” and FIRO as the token, then choose an available destination and enter in the address in which you want to receive your rsFIRO.</p>

<p><img src="/blog/assets/rsfiro-live/rosenbridge1.png" alt="rosenbridgeBridge" /></p>

<p>Follow the transfer instructions and check the receiving address, fees and expected amount before sending. Switch to your transparent balance and ensure you are using a supported wallet <strong>(Campfire or Reference Firo-QT)</strong> that can embed the additional data to allow the bridging.</p>

<p><img src="/blog/assets/rsfiro-live/bridge1.jpg" alt="bridge1" /></p>

<p><img src="/blog/assets/rsfiro-live/bridge2.jpg" alt="bridge2" /></p>

<p>Click on copy and paste the data into the “Send to” or “Pay to” address field. You will see a note that the <strong>transaction contains certain metadata. This is important as without it, your funds will not be bridged and require recovery!</strong></p>

<p><img src="/blog/assets/rsfiro-live/bridge3.png" alt="bridge3" /></p>

<p><img src="/blog/assets/rsfiro-live/bridge4.png" alt="bridge4" /></p>

<p>Allow a few hours for bridging (typically 2-4 hours). Rosen Bridge prioritizes security and safety over speed.</p>

<p>You can check on the <a href="https://app.rosen.tech/events">events page</a> to see how your bridging is coming along.</p>

<p><img src="/blog/assets/rsfiro-live/rosenbridge2.png" alt="rosenbridgeEvent" /></p>

<p>Rosen Bridge charges a fee of <strong>0.5% of the amount transferred, with a US$10 minimum, plus network fees</strong>. This is used to support bridge infrastructure and development. Fees can change, so check the app’s quote for your chosen route before proceeding. The minimum fee can make smaller transfers expensive.</p>

<p>If you can’t wait or your transfer is small, <strong>vsnation</strong>, a community member, has also built and runs <strong><a href="https://buyfiro.app/">buyfiro.app</a></strong>, an independent service for acquiring FIRO and bridging FIRO. It is separate from the Firo core team; check the service for its current routes, fees and availability.</p>

<p><img src="/blog/assets/rsfiro-live/buyfiroapp.png" alt="buyfiroapp" /></p>

<p>If you want to bridge back from rsFIRO to FIRO, it’s the same process but in reverse.</p>

<p><img src="/blog/assets/rsfiro-live/rosenbridge3.png" alt="rosenbridgeBridge2" /></p>

<h2 id="more-markets-fewer-gatekeepers">More Markets, Fewer Gatekeepers</h2>

<p>We are preparing a quest platform to encourage people to try Firo and rsFIRO. Details will follow on our <a href="https://x.com/firoorg">X account</a> and <a href="https://t.me/fironews">Telegram announcement channel</a>.</p>

<p>Thank you to the <a href="https://rosen.tech/">Rosen Bridge</a> team and everyone who has helped with the integration, testing and initial liquidity. We now have another way for people to reach FIRO - and a practical way for the community to help keep it accessible and unstoppable.</p>

<p>With rsFIRO live, the community can do more than ask for exchange listings. We can create trading pools, contribute liquidity and bring FIRO to new users across chains. Every additional market gives people another way to reach FIRO - and makes us less dependent on the platforms that can shut us out.</p>

<p><strong>An exchange can decide what it lists. It should not get to decide FIRO’s future.</strong></p>]]></content><author><name>Reuben Yap</name></author><category term="community" /><category term="news" /><summary type="html"><![CDATA[FIRO is now live on Rosen Bridge. You can move native FIRO to other supported blockchains as rsFIRO, trade it there, and redeem it back to native FIRO. Trading pools are already available on Uniswap on Ethereum, PancakeSwap on BNB Chain and Mew Finance on Ergo.]]></summary></entry><entry><title type="html">FIRO Is Now Listed on Nonlogs.io</title><link href="https://firo.org/2026/09/08/firo-nonlogs.html" rel="alternate" type="text/html" title="FIRO Is Now Listed on Nonlogs.io" /><published>2026-09-08T00:00:00+00:00</published><updated>2026-09-08T00:00:00+00:00</updated><id>https://firo.org/2026/09/08/firo-nonlogs</id><content type="html" xml:base="https://firo.org/2026/09/08/firo-nonlogs.html"><![CDATA[<p>FIRO is now listed on <a href="https://nonlogs.io/">Nonlogs.io</a>, a privacy-focused cryptocurrency exchange built around straightforward fees, transparent accounting, and clear control of your assets.</p>

<p>Three trading pairs are live:</p>

<ul>
  <li><a href="https://nonlogs.io/trade/FIRO-USDT">FIRO/USDT</a></li>
  <li><a href="https://nonlogs.io/trade/FIRO-BTC">FIRO/BTC</a></li>
  <li><a href="https://nonlogs.io/trade/FIRO-XMR">FIRO/XMR</a></li>
</ul>

