Zama Protocol Change Log
This page tracks upcoming and ongoing milestones for the Zama Protocol and related releases. It updates as new versions are planned and deployed.
Zama Protocol status
Deployed and planned FHEVM versions on the Testnet and Mainnet.
See the full version status in the Zama Protocol Version Dashboard.
Product updates
FHEVM v0.13 — June 2026
Highlights
The v0.13 release strengthens multichain support, introduces a redesigned developer SDK, and improves coprocessor consensus monitoring:
Improved Multichain support, building on the multi-chain foundation introduced in v0.12 with per-chain worker isolation and simplified host chain configuration.
New
@fhevm/sdknpm package with a major refactor of the relayer SDK.New FHE operations:
FHE.sumandFHE.isInfor aggregation and membership checks on encrypted values.All-contracts delegation: delegating to the
0xffffffffffffffffffffffffffffffffffffffffsentinel address grants a user delegation rights over all contracts.Coprocessor consensus drift monitoring, with metrics and logs that can be used for alerting.
tfhe-rs upgraded to v1.6.1 across the Coprocessor and KMS.
New features
FHE.sum(Copro): sums a list of encrypted values in a single FHE operation.FHE.isIn(Copro): checks whether an encrypted value belongs to a given set.All-contracts delegation (Copro, KMS, Devex): users can delegate decryption rights across all contracts at once by delegating the
0xffffffffffffffffffffffffffffffffffffffffcontract address. See RFC 017.@fhevm/sdknpm package (Devex): new SDK package replacing the previous relayer SDK structure, with a major refactor.Coprocessor consensus drift monitoring (Copro): detects anomalous coprocessor consensus drift.
Generic event listener (Copro, Gateway): a generic event listener is now integrated in the Coprocessor.
AI skills repository (Devex): a new public repository of AI agent skills for building on FHEVM — zama-ai/skills.
Improvements
Multichain hardening (Copro): host chains are now seeded declaratively with per-chain worker isolation, the host chain ID is derived from ciphertext handles instead of static gw-listener configuration, and Helm charts are updated for multi-coprocessor and multichain deployments.
IAM authentication for the Coprocessor RDS (Copro): database access now supports IAM-based authentication instead of static credentials.
Improved consensus reconciliation (Copro): better reconciliation logic for multi-coprocessor consensus.
KMS context and
extra_dataverification (KMS, Gateway, Copro): context and extra_data are now verified on all KMS endpoints.tfhe-rs upgraded to
v1.6.1(Copro, KMS).Extensive end-to-end test suite (Devex): broader e2e coverage across input, compute, and decryption flows.
FHEVM v0.12 — April 2026
Highlights
The v0.12 release brings multi-chain support, stronger consensus, and tighter resource controls to the Zama Protocol:
Multi-chain coprocessor support and multi-coprocessor consensus with deterministic ciphertext re-randomisation, enabling coprocessors to converge on identical FHE results across chains.
KMS context-aware decryptions introducing epoch IDs and context-state validation across the Gateway, KMS connector, and host contracts.
Per-block HCU metering on the host with configurable per-block, per-transaction, and per-depth Homomorphic Compute Unit limits, plus a whitelist for privileged callers.
Simplified ACL (v2) replacing the MultichainACL contract suite with a single access-control flow on the host chain.
Compressed key generation on GPU in the KMS, lowering key-generation overhead for GPU-backed deployments.
New features
Multi-chain coprocessor support (Copro): coprocessors can now serve multiple host chains in a single deployment.
Multi-coprocessor consensus (Copro): independent coprocessors converge on identical FHE results, with deterministic re-randomisation as the foundation.
KMS context-aware decryptions (Gateway, KMS, Host contracts): a new "KMS context" system adds epoch IDs and context state to decryption operations. Decryption requests carry context-aware
extraData, and the KMS connector validates context state via a newkms_contexttable and Ethereum listener.Per-block HCU limits (Host contracts): a new
HCULimitcontract enforces configurable per-block, per-transaction, and per-transaction-depth Homomorphic Compute Unit limits, with a whitelist mechanism for privileged callers to bypass block limits.Compressed key generation on GPU (KMS).
