github tempoxyz/tempo v1.16.0
Release v1.16.0

Release v1.16.0

Important

This release is required for the T12 network upgrade scheduled for testnet on October 8, 2026 16:00 CEST (1791468000) and mainnet on October 13, 2026 16:00 CEST (1791900000). Node operators must update before activation.

This release contains a breaking change for integrators & developers, please check the release notes below.

T12 adds configurable nonces for parallel expiring transactions, enables MPP sessions for closed-loop stablecoins, relaxes ABI validation, aligns Stablecoin DEX quote and swap calculations, and adds authorized burns for TIP-20 tokens.

Update Priority

User Class Priority
Validators High
RPC Nodes High

Nodes running an earlier release can fall out of sync at the T12 activation timestamp.

Activation Times

Network Date Timestamp
Testnet October 8, 2026 16:00 CEST (14:00 UTC) 1791468000
Mainnet October 13, 2026 16:00 CEST (14:00 UTC) 1791900000

TIPs included with T12

  1. TIP-1106: Configurable nonces for expiring transactions: Allows any uint64 value in the existing nonce field. Distinct nonces let otherwise identical transactions be submitted in parallel within the same validity window, without coordinating sequential nonces or adding access-list entries solely for uniqueness.
  2. TIP-1095: MPP sessions for closed-loop stablecoins: Enables recipient-restricted TIP-20 tokens to fund payment channels without requiring issuers to allowlist the channel reserve. Funding and settlement enforce TIP-403 permissions against the payer and payee; refunds can return unused funds to the original payer. Token pauses and account receive policies still apply.
  3. TIP-1116: Relaxed ABI validation: Accepts trailing bytes in otherwise valid calls to Tempo's native contracts, restoring compatibility with calldata suffixes rejected at T11. Other strict decoding checks remain.
  4. TIP-1088: Accurate swap quotes and cheaper execution: Uses the same per-order matching and rounding for quotes and swaps. For unchanged orderbook state, quotes match swap fill calculations. Removes redundant liquidity-tracking writes during swaps, order placement, and cancellation.
  5. TIP-1006: Authorized burns for TIP-20 tokens: Adds burnAt(from, amount) for contracts granted BURN_AT_ROLE, enabling issuer-authorized burn-and-mint bridging without a separate user token approval. Token pauses, protected-address checks, and applicable access-key spending limits still apply.

Operators

What's Changed

  • Finalization gossip enabled by default (#7950): Validators and certified followers now enable P2P finalization-certificate gossip automatically. Disable it with --consensus.devp2p.finalizations=false; it remains disabled in dev and uncertified follower modes.
  • Testnet network identity (#8064): Updates testnet network identities and activation epochs.
  • AA transaction pool (#8065): Refreshes the AA 2D pool's base fee on canonical state changes, keeping transaction ordering and eviction priorities current.
  • Expiring-nonce validation (#8066): Corrects pre-T12 expiring-nonce error classification while keeping ordinary nonce overflow permanently invalid.
  • Consensus snapshot replay (#8091): Resets the delivery batch on stale-skipped forkchoice updates to prevent snapshot replay from starving finalized deliveries.

Developers

Compatible tooling versions

Package Version Notes
Foundry nightly (2026-10-03) Includes T12 hardfork support and updated Tempo precompile bindings.
viem 2.57.3 Includes TIP-1106 expiring nonce preservation and TIP-1006 burnAt support, added in 2.57.2.
pytempo 0.6.1 Adds T12 burn_at and burn_at_role helpers and updated ABIs. Requires Python 3.10+.
tempo-go 0.6.1 Adds T12 expiring nonce discriminators and burnAt bindings.
tempo-alloy 1.16.0 Rust client and transaction builders with updated Tempo SDK dependencies. crates.io publication pending.
tempo-primitives 1.16.0 Shared Tempo transaction and signature types. crates.io publication pending.
tempo-contracts 1.16.0 Includes T12 burnAt, BURN_AT_ROLE, and BurnAt event bindings. crates.io publication pending.
tempo-chainspec 1.16.0 Includes T12 activation schedules for mainnet and testnet. crates.io publication pending.
tempo-hardfork 1.16.0 Includes T12 hardfork identifiers and activation timestamps. crates.io publication pending.
Zones v0.3.4 Includes T12 support and inheritance of the parent chain’s hardfork schedule.

Breaking behavior at T12

  • Native contract gas limits: Before writing to storage, a native contract call must have more than 2,300 gas remaining or it fails with an out-of-gas error. Re-estimate hardcoded transaction gas limits on T12 testnet and test any explicit caps on gas forwarded to native contracts. Fees remain based on gas actually used.
  • DEX tick liquidity storage: Stored tick liquidity totals stop updating at T12. Integrations reading those totals directly from storage must switch to getTickLevel() or sum the remaining amounts of active orders. Quote and swap APIs are unchanged.

Integration Notes

  • Assign distinct uint64 nonces to otherwise identical expiring transactions after activation. Ensure builders and signers preserve the supplied nonce, and remove access-list entries used only for uniqueness. Retry by resending the original signed transaction while it remains valid.
  • Existing MPP channels need no migration. Closed-loop credits can be used with sessions after activation.
  • Integrations affected by T11's strict ABI validation can restore calldata suffixes after T12 activates on their network.
  • Grant BURN_AT_ROLE only to tightly scoped contracts, such as a bridge that burns only amounts users request to bridge out. ISSUER_ROLE and BURN_BLOCKED_ROLE do not grant access to burnAt.

Full Changelog: v1.15.1...v1.16.0

Don't miss a new tempo release

NewReleases is sending notifications on new releases.