<h2 id="about-nonlogsio">About Nonlogs.io</h2>

<p>Nonlogs.io is built for users who take their financial privacy seriously - and their privacy policy backs that up. To sign up, you need only a username and email address. There is no KYC, no government ID, no phone number, no residential address, and no third-party background checks. The platform collects only what it needs to operate the exchange: account credentials, trading records, wallet activity, and security data.</p>

<p>On the tracking front, Nonlogs uses only essential session and security cookies - no advertising pixels, no cross-site trackers, and no third-party analytics. They do not build advertising profiles or sell account data.</p>

<p>The exchange also publishes its reserves openly so users can verify solvency themselves - a standard that most centralized exchanges still don’t meet.</p>

<p>The FIRO/XMR pair is a particularly natural fit. Two of the most principled privacy coins in the space, tradeable directly against each other without routing through a centralized intermediary or wrapped token.</p>

<p>Start trading FIRO on Nonlogs.io today: <a href="https://nonlogs.io/">nonlogs.io</a></p>]]></content><author><name>Augustus Jong</name></author><category term="community" /><category term="news" /><category term="exchange" /><summary type="html"><![CDATA[FIRO is now listed on Nonlogs.io, a privacy-focused cryptocurrency exchange built around straightforward fees, transparent accounting, and clear control of your assets.]]></summary></entry><entry><title type="html">Firo v0.14.18.0 Released: Spark Functionality to be Fully Restored</title><link href="https://firo.org/2026/08/27/firo-v014180-release.html" rel="alternate" type="text/html" title="Firo v0.14.18.0 Released: Spark Functionality to be Fully Restored" /><published>2026-08-27T00:00:00+00:00</published><updated>2026-08-27T00:00:00+00:00</updated><id>https://firo.org/2026/08/27/firo-v014180-release</id><content type="html" xml:base="https://firo.org/2026/08/27/firo-v014180-release.html"><![CDATA[<p>We have released <strong>Firo v0.14.18.0</strong>, the mandatory hard fork release that restores full Spark functionality following the <a href="https://firo.org/2026/08/13/spark-vulnerability-mitigated.html">Spark vulnerability mitigation announced earlier this month</a>.</p>

<p>The hard fork will activate at <strong>block 1,371,000, approximately September 4, 2026 at 10:00 UTC.</strong></p>

<p><strong>All Firo wallet users, full node and masternode operators, miners, exchanges, and other service providers should upgrade to v0.14.18.0 before the activation block.</strong></p>

<h2 id="what-changes">What Changes</h2>

<p>As described in our previous update, the Spark vulnerability affected <strong>multi-input Spark spends</strong>. Single-input Spark transactions were unaffected.</p>

<p>To secure the network while a permanent fix was prepared and reviewed, v0.14.17.2 temporarily restricted Spark spends to a single input.</p>

<p>Firo v0.14.18.0 introduces <strong>a new versioned Spark spend format containing the permanent fix.</strong></p>

<p>Until block 1,371,000, the existing single-input restriction remains in place. Once the hard fork activates, wallets running v0.14.18.0 will automatically begin using the new spend format and <strong>normal multi-input Spark spending will be restored.</strong></p>

<p>There is <strong>no migration required</strong>. Existing Spark coins, balances, addresses and wallet keys remain valid.</p>

<h2 id="what-you-need-to-do">What You Need To Do</h2>

<p><strong>Upgrade to Firo v0.14.18.0 before block 1,371,000.</strong></p>

<p>You can obtain the latest release from:</p>

<ul>
  <li><a href="https://firo.org/get-firo/download/">Firo Downloads</a></li>
  <li><a href="https://github.com/firoorg/firo/releases/tag/v0.14.18.0">Firo GitHub Releases</a></li>
</ul>

<p>As this is a hard fork, nodes that have not upgraded will no longer remain compatible with the network once the activation height is reached.</p>

<p>If you do not need to spend your Spark funds immediately, we continue to recommend <strong>waiting until the hard fork activates before making Spark transactions.</strong></p>

<p>Single-input Spark spends remain available before activation for users who need to move funds, but splitting a payment across multiple single-input transactions can reveal correlations between transaction amounts and therefore provide weaker privacy than a normal multi-input Spark spend.</p>

<h2 id="additional-security-hardening">Additional Security Hardening</h2>

<p>While preparing the permanent fix, we used the opportunity to conduct a broader review of the Spark implementation and surrounding consensus code.</p>

<p>v0.14.18.0 therefore includes a number of additional hardening measures beyond the original vulnerability fix, including improvements to Spark transaction validation, proof verification, duplicate mint handling, reorganisation handling and validation of malformed Spark data.</p>

<p>The release also includes additional wallet, P2P and node stability fixes.</p>

<p>These changes do not require users to take any action beyond upgrading.</p>

<h2 id="responsible-disclosure-and-review">Responsible Disclosure and Review</h2>

