Release v1.16.0
Important
This release is required for the T12 network upgrade scheduled for testnet on October 8, 2026 16:00 CEST (1791468000) and mainnet on October 13, 2026 16:00 CEST (1791900000). Node operators must update before activation.
This release contains a breaking change for integrators & developers, please check the release notes below.
T12 adds configurable nonces for parallel expiring transactions, enables MPP sessions for closed-loop stablecoins, relaxes ABI validation, aligns Stablecoin DEX quote and swap calculations, and adds authorized burns for TIP-20 tokens.
Update Priority
| User Class | Priority |
|---|---|
| Validators | High |
| RPC Nodes | High |
Nodes running an earlier release can fall out of sync at the T12 activation timestamp.
Activation Times
| Network | Date | Timestamp |
|---|---|---|
| Testnet | October 8, 2026 16:00 CEST (14:00 UTC) | 1791468000
|
| Mainnet | October 13, 2026 16:00 CEST (14:00 UTC) | 1791900000
|
TIPs included with T12
- TIP-1106: Configurable nonces for expiring transactions: Allows any
uint64value in the existingnoncefield. Distinct nonces let otherwise identical transactions be submitted in parallel within the same validity window, without coordinating sequential nonces or adding access-list entries solely for uniqueness. - TIP-1095: MPP sessions for closed-loop stablecoins: Enables recipient-restricted TIP-20 tokens to fund payment channels without requiring issuers to allowlist the channel reserve. Funding and settlement enforce TIP-403 permissions against the payer and payee; refunds can return unused funds to the original payer. Token pauses and account receive policies still apply.
- TIP-1116: Relaxed ABI validation: Accepts trailing bytes in otherwise valid calls to Tempo's native contracts, restoring compatibility with calldata suffixes rejected at T11. Other strict decoding checks remain.
- TIP-1088: Accurate swap quotes and cheaper execution: Uses the same per-order matching and rounding for quotes and swaps. For unchanged orderbook state, quotes match swap fill calculations. Removes redundant liquidity-tracking writes during swaps, order placement, and cancellation.
- TIP-1006: Authorized burns for TIP-20 tokens: Adds
burnAt(from, amount)for contracts grantedBURN_AT_ROLE, enabling issuer-authorized burn-and-mint bridging without a separate user token approval. Token pauses, protected-address checks, and applicable access-key spending limits still apply.
Operators
What's Changed
- Finalization gossip enabled by default (#7950): Validators and certified followers now enable P2P finalization-certificate gossip automatically. Disable it with
--consensus.devp2p.finalizations=false; it remains disabled in dev and uncertified follower modes. - Testnet network identity (#8064): Updates testnet network identities and activation epochs.
- AA transaction pool (#8065): Refreshes the AA 2D pool's base fee on canonical state changes, keeping transaction ordering and eviction priorities current.
- Expiring-nonce validation (#8066): Corrects pre-T12 expiring-nonce error classification while keeping ordinary nonce overflow permanently invalid.
- Consensus snapshot replay (#8091): Resets the delivery batch on stale-skipped forkchoice updates to prevent snapshot replay from starving finalized deliveries.
Developers
Compatible tooling versions
| Package | Version | Notes |
|---|---|---|
| Foundry | nightly (2026-10-03) | Includes T12 hardfork support and updated Tempo precompile bindings. |
| viem | 2.57.3 | Includes TIP-1106 expiring nonce preservation and TIP-1006 burnAt support, added in 2.57.2.
|
| pytempo | 0.6.1
| Adds T12 burn_at and burn_at_role helpers and updated ABIs. Requires Python 3.10+.
|
| tempo-go | 0.6.1
| Adds T12 expiring nonce discriminators and burnAt bindings.
|
| tempo-alloy | 1.16.0 | Rust client and transaction builders with updated Tempo SDK dependencies. crates.io publication pending. |
| tempo-primitives | 1.16.0 | Shared Tempo transaction and signature types. crates.io publication pending. |
| tempo-contracts | 1.16.0 | Includes T12 burnAt, BURN_AT_ROLE, and BurnAt event bindings. crates.io publication pending.
|
| tempo-chainspec | 1.16.0 | Includes T12 activation schedules for mainnet and testnet. crates.io publication pending. |
| tempo-hardfork | 1.16.0 | Includes T12 hardfork identifiers and activation timestamps. crates.io publication pending. |
| Zones | v0.3.4 | Includes T12 support and inheritance of the parent chain’s hardfork schedule. |
Breaking behavior at T12
- Native contract gas limits: Before writing to storage, a native contract call must have more than 2,300 gas remaining or it fails with an out-of-gas error. Re-estimate hardcoded transaction gas limits on T12 testnet and test any explicit caps on gas forwarded to native contracts. Fees remain based on gas actually used.
- DEX tick liquidity storage: Stored tick liquidity totals stop updating at T12. Integrations reading those totals directly from storage must switch to
getTickLevel()or sum the remaining amounts of active orders. Quote and swap APIs are unchanged.
Integration Notes
- Assign distinct
uint64nonces to otherwise identical expiring transactions after activation. Ensure builders and signers preserve the supplied nonce, and remove access-list entries used only for uniqueness. Retry by resending the original signed transaction while it remains valid. - Existing MPP channels need no migration. Closed-loop credits can be used with sessions after activation.
- Integrations affected by T11's strict ABI validation can restore calldata suffixes after T12 activates on their network.
- Grant
BURN_AT_ROLEonly to tightly scoped contracts, such as a bridge that burns only amounts users request to bridge out.ISSUER_ROLEandBURN_BLOCKED_ROLEdo not grant access toburnAt.
Full Changelog: v1.15.1...v1.16.0