Firo Hard Fork Activates to Fix Privacy Flaw Risking Endless Token Creation
Firo network upgrade closes inflation loophole
The Firo blockchain has activated a mandatory hard fork designed to repair a serious vulnerability in its privacy system. The change took effect at block height 1,371,000. This upgrade forces all network participants to update their software to version 0.14.18.0. Any node operator who fails to install the new version before the block height is reached will find their software incompatible with the rest of the network.
Key details of the upgrade
- The fork activates at block 1,371,000, which Firo estimated would arrive around 10 a.m. UTC on Friday.
- The release restores "multi-input Spark" transactions, a core privacy feature that had been restricted due to a security flaw.
- No migration of funds is required. Existing Spark coins, balances, and wallet keys remain valid and do not need to be moved or reminted.
- A researcher previously demonstrated the flaw by creating approximately 200 FIRO tokens in a controlled test on the main network.
Origin of the vulnerability
On August 13, Firo disclosed a flaw in its Spark transaction protocol. Spark is the system used for private transactions on the network. The bug existed in "multi-input spends," which allow a single transaction to combine funds from multiple private coin sources. Under specific conditions, this flaw could allow an attacker to forge coins and endlessly inflate the total supply of FIRO. However, the vulnerability did not compromise wallet security or private keys, nor could it be used to steal funds from an address. It also did not affect "single-input spends." To protect the supply during the interim, developers issued version 0.14.17.2. This temporary fix forced all Spark transactions to use only one input at a time. Users with larger payments had to split them into multiple separate transactions. While this prevented the inflation attack, it weakened privacy because the split transactions were more easily linked or correlated by observers.
How the new version fixes the issue
Version 0.14.18.0 introduces a new cryptographic standard called "versioned Chaum V2." This updated format permanently resolves the inflation risk while restoring full multi-input privacy functionality. Once the network reaches the activation block, updated wallets will automatically return to normal multi-input spending. The new software also ensures that historical Spark transactions continue to be validated correctly.
What is still unclear
Firo stated that it plans to publish a full technical disclosure and post-mortem after the fork activates. Details regarding the complete scope of the vulnerability and specific recommendations for long-term network monitoring have not yet been released.
Why this matters for the network
This event highlights the fragility of privacy coins when cryptographic assumptions are challenged. The stopgap measure showed that fixing a supply integrity issue often comes at the cost of user privacy. By restoring multi-input spends, the new version aims to ensure the currency remains both scarce and private.