<p>We would once again like to thank <strong>Carter Annandale (@carter-0)</strong>, who responsibly disclosed the original vulnerability, and <strong>Giap Vu</strong>, who independently identified and reported the same issue shortly afterwards.</p>

<p>The permanent fix and surrounding changes have undergone extensive review by the Firo core team together with <strong>Cypher Stack</strong>, with additional review assistance from <strong>HashCloak</strong>.</p>

<p>We are particularly grateful to everyone who assisted during the initial coordinated mitigation, including the mining pools and masternode hosting providers who deployed the protective changes before the vulnerability was publicly announced.</p>

<p>Their fast response allowed us to secure the network without exposing the vulnerability while a significant portion of the network remained susceptible.</p>

<h2 id="what-happens-next">What Happens Next</h2>

<p>Once block 1,371,000 is reached:</p>

<ul>
  <li>The new versioned Spark spend format activates.</li>
  <li>Full multi-input Spark spending is restored.</li>
  <li>The temporary privacy limitations associated with single-input-only spending are removed.</li>
  <li>Existing Spark funds continue to work without migration or reminting.</li>
</ul>

<p>As promised in our <a href="https://firo.org/2026/08/13/spark-vulnerability-mitigated.html">previous announcement</a>, we will publish a <strong>full technical disclosure and post-mortem after the hard fork has successfully activated.</strong></p>

<p>This will cover the underlying cryptographic issue, why it affected multi-input transactions, how the mitigation worked, how the permanent fix addresses it, and the lessons we have taken from the incident.</p>

<p>For now, the most important action is straightforward:</p>

<p><strong>Upgrade to Firo v0.14.18.0 before block 1,371,000.</strong></p>]]></content><author><name>Augustus Jong</name></author><category term="community" /><category term="news" /><summary type="html"><![CDATA[We have released Firo v0.14.18.0, the mandatory hard fork release that restores full Spark functionality following the Spark vulnerability mitigation announced earlier this month. The hard fork will activate at block 1,371,000, approximately September 4, 2026 at 10:00 UTC. All Firo wallet users, full node and masternode operators, miners, exchanges, and other service providers should upgrade to v0.14.18.0 before the activation block. What Changes As described in our previous update, the Spark vulnerability affected multi-input Spark spends. Single-input Spark transactions were unaffected. To secure the network while a permanent fix was prepared and reviewed, v0.14.17.2 temporarily restricted Spark spends to a single input. Firo v0.14.18.0 introduces a new versioned Spark spend format containing the permanent fix. Until block 1,371,000, the existing single-input restriction remains in place. Once the hard fork activates, wallets running v0.14.18.0 will automatically begin using the new spend format and normal multi-input Spark spending will be restored. There is no migration required. Existing Spark coins, balances, addresses and wallet keys remain valid. What You Need To Do Upgrade to Firo v0.14.18.0 before block 1,371,000. You can obtain the latest release from: Firo Downloads Firo GitHub Releases As this is a hard fork, nodes that have not upgraded will no longer remain compatible with the network once the activation height is reached. If you do not need to spend your Spark funds immediately, we continue to recommend waiting until the hard fork activates before making Spark transactions. Single-input Spark spends remain available before activation for users who need to move funds, but splitting a payment across multiple single-input transactions can reveal correlations between transaction amounts and therefore provide weaker privacy than a normal multi-input Spark spend. Additional Security Hardening While preparing the permanent fix, we used the opportunity to conduct a broader review of the Spark implementation and surrounding consensus code. v0.14.18.0 therefore includes a number of additional hardening measures beyond the original vulnerability fix, including improvements to Spark transaction validation, proof verification, duplicate mint handling, reorganisation handling and validation of malformed Spark data. The release also includes additional wallet, P2P and node stability fixes. These changes do not require users to take any action beyond upgrading. Responsible Disclosure and Review We would once again like to thank Carter Annandale (@carter-0), who responsibly disclosed the original vulnerability, and Giap Vu, who independently identified and reported the same issue shortly afterwards. The permanent fix and surrounding changes have undergone extensive review by the Firo core team together with Cypher Stack, with additional review assistance from HashCloak. We are particularly grateful to everyone who assisted during the initial coordinated mitigation, including the mining pools and masternode hosting providers who deployed the protective changes before the vulnerability was publicly announced. Their fast response allowed us to secure the network without exposing the vulnerability while a significant portion of the network remained susceptible. What Happens Next Once block 1,371,000 is reached: The new versioned Spark spend format activates. Full multi-input Spark spending is restored. The temporary privacy limitations associated with single-input-only spending are removed. Existing Spark funds continue to work without migration or reminting. As promised in our previous announcement, we will publish a full technical disclosure and post-mortem after the hard fork has successfully activated. This will cover the underlying cryptographic issue, why it affected multi-input transactions, how the mitigation worked, how the permanent fix addresses it, and the lessons we have taken from the incident. For now, the most important action is straightforward: Upgrade to Firo v0.14.18.0 before block 1,371,000.]]></summary></entry><entry><title type="html">Firo Community Fund Committee: 5th Term Confirmed</title><link href="https://firo.org/2026/08/17/5th-term-cfc-members-formed.html" rel="alternate" type="text/html" title="Firo Community Fund Committee: 5th Term Confirmed" /><published>2026-08-17T00:00:00+00:00</published><updated>2026-08-17T00:00:00+00:00</updated><id>https://firo.org/2026/08/17/5th-term-cfc-members-formed</id><content type="html" xml:base="https://firo.org/2026/08/17/5th-term-cfc-members-formed.html"><![CDATA[<p>The 7 member Community Fund Committee (“CFC”) is formed to oversee the Firo Community Fund (“FCF”) has been completed!</p>

