{
  "version": 1,
  "event_id": "evt_75de257f8e4bea2d",
  "url": "https://xiyu.news/events/evt_75de257f8e4bea2d/",
  "json": "https://xiyu.news/api/events/evt_75de257f8e4bea2d.json",
  "type": "security_incident",
  "status": "monitoring",
  "category": "crypto",
  "title": {
    "zh": "Firo 紧急硬分叉修复 Spark 漏洞，防止无限代币铸造",
    "en": "Privacy coin flaw risks endless token creation, leaving node operators with a deadline in hours to fix it"
  },
  "current_state": {
    "zh": "Firo 正在执行一项紧急硬分叉，该分叉于 2024 年 9 月 4 日在区块 1,371,000 处激活，要求所有节点运营者、矿工、交易所和钱包用户升级至 v0.14.18.0。该升级永久修复了 8 月披露的 Spark 漏洞——该漏洞在特定条件下可伪造代币并增发 FIRO——同时恢复正常的 multi-input Spark 支付功能。\n\n隐私协议中出现可增发供给的漏洞属于严重安全事件，因为它直接威胁代币的稀缺性和用户信任。此次硬分叉也表明，小型隐私币必须迅速协调节点、交易所和用户，才能在漏洞被利用之前完成修复。\n\n该漏洞于 8 月 13 日披露，并未危及钱包、密钥或单输入支付；不过一名研究人员曾在主网受控测试中铸造了约 200 FIRO。作为临时防御措施，v0.14.17.2 曾将 Spark 支付限制为单输入，但这会因拆分金额更容易被关联而削弱隐私；v0.14.18.0 通过引入版本化的 Chaum V2 证明和交易格式来彻底修复。",
    "en": "Firo activates a hard fork within hours to fix a Spark vulnerability that could allow endless token creation, requiring node operators to upgrade."
  },
  "first_seen_at": "2026-09-04T22:27:17.282910+00:00",
  "last_updated_at": "2026-09-04T22:27:17.282910+00:00",
  "last_material_change_at": "2026-09-04T22:27:17.282910+00:00",
  "confidence": 0.75,
  "updates_count": 1,
  "sources_count": 1,
  "entities": [
    "privacy",
    "privacy-coin"
  ],
  "identifiers": [],
  "topics": [
    "firo",
    "hard-fork",
    "privacy-coin",
    "vulnerability"
  ],
  "updates": [
    {
      "update_id": "upd_89e8351d5cda98d0",
      "event_id": "evt_75de257f8e4bea2d",
      "occurred_at": "2026-09-04T20:05:37Z",
      "published_at": "2026-09-04T20:05:37Z",
      "first_seen_at": "2026-09-04T22:27:17.282910Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "Firo 紧急硬分叉修复 Spark 漏洞，防止无限代币铸造",
      "title_en": "Privacy coin flaw risks endless token creation, leaving node operators with a deadline in hours to fix it",
      "what_changed_zh": "Firo 正在执行一项紧急硬分叉，该分叉于 2024 年 9 月 4 日在区块 1,371,000 处激活，要求所有节点运营者、矿工、交易所和钱包用户升级至 v0.14.18.0。该升级永久修复了 8 月披露的 Spark 漏洞——该漏洞在特定条件下可伪造代币并增发 FIRO——同时恢复正常的 multi-input Spark 支付功能。\n\n隐私协议中出现可增发供给的漏洞属于严重安全事件，因为它直接威胁代币的稀缺性和用户信任。此次硬分叉也表明，小型隐私币必须迅速协调节点、交易所和用户，才能在漏洞被利用之前完成修复。\n\n该漏洞于 8 月 13 日披露，并未危及钱包、密钥或单输入支付；不过一名研究人员曾在主网受控测试中铸造了约 200 FIRO。作为临时防御措施，v0.14.17.2 曾将 Spark 支付限制为单输入，但这会因拆分金额更容易被关联而削弱隐私；v0.14.18.0 通过引入版本化的 Chaum V2 证明和交易格式来彻底修复。",
      "what_changed_en": "Firo activates a hard fork within hours to fix a Spark vulnerability that could allow endless token creation, requiring node operators to upgrade.",
      "current_state_zh": "Firo 正在执行一项紧急硬分叉，该分叉于 2024 年 9 月 4 日在区块 1,371,000 处激活，要求所有节点运营者、矿工、交易所和钱包用户升级至 v0.14.18.0。该升级永久修复了 8 月披露的 Spark 漏洞——该漏洞在特定条件下可伪造代币并增发 FIRO——同时恢复正常的 multi-input Spark 支付功能。\n\n隐私协议中出现可增发供给的漏洞属于严重安全事件，因为它直接威胁代币的稀缺性和用户信任。此次硬分叉也表明，小型隐私币必须迅速协调节点、交易所和用户，才能在漏洞被利用之前完成修复。\n\n该漏洞于 8 月 13 日披露，并未危及钱包、密钥或单输入支付；不过一名研究人员曾在主网受控测试中铸造了约 200 FIRO。作为临时防御措施，v0.14.17.2 曾将 Spark 支付限制为单输入，但这会因拆分金额更容易被关联而削弱隐私；v0.14.18.0 通过引入版本化的 Chaum V2 证明和交易格式来彻底修复。",