Coprocessor state revert tooling (Copro): new
revert_coprocessor_db_state.sqlscript, packaged in the db-migration Docker image, that can revert a coprocessor to a previous block number.Gateway ciphertext drift detection (Gateway): opt-in detection comparing local ciphertext digests against on-chain consensus, enabled via
--ciphertext-commits-address.Library-Solidity additions:
FHE.isPublicDecryptionResultValidview function for on-chain decryption signature validation;FHE.fromExternalreturns a trivial-encrypt of0for uninitialized handles instead of reverting.relayer-sdk v0.5.x (Devex): new
extraDataparameter on the relayer SDK.
Improvements
ACL simplification (v2) (Host contracts): the MultichainACL contract suite is removed; access control is consolidated on the host chain with simpler validation.
New handle format (Host contracts): handle hashing now includes a
FHE_compdomain separator and the previous block hash + timestamp, strengthening uniqueness across chains and time.Per-FHE-operation re-randomisation (Copro): ciphertext inputs are re-randomised per FHE operation using a deterministic seed derived from input ciphertexts and operator.
Re-randomisation of input ciphertexts before first compression (Copro).
KMS-connector switched to
eth_getLogs(KMS): replaces subscription-based event listening with batched database insertion.tfhe-rs upgraded to v1.5.4 (Copro/MPC).
Contract upgrade version check CI: a new workflow enforces that
REINITIALIZER_VERSIONand version constants are bumped when contract bytecode changes.ECDSA.solrenamed toFhevmECDSA.solto fix naming conflicts.
Breaking changes
MultichainACL contracts deleted:
MultichainACL.sol,MultichainACLChecks.sol, andIMultichainACL.solare removed entirely.isUserDecryptionReadysignature changed: theaddress userAddressparameter was removed. The old signature is preserved via a backward-compatibility overload but is deprecated.New handle format:
FHEVMExecutorhandle hashing now prependsCOMPUTATION_DOMAIN_SEPARATOR("FHE_comp") and appendsblockhash(block.number-1)+block.timestamp.HCULimitcontract required:FHEVMExecutorREINITIALIZER_VERSIONbumped to 3; initialization requireshcuCapPerBlock,maxHCUDepthPerTx, andmaxHCUPerTx. Integrators must sync to get whitelisted contracts.ACL
REINITIALIZER_VERSIONbumped to 4:ExpirationDateBeforeOneHourerror replaced byExpirationDateInThePast. Validation now only checksexpirationDate > block.timestamp.KMSVerifierupgraded for context-aware decryption with epoch / context support.ECDSA.solrenamed toFhevmECDSA.sol: import path changes fromcryptography/ECDSA.soltocryptography/FhevmECDSA.sol; library renamed fromECDSAtoFhevmECDSA.Coprocessor:
tenantstable removed from the DB; legacytfhe-workergRPC endpoint removed.
Bug fixes
Backport of
prepareUpgradeflows to the 0.12.x line.Reduced coprocessor migration lock time during the 0.12 migration.
Coprocessor no longer reads key blobs from the database on key cache hits.
Resources
FHEVM v0.11 — February 2026
This release brings major performance and security improvements to the Zama Protocol.
Highlights
tfhe-rs v1.5.0 upgrade across Coprocessor and KMS for improved FHE performance
ACL checks on host chain for direct access control enforcement through the relayer and KMS connector
Delegated decryption with a complete end-to-end flow
FHE statistics for TFHE-rs for better observability into Coprocessor FHE operations
New features
GPU acceleration: Optional GPU backends for ZK proof verification, Switch-and-Squash (SnS), and re-randomization. CPU-only deployments remain fully supported.
Delegated decryption: Complete end-to-end support for delegated user decryption, allowing authorized addresses to decrypt on behalf of users.
Operator staking system: New ERC-4626-based staking contracts with UUPS upgradeability, permit support, and Operator Rewarder contracts for fee management.