<p>The following community members will serve as CFC members for a period of 1 year starting from September 2026:</p>

<ul>
  <li>rottenwheel</li>
  <li>nrsimha</li>
  <li>Jagmo (jh_ride)</li>
  <li>Firofan</li>
  <li>ddadybayo</li>
  <li>vaselexa (centaurea)</li>
  <li>Thorfried</li>
</ul>

<p>The newly elected committee brings together long-standing community members, technical experts, and developers who have consistently participated in proposal reviews and guided the allocation of the Firo Community Fund.</p>

<p>We would like to extend our gratitude to the newly elected members for serving on the Firo Community Fund (FCF) and for contributing to the decentralization of funding decisions. We also sincerely thank the outgoing committee members for their dedication and service to the project.</p>

<h2 id="how-to-apply-for-funding-from-the-firo-community-fund">How to apply for funding from the Firo Community Fund</h2>

<p>Anyone is welcome to request funding from the FCF by submitting a proposal through the <a href="https://funding.firo.org/">Firo Crowdfunding System</a> and opening a <a href="https://forum.firo.org/c/fcs-proposals/16">forum thread</a> to invite community discussion. In addition, the Community Fund Committee has the authority to put forward proposals of their own for consideration.</p>

<h2 id="what-are-the-responsibilities-of-the-community-fund-committee">What are the responsibilities of the Community Fund Committee?</h2>

<ol>
  <li>To decide along with taking into account community feedback on how the Firo Community Fund should be utilised.</li>
  <li>To help evaluate community requests for funding, do due diligence of applicants applying for funding and obtain all necessary information to ensure sufficient detail for scope of work.</li>
  <li>To evaluate and approve payment of milestone requests.</li>
  <li>To make all reasonings of the CFC for approval/rejection public.</li>
  <li>CFC can request for the core team’s feedback and opinion on proposals.</li>
  <li>To always conduct themselves with professionalism without resorting to personal attacks or insults.</li>
</ol>

<h2 id="how-will-the-firo-community-fund-fcf-be-utilised">How will the Firo Community Fund (FCF) be utilised?</h2>

<ol>
  <li>FCF funds must always be utilised for the benefit of Firo. Research, development or promotional activities that do not directly benefit Firo should not be undertaken.</li>
  <li>All FCF expenditure has to be disclosed. Any proposal that does not allow this will not be able to be funded from the FCF.</li>
  <li>FCF funds should not be used for giveaways even for the purpose of promoting adoption or participation.</li>
  <li>FCF funds should not be used to host purely social events. Educational or awareness events are acceptable but must be the primary component of the event.</li>
  <li>FCF funds should be used and while there shouldn’t be a pressure to spend funds, the FCF should not be hoarded.</li>
  <li>CFC can choose to use the FCF to employ contractors to embark on specific tasks or roles that will report directly to the CFC.</li>
  <li>Should the CFC deem fit, FCF funds can be burnt by sending it to this <a href="https://explorer.firo.org/address/aFiroBurningAddressDoNotSendrPtjYA">burn address</a>.</li>
  <li>FCF funds address can be viewed <a href="https://explorer.firo.org/address/aFA2TbqG9cnhhzX5Yny2pBJRK5EaEqLCH7">here</a>.</li>
</ol>

<h2 id="where-can-i-see-the-deliberations-of-the-community-fund-committee">Where can I see the deliberations of the Community Fund Committee?</h2>