      "current_state_en": "Firo activates a hard fork within hours to fix a Spark vulnerability that could allow endless token creation, requiring node operators to upgrade.",
      "detailed_summary_zh": "Firo activates a hard fork within hours to fix a Spark vulnerability that could allow endless token creation, requiring node operators to upgrade.",
      "detailed_summary_en": "Firo activates a hard fork within hours to fix a Spark vulnerability that could allow endless token creation, requiring node operators to upgrade.",
      "background_zh": "Firo 原名 Zcoin，是 2016 年推出的隐私导向加密货币，定位为私人数字现金。其 Spark 协议基于 Lelantus Spark 设计，利用零知识证明隐藏发送方、接收方和金额，同时保持区块链可验证；主网 Spark 地址以“sm”开头，长度为 144 个字符。硬分叉是一种网络级规则变更，要求所有节点升级以保持兼容；masternode（主节点）是除常规交易验证外还承担额外功能的专用节点。",
      "background_en": "Firo, formerly known as Zcoin, is a privacy-focused cryptocurrency launched in 2016 that aims to serve as private digital cash. Its Spark protocol, built on the Lelantus Spark design, uses zero-knowledge proofs to hide the sender, receiver, and amounts while keeping the blockchain verifiable; Spark addresses on mainnet start with 'sm' and are 144 characters long. A hard fork is a network-wide rule change that requires all nodes to update to remain compatible, and masternodes are specialized nodes that perform extra functions beyond standard transaction verification.",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "此次漏洞直接关系到 Firo 网络的原生代币 FIRO，因为可伪造代币的缺陷会威胁其供应上限并削弱持有者信心；极短的升级窗口还给交易所和节点运营者带来运营风险，可能影响硬分叉前后的 FIRO 交易与流动性。该事件或会波及整个隐私币赛道的市场情绪，但直接冲击可能局限于 Firo 自身生态。",
      "market_impact_en": "The vulnerability directly exposes FIRO, the network's native token, because a flaw that permits forged coins threatens its supply cap and could undermine holder confidence; the short upgrade window also creates operational risk for exchanges and node operators, which could affect FIRO trading and liquidity around the fork. The incident may ripple into sentiment for privacy-coin projects generally, although the direct market impact is likely contained to Firo's ecosystem.",
      "importance_score": 8.0,
      "references": [
        {
          "url": "https://en.wikipedia.org/wiki/Firo_(cryptocurrency)",
          "title": "Firo (cryptocurrency) - Wikipedia"
        },
        {
          "url": "https://firo.org/2024/01/18/spark-is-live.html",
          "title": "Lelantus Spark is live on Firo | Firo - Privacy-preserving cryptocurrency"
        }
      ],
      "confidence": 0.75,
      "story_ids": [
        "rss:cryptoslate.com_feed_:906867f0703d8344"
      ],
      "sources": [
        {
          "url": "https://cryptoslate.com/privacy-coin-flaw-risks-endless-token-creation-leaving-node-operators-with-a-deadline-in-hours-to-fix-it/",
          "label": "CryptoSlate",
          "source_type": "rss",
          "official": false
        }
      ]
    }
  ]
}