Confidential Tokens Registry: Added a Confidential Tokens Registry and ERC-7984 upgradeable wrapper contracts for encrypted token assets.
CLI tool: Added a new command-line tool for common FHEVM workflows.
BNB chain support: Added configurations for BNB chain deployments.
Improvements
tfhe-rs upgrade to v1.5.0: Updated across the Coprocessor and KMS, while FHE keys and serialized ciphertexts remain generally compatible.
ACL checks on host chain: Decryption ACL checks now run directly on the host chain through the relayer and KMS connector, reducing trust assumptions.
FHE statistics: Added FHE operation statistics and decryption performance metrics in the Coprocessor.
Dependence-chain processing: Improved the Coprocessor scheduler for better parallelism.
Host-listener poller mode: Added an alternative polling mode that replaces WebSocket-based event listening.
KMS garbage collection: Added garbage collection for KMS operations.
Database optimizations: Improved indexing for the
ciphertext_digesttable.
Fixes
Overflow prevention in the
ProtocolStakingcooldown mechanismERC-4626 inflation attack mitigation using decimal offset
Better handling of cyclic dependence errors in the Coprocessor
Improved
eth_getLogstimeout management in the host-listener
Resources
FHEVM v0.10 — October 2025
This preview introduces a dedicated payment contract in the Gateway and flexible delegation of decryption rights through smart contracts.
These changes improve fee management, access control, and the usability of encrypted operations.
Preview
Gateway payment contract for Coprocessor and KMS fee management
Delegation through smart contracts for controlled decryption access
Time-scoped permissions for temporary or session-based access
Contract-scoped permissions for stricter access control
New features
Gateway payment contract: Adds a dedicated payment contract within the Gateway to manage fees for Coprocessor and KMS operations, including input and decryption flows.
Delegation via smart contracts: Users can delegate decryption rights to other addresses with fine-grained control over scope and duration:
Explicit authorization for another address to generate EIP-712 signatures and run
userDecryptoperationsDelegation validity defined by timestamp for temporary or session-based access
Delegation scoped to specific contract addresses for context-aware access control
Improvements
More flexible encrypted data access through delegation
More transparent fee management with a dedicated Gateway payment flow
Resources
FHEVM v0.9 — October 2025
This release adds new key generation capabilities, dynamic coprocessor management, and a redesigned decryption event flow.
These changes improve flexibility, scalability, and consensus handling while deprecating older event formats.
Breaking changes
The methods FHE.requestDecryption and FHE.setDecryptionOracle are now deprecated and must be removed.
Update your contracts to use the new decryption flow through the relayer.
Highlights
On-chain FHE key and CRS generation
Dynamic pauser management
Transaction input re-randomization
Redesigned user decryption events
Gateway API cleanup and renaming
New features
Support generation of FHE key and CRS on-chain:
Request FHE key and CRS generation directly through the Gateway.
New environment variables for gateway contracts:
KMS_GENERATION_THRESHOLD— threshold used to validate consensus on FHE key or CRS generationKMS_NODE_STORAGE_URL_[0-N]— storage base URL for public materials for each KMS node
New environment variable for the coprocessor (
gw-listener):KMS_GENERATION_ADDRESS— address of theKMSGenerationgateway contract
New environment variable for the connector:
KMS_GENERATION_ADDRESS— address of theKMSGenerationgateway contract
New
PauserSetimmutable contract:Host and Gateway contracts can now be paused by any address added in
PauserSet.New environment variables for gateway contracts:
NUM_PAUSERS— number of pauser addresses to add. Set this ton_kms + n_copro.PAUSER_ADDRESS_[0-N]— pauser addresses
New environment variables for host contracts:
NUM_PAUSERS— number of pauser addresses to add. Set this ton_kms + n_copro.PAUSER_ADDRESS_[0-N]— pauser addresses
Re-randomization of transaction inputs:
All transaction inputs, including state inputs, are re-encrypted before FHE evaluation.
This provides sIND-CPAD security.