<p>All discussions of the CFC can be seen in our <a href="https://discord.gg/TGZPRbRT3Y">Discord</a> in the channel #communityfund or The <a href="https://t.me/firocfc">CFC telegram group</a> and is read-only. You will need to have verified status by passing the captcha to view the channel.</p>]]></content><author><name>Augustus Jong</name></author><category term="community" /><category term="news" /><summary type="html"><![CDATA[The 7 member Community Fund Committee (“CFC”) is formed to oversee the Firo Community Fund (“FCF”) has been completed! The following community members will serve as CFC members for a period of 1 year starting from September 2026: rottenwheel nrsimha Jagmo (jh_ride) Firofan ddadybayo vaselexa (centaurea) Thorfried The newly elected committee brings together long-standing community members, technical experts, and developers who have consistently participated in proposal reviews and guided the allocation of the Firo Community Fund. We would like to extend our gratitude to the newly elected members for serving on the Firo Community Fund (FCF) and for contributing to the decentralization of funding decisions. We also sincerely thank the outgoing committee members for their dedication and service to the project. How to apply for funding from the Firo Community Fund Anyone is welcome to request funding from the FCF by submitting a proposal through the Firo Crowdfunding System and opening a forum thread to invite community discussion. In addition, the Community Fund Committee has the authority to put forward proposals of their own for consideration. What are the responsibilities of the Community Fund Committee? To decide along with taking into account community feedback on how the Firo Community Fund should be utilised. To help evaluate community requests for funding, do due diligence of applicants applying for funding and obtain all necessary information to ensure sufficient detail for scope of work. To evaluate and approve payment of milestone requests. To make all reasonings of the CFC for approval/rejection public. CFC can request for the core team’s feedback and opinion on proposals. To always conduct themselves with professionalism without resorting to personal attacks or insults. How will the Firo Community Fund (FCF) be utilised? FCF funds must always be utilised for the benefit of Firo. Research, development or promotional activities that do not directly benefit Firo should not be undertaken. All FCF expenditure has to be disclosed. Any proposal that does not allow this will not be able to be funded from the FCF. FCF funds should not be used for giveaways even for the purpose of promoting adoption or participation. FCF funds should not be used to host purely social events. Educational or awareness events are acceptable but must be the primary component of the event. FCF funds should be used and while there shouldn’t be a pressure to spend funds, the FCF should not be hoarded. CFC can choose to use the FCF to employ contractors to embark on specific tasks or roles that will report directly to the CFC. Should the CFC deem fit, FCF funds can be burnt by sending it to this burn address. FCF funds address can be viewed here. Where can I see the deliberations of the Community Fund Committee? All discussions of the CFC can be seen in our Discord in the channel #communityfund or The CFC telegram group and is read-only. You will need to have verified status by passing the captcha to view the channel.]]></summary></entry><entry><title type="html">Spark Vulnerability Mitigated</title><link href="https://firo.org/2026/08/13/spark-vulnerability-mitigated.html" rel="alternate" type="text/html" title="Spark Vulnerability Mitigated" /><published>2026-08-13T00:00:00+00:00</published><updated>2026-08-13T00:00:00+00:00</updated><id>https://firo.org/2026/08/13/spark-vulnerability-mitigated</id><content type="html" xml:base="https://firo.org/2026/08/13/spark-vulnerability-mitigated.html"><![CDATA[<p>A vulnerability was identified via responsible disclosure and has been mitigated in the Spark protocol. It affects multi-input Spark spends only; single-input spends are unaffected. Your wallet and private keys are safe. This is not a wallet-compromise or key-theft bug. No one can access your wallet, obtain your keys, or remove coins from your address. This is a supply-integrity (inflation) issue: under specific conditions an attacker could forge Spark coins in multi-input transactions. We have mitigated it by disabling multi-input spends temporarily and are monitoring supply closely.</p>

<p><strong>Please upgrade to <a href="https://github.com/firoorg/firo/releases/tag/v0.14.17.2">v0.14.17.2</a>.</strong> Until the next hard fork, Spark spends are limited to a single input. For maximum privacy, wait for the next hard fork (v0.14.18.0) before spending Spark. Single-input-only spends can leak amount correlations (see below).</p>

<h2 id="what-happened">What Happened</h2>

<p>On 1 August 2026 we received a vulnerability disclosure from <a href="https://carter.red">Carter Annandale</a> regarding the Spark protocol. We acknowledged it on 2 August and confirmed its validity: the issue allows an attacker to forge Spark coins in multi-input transactions. Single-input transactions are not affected. On 6 August we received an independent report of the same issue from <a href="https://x.com/realg14pppp">Giap Vu.</a></p>

<p>Aside from a small, controlled amount (~200 FIRO) generated on mainnet by the researcher to validate the finding, we have found no evidence of inflation at this time and are continuing to monitor closely.</p>

<h2 id="on-the-nature-of-the-bug">On the Nature of the Bug</h2>

<p>The vulnerability originated in the Spark cryptography paper and was missed by both cryptography audits (we commissioned two) and the code audit. It is not a typo, a missing bounds check, or an obviously dropped validation but instead is a subtle error. Reassuringly, it is straightforward to fix and does not require any overhaul or redesign of the Lelantus Spark protocol.</p>

<h2 id="how-we-mitigated-it">How We Mitigated It</h2>

<p>The main challenge was deploying a fix without alerting adversaries while the network updated. Working with key infrastructure providers, we first deployed a patch that disables multi-input Spark spends, securing the network ahead of a public release. Our thanks to WoolyPooly, Cedric Crispin, and Rplant on the mining side and Nodehub, Allnodes, Evoznode and Pecunia on the masternode side for their fast updates, which gave us the consensus needed to secure the network. Others were contacted but did not respond.</p>

<p>The fix was developed and reviewed by the Firo core team together with the developers and cryptographers at <a href="https://cypherstack.com/">Cypher Stack</a>, and additionally reviewed by <a href="https://hashcloak.com/">HashCloak</a> (one of the original Spark cryptography and code auditors). The team at Cypher Stack had jumped into action despite a busy period and did a lot of the heavy lifting, unprompted and voluntarily, greatly relieving the load. In particular, we would like to thank Josh Babb, Samuel Graf Noether, Julian Anderson, Dan Miller and Diego Salazar. HashCloak has also been a long time supporter of Firo and we would like to thank Mikerah and Manish for helping to validate the fixes.</p>

<h2 id="releases">Releases</h2>

<p><strong><a href="https://github.com/firoorg/firo/releases/tag/v0.14.17.2">v0.14.17.2 (available now)</a>:</strong> Allows users to make single-input Spark spends if they need to move funds before the next hard fork. Note that because Spark mints cannot currently be consolidated, single-input spends may reveal some correlation between amounts.</p>

<p><strong>v0.14.18.0 (targeted for the 3rd week of August):</strong> A hard fork that re-enables full multi-input Spark spends. We will announce the exact activation height ahead of time. To protect your privacy, <strong>we recommend waiting until the v0.14.18.0 hard fork before making Spark spends, to avoid amount-correlation analysis.</strong></p>

<p>Full technical details of the fix will be published after the second hard fork has activated.</p>]]></content><author><name>Reuben Yap</name></author><category term="dev" /><category term="news" /><summary type="html"><![CDATA[A vulnerability was identified via responsible disclosure and has been mitigated in the Spark protocol. It affects multi-input Spark spends only; single-input spends are unaffected. Your wallet and private keys are safe. This is not a wallet-compromise or key-theft bug. No one can access your wallet, obtain your keys, or remove coins from your address. This is a supply-integrity (inflation) issue: under specific conditions an attacker could forge Spark coins in multi-input transactions. We have mitigated it by disabling multi-input spends temporarily and are monitoring supply closely.]]></summary></entry><entry><title type="html">Nomination Thread for a New Community Fund Committee 2026</title><link href="https://firo.org/2026/07/14/firo-cfc-nomination-5th-term.html" rel="alternate" type="text/html" title="Nomination Thread for a New Community Fund Committee 2026" /><published>2026-07-14T00:00:00+00:00</published><updated>2026-07-14T00:00:00+00:00</updated><id>https://firo.org/2026/07/14/firo-cfc-nomination-5th-term</id><content type="html" xml:base="https://firo.org/2026/07/14/firo-cfc-nomination-5th-term.html"><![CDATA[<p>The one year term of the <a href="https://forum.firo.org/t/firo-4th-community-fund-committee-elections/4114">4th CFC Committee</a> will be coming to an end in approximately 2 months and the time for the 5th CFC nominations is underway in preparation for the election.</p>

<p>Please express your interest in standing for election in the <a href="https://forum.firo.org/t/nominations-for-the-5th-community-fund-committee-cfc-are-now-open/4339">Forum thread here</a>. Do ensure you introduce yourself and why you are applying to the post and your experience/history with Firo.</p>

<p>The 7 member CFC forms an important role in gradually decentralizing governance and sets up an independent fund (Firo Community Fund) to be used for the benefit of Firo. The FCF has been used to fund various community management efforts, audits, social media/marketing support and also to assist the core team where additional funds are required.</p>

<p>Current CFC Members:</p>

<ol>
  <li>@FiroFiend</li>
  <li>@firofan</li>
  <li>@vaselexa</li>
  <li>@ddadybayo</li>
  <li>@rehrar</li>
  <li>@jagmot</li>
  <li>@Nrsimha</li>
</ol>

<p>CFC Committee positions are at this point in time done on a volunteer basis and we recommend only active and motivated members of the Firo community apply. There is no restriction on existing committee members seeking re-election.</p>

<p>Below is a reminder of the role of the CFC and the Firo Community Fund (FCF) it manages:</p>

<h2 id="brief-summary-of-how-the-cfc-came-to-be">Brief Summary of How the CFC Came to Be</h2>

<p>Firo conducted a series of community votes to adjust its tokenomics and established the Firo Community Fund. This process spanned several months and involved multiple vetted polls to ensure alignment with the community’s wishes. A committee comprising seven elected community members was established to manage fund allocation.</p>

<p>Following the nomination phase, nominees (who are new) undergo a vetting process, including an interview, to assess their eligibility and alignment with the community’s voting objectives. The interview, which can be conducted through text or online meetings, delves into the nominees’ beliefs in Firo, their grasp of Firo’s technology, personal background (without revealing sensitive information), and their vision for the fund’s utilization. Nominees not widely known in the community must provide proof of active participation for at least a year.</p>

<p>Moving on from these specifics, it’s essential to outline the responsibilities and prerequisites expected of a member of the Firo Community Fund Committee (CFC).</p>