This feature is transparent to users.
Improvements
User decryption response:
Encrypted shares and signatures are no longer aggregated on-chain in the Gateway.
Each KMS response now emits its own event.
New events in the
Decryptioncontract:UserDecryptionResponse(uint256 indexed decryptionId, uint256 indexShare, bytes userDecryptedShare, bytes signature, bytes extraData);UserDecryptionResponseThresholdReached(uint256 indexed decryptionId);
Breaking changes
This event is deprecated from the Gateway Decryption contract:
PublicDecryptionResponse(uint256 indexed decryptionId, bytes decryptedResult, bytes[] signatures, bytes extraData)
User decryption request:
User EIP-712 signature verification is simplified in the Gateway
Decryptioncontract.
Breaking changes
The uint256 contractsChainId field is no longer part of the UserDecryptRequestVerification struct used for EIP-712 signature verification.
Gateway contract renaming:
MultichainAclis renamed toMultichainACL.KmsManagementis renamed toKMSGeneration.
Breaking changes
These Gateway contracts are renamed:
MultichainAcl→MultichainACLKmsManagement→KMSGeneration
These environment variables are renamed:
KMS_MANAGEMENT_ADDRESS→KMS_GENERATION_ADDRESSKMS_CONNECTOR_KMS_MANAGEMENT_CONTRACT__ADDRESS→KMS_CONNECTOR_KMS_GENERATION_CONTRACT__ADDRESS
In the KMS Connector Helm chart values.yaml, this field is renamed:
kmsManagement→kmsGeneration
Gateway check functions replaced:
All external
check...view functions are removed from the Gateway contracts.Associated errors are moved to other contracts or removed.
Equivalent
is...view functions now return a boolean instead of reverting.
Breaking changes
All check... view functions are removed from the Gateway contracts.
For example:
checkPublicDecryptAllowedis replaced byisPublicDecryptAllowedPublicDecryptNotAllowedis moved to theDecryptioncontract
Resources
FHEVM v0.8 — September 2025
This release makes FHEVM more scalable, secure, and developer-friendly.
Highlights
New KMS connector for modular integration
Compressed ciphertexts for lighter payloads
Flexible
extraDatafield for richer appsPost-quantum ML-KEM512 for faster, smaller decrypts
Stronger chain resilience and ERC-7995 compliance
New features
New KMS connector: Added a new Key Management System connector to improve modularity and integration.
Compressed ciphertext support: Added support for compressed ciphertexts in both the SnS worker and KMS, reducing payload sizes.
Generic
extraDatafield: Gateway functions, events, and signed structs now include a genericextraDatafield for extensibility and custom data support.SepoliaConfigupdate: Added theprotocolId()function to support protocol identification.
Improvements
ERC-7995 compatibility: Updated the Oracle callback interface for compliance, following ERC-7995.
Reduced user decrypt payload size: Migrated to ML-KEM512 for 128-bit equivalent post-quantum security. This reduces decrypt response sizes and allows more responses per block.
Host listener: Added reorganization handling in the host listener for stronger chain resilience.
Library storage layout: Adjusted the storage layout to align with the standard guidelines.
Breaking changes
Oracle callback function signature now requires this format:
function callbackExample(
uint256 requestID,
bytes memory cleartexts,
bytes memory decryptionProof
) external;Resources
FHEVM v0.7 — July 2025
This release introduces the first iteration of the Zama Protocol.
Highlights
Gateway is now a core component for protocol orchestration.
Coprocessor input verification is now enforced on the coprocessor side.
Decryption pipeline now prepares ciphertexts for decryption on coprocessors.
Solidity library is restructured to match the new protocol architecture.
Breaking changes
Renamed the library from
TFHEtoFHEIntroduced
FHE.requestDecryptionwith support formsg.value, deprecatingGatewayCallerRemoved
ebytesXXXtypesReplaced
einputwithexternalEuintXXX,externalEbool, andexternalEaddressIntroduced per-transaction operation limits, replacing the previous per-block limit
Resources
Last updated