<h2 id="responsibilities-of-community-fund-committee-members">Responsibilities of Community Fund Committee Members</h2>

<ol>
  <li>To decide along with taking into account community feedback on how the community fund should be utilized.</li>
  <li>To help evaluate community requests for funding, do due diligence on applicants applying for funding, and obtain all necessary information to ensure sufficient detail for the scope of work.</li>
  <li>To evaluate and approve payment of milestone requests.</li>
  <li>To make all reasoning of the CFC for approval/rejection public.</li>
  <li>CFC can request the core team’s feedback and opinion on proposals.</li>
  <li>To always conduct themselves with professionalism without resorting to personal attacks or insults.</li>
</ol>

<h2 id="minimum-requirements-to-be-eligible-to-be-a-committee-member">Minimum Requirements to Be Eligible to Be a Committee Member</h2>

<ol>
  <li>Be a recognized and active community member of Firo for at least a year, OR a recognized industry expert/specialist.</li>
  <li>Solid understanding of Firo’s technology stack and current roadmap and goals.</li>
  <li>Cannot be a current full-time member of the Firo core team. Part-time contributors or contractors of Firo’s core team are allowed but must be disclosed.</li>
  <li>Be able to attend a CFC meeting once a month or appoint a proxy to do the same (though proxies should be used sparingly).</li>
  <li>While a technical or development background isn’t required, having a few committee members with some technical background would be helpful in evaluating proposals.</li>
  <li>Be able to read, check and vote on proposals for funding at least once a week.</li>
  <li>Be 18 years old and above.</li>
</ol>

<h2 id="removal-of-cfc-members">Removal of CFC Members</h2>

<ol>
  <li>If a CFC member is suspected or found to have been involved in fraud, scam, or other deceitful behavior, the other CFC members can vote to remove them via majority vote.</li>
  <li>If a CFC member has acted in an unbecoming or unprofessional manner, the other CFC members can vote to remove them via a majority vote.</li>
  <li>If a CFC member is absent for 2 meetings in a row without due cause, they shall be removed automatically.</li>
  <li>If a CFC member has continuously failed to vote on proposals for funding, a vote shall be held at the next CFC meeting by the other CFC members on whether to remove them.</li>
  <li>If a CFC member is removed, nominations should be open for the spot for the remaining term.</li>
</ol>

<h2 id="meetings-quorums-and-voting">Meetings, Quorums, and Voting</h2>

<ol>
  <li>A meeting should be held at least once a month with CFC members. The purpose of this meeting is to discuss proposals or to decide how to allocate the FCF funds or any other matters arising. Given CFC members may be in different time zones, this should be taken into account when determining the time of the meeting and the opportunity to take turns for amenable timing.</li>
  <li>Core team members or their representatives should always be allowed to observe and attend all CFC meetings, but shall not have a vote unless otherwise specified.</li>
  <li>The minutes of these meetings shall always be publicly available.</li>
  <li>The meeting can be conducted by text or online meetings.</li>
  <li>A quorum should be 5 members. Votes are passed using a majority of votes. In the event of an equality of votes, the core team shall have a casting vote.</li>
  <li>Proposals for funding can be approved without the need for a meeting and shall be voted on in the proposal thread itself.</li>
  <li>When voting for or against a proposal for funding, all CFC members are required to state the reasoning behind their choice.</li>
  <li>Anyone can open a proposal for funding, including CFC members.</li>
  <li>If a CFC member is an applicant for funding, the member cannot vote on that proposal. Also, if a CFC member has a close relationship (e.g. family member, best friend, significant other, spouse) with the applicant for funding, the CFC member should disclose the relationship and put it to the other CFC members to decide whether the member should be allowed to vote or choose to abstain voluntarily.</li>
  <li>If the CFC wishes to make funds available to the core team to assist them (for instance to cover a shortfall or to pay for a specific employee to retain them), a higher vote threshold is required, which is 5 members out of 7 instead of the usual majority of votes.</li>
</ol>

<h2 id="general-guidelines-to-community-fund-usage">General Guidelines to Community Fund Usage</h2>

<ol>
  <li>Trust needs to be earned. While anyone can propose to be funded from the FCF, the person’s track record needs to be evaluated, the necessary due diligence needs to be taken, and milestone payments adjusted appropriately.</li>
  <li>The CFC can choose to employ contractors to embark on specific tasks, but shall seek community feedback. Where it involves core code, the CFC has to consult the core team.</li>
  <li>The CFC should not be used to host parties or purely social events. Educational or awareness events are okay but should be done with appropriate evidence and not paid upfront.</li>
  <li>The CFC is to be used and while there shouldn’t be pressure to spend the CFC funds, the CFC funds shouldn’t be hoarded.</li>
  <li>CFC funds should always be utilized for the benefit of Firo. Research or development that does not directly benefit Firo should not be undertaken.</li>
  <li>CFC funds should not be used for giveaways, even for the purpose of promoting adoption or participation. These have limited effects.</li>
  <li>All CFC expenditure has to be disclosed. Contractors that prohibit this should not be engaged.</li>
  <li>Should the CFC deem fit, FCF funds can be burnt by sending them to this burn address <a href="https://explorer.firo.org/address/aFiroBurningAddressDoNotSendrPtjYA">https://explorer.firo.org/address/aFiroBurningAddressDoNotSendrPtjYA</a>.</li>
  <li>FCF funds address can be viewed <a href="https://explorer.firo.org/address/aFA2TbqG9cnhhzX5Yny2pBJRK5EaEqLCH7">here</a>, which are from time to time anonymized.</li>
  <li>Utilization of CFC funds and proposals can always be viewed on the <a href="https://funding.firo.org/">Firo Community Crowdfunding</a> page under the category of CFC.</li>
</ol>

<h2 id="what-the-cfc-is-not">What the CFC Is NOT</h2>

<ol>
  <li>The CFC are NOT representatives of the opinion of the Firo Community. They are only tasked with matters to do with the Community Fund and do not replace the usual process of getting feedback from the general community and core team in implementing large changes.</li>
  <li>The CFC shall not represent itself as core team members or as representatives of the project.</li>
</ol>]]></content><author><name>Augustus Jong</name></author><category term="announcement" /><category term="news" /><category term="community" /><summary type="html"><![CDATA[The one year term of the 4th CFC Committee will be coming to an end in approximately 2 months and the time for the 5th CFC nominations is underway in preparation for the election.]]></summary></entry><entry><title type="html">Mandatory Release: Firo v0.14.16.1</title><link href="https://firo.org/2026/06/05/firo-v014161-release.html" rel="alternate" type="text/html" title="Mandatory Release: Firo v0.14.16.1" /><published>2026-06-05T00:00:00+00:00</published><updated>2026-06-05T00:00:00+00:00</updated><id>https://firo.org/2026/06/05/firo-v014161-release</id><content type="html" xml:base="https://firo.org/2026/06/05/firo-v014161-release.html"><![CDATA[<p>Firo v0.14.16.1 is a mandatory release. <strong>All users must update to this version even if they have already updated to v0.14.16.0.</strong> All wallets, full nodes, and masternodes must be updated prior to block 1,329,000 (approximately 22 June 2026).</p>

<p>As always, please <strong>backup your wallet</strong> before updating.</p>

<p>Download the latest release here: <a href="https://github.com/firoorg/firo/releases/tag/v0.14.16.1">https://github.com/firoorg/firo/releases/tag/v0.14.16.1</a></p>

<hr />

<h2 id="whats-new">What’s New</h2>

<h3 id="spark-name-overflow-fix">Spark Name Overflow Fix</h3>

<p>This release resolves an overflow bug in Spark Name handling that was present in v0.14.16.0. The fix is the primary reason this follow-up release is mandatory - all users on v0.14.16.0 must update to ensure correct Spark Name behavior at and beyond the activation block.</p>

<h3 id="minor-spark-name-vulnerability-fix">Minor Spark Name Vulnerability Fix</h3>

<p>Fixes a minor vulnerability where a Spark Name transfer permission could remain valid indefinitely. Transfer permissions now expire correctly, limiting the window in which they can be used.</p>

<h3 id="receive-request-model-fix">Receive Request Model Fix</h3>

<p>Fixes crashes in the receive request dialog and incorrect handling of recent request history in the Qt wallet.</p>

<h3 id="spark-address-book-refresh-fix">Spark Address Book Refresh Fix</h3>

<p>Fixes a bug where Spark address book options could remain unavailable after syncing past the Spark activation block, requiring a wallet restart to resolve. The wallet now correctly detects activation even when the sync jumps past the exact activation height.</p>

<h3 id="lelantus-strip">Lelantus Strip</h3>

<p>Internal cleanup work removing legacy Lelantus components as the protocol continues to consolidate around Lelantus Spark.</p>

<hr />

<h2 id="update-deadline">Update Deadline</h2>

<p>This is a mandatory update that supersedes v0.14.16.0. <strong>All wallets, full nodes, and masternodes must be updated to v0.14.16.1 before block 1,329,000, approximately 22 June 2026.</strong> This applies even if you recently updated to v0.14.16.0.</p>

<hr />

<h2 id="download">Download</h2>

<p>Binaries are available for Linux, macOS, and Windows on the <a href="https://github.com/firoorg/firo/releases/tag/v0.14.16.1">GitHub releases page</a>.</p>]]></content><author><name>Augustus Jong</name></author><category term="community" /><category term="dev" /><category term="news" /><summary type="html"><![CDATA[Firo v0.14.16.1 is a mandatory release. All users must update to this version even if they have already updated to v0.14.16.0. All wallets, full nodes, and masternodes must be updated prior to block 1,329,000 (approximately 22 June 2026).]]></summary></entry></feed>