Every HIP we have submitted to Hiero, in one place, kept current automatically.
Post-quantum signatures, account-level HBAR vaults, off-ledger execution, clearer contract limits, and the
application standards that make CLPR safe for real money.
At a glance · By theme · Timeline · How we write HIPs · How this repository works
Hiero is the open-source distributed ledger behind Hedera, hosted by LF Decentralized Trust. Changes to Hiero, and standards built on it, are proposed as Hiero Improvement Proposals (HIPs) in hiero-ledger/hiero-improvement-proposals and decided in the open, as HIP-1 describes. This repository collects every HIP that ColdAI has submitted, with a summary, its status, the implementation work behind it, and a snapshot of the full text.
Note
The pull requests in the Hiero repository are the source of truth. Every proposal here is a draft under public review until Hiero's process says otherwise. Comments belong on the pull request or the HIP's discussion, not in this repository.
| PR | Proposal | Category | Status | Submitted | Implementation |
|---|---|---|---|---|---|
| #1563 | Lightsphere Lightsphere - Off-Ledger Execution Spheres Anchored to Hiero |
Application | Draft · closed | 2026-10-07 | ColdAI-org/lightsphere |
| #1560 | Contract trace data limit Explicit Status and Pre-flight Parity for the Contract Trace Data Size Limit |
Service | Draft · closed | 2026-10-05 | Evidence on Hedera testnet LFDT-CLPR/clpr-smart-contracts#37 LFDT-CLPR/clpr-smart-contracts#38 |
| #1550 | HCPQ: ML-DSA-44 signatures Ledger-Bound ML-DSA-44 Transaction Signatures |
Core | Draft · closed | 2026-09-09 | hiero-ledger/hiero-cryptography#693 hiero-ledger/hiero-consensus-node#27253 |
| #1546 | CLPR intent settlement CLPR Intent Settlement and Liquidity Clearing Standard |
Application | Draft · closed | 2026-09-02 | Specification |
| #1545 | CLPR canonical asset transfer CLPR Canonical Asset Transfer Standard |
Application | Draft · closed | 2026-09-02 | Specification |
| #1544 | CLPR financial security profiles CLPR Financial Security Profiles and Value Guards |
Application | Draft · closed | 2026-09-02 | Specification |
| #1539 | HBAR vaulted balances HBAR Vaulted Balances with Delayed Release and Recovery |
Service | Draft · closed | 2026-08-31 | Specification |
A standard for off-ledger execution that settles to Hiero. In signed mode, 2–16 parties co-sign states and settle once. In network mode, a whole Hiero network (for example a HashSphere) connects over CLPR and has a guaranteed exit. Includes a throughput accounting rule so claims can be compared.
- Submitted 2026-10-07
- Discussion hiero-ledger/hiero-improvement-proposals#1562
- Building the reference implementation found two double-payout bugs in the first draft, both fixed in the spec
- An independent review moved signed mode from HIP-632 account-key checks to signing keys bound into each sphere
- Implementation: ColdAI-org/lightsphere — Reference implementation: contracts, Go benchmark harness, TypeScript client and watchtower. 46 tests; 46,688 effective tx/s measured on one machine
- Read the full proposal · Pull request
An opt-in post-quantum transaction signature profile using standard FIPS 204 ML-DSA-44. Signatures are bound to the ledger ID and to the exact canonical transaction bytes. Existing Ed25519 and ECDSA keys are unchanged, and the profile is disabled by default.
- Submitted 2026-09-09 · updated 2026-10-01
- Discussion hiero-ledger/hiero-improvement-proposals#1550
- Reviewed by @mgarbs
- Reviewed by a Hiero maintainer; every point addressed, including cross-language vectors and an algorithm-ID registry
- Implementation: hiero-ledger/hiero-cryptography#693 — ML-DSA-44 profile, key IDs, transcript signing, and conformance vectors re-checked with OpenSSL
- Implementation: hiero-ledger/hiero-consensus-node#27253 — Consensus-node integration, canonical transaction checks, and integration tests
- Read the full proposal · Pull request
An account-native HBAR vault. Vaulted HBAR keeps staking but can only move through a delayed, destination-bound release. During the delay, a separate guardian key can cancel the release or recover the funds to a pre-committed account, which limits the damage from a stolen signing key.
- Submitted 2026-08-31
- Discussion hiero-ledger/hiero-improvement-proposals#1539
- Read the full proposal · Pull request
Makes the consensus node's 262,144-byte contract trace-size cap visible as itself, with its own response code instead of INSUFFICIENT_GAS. Mirror-node simulation and the JSON-RPC relay then report the same failure before a transaction is sent.
- Submitted 2026-10-05
- Discussion hiero-ledger/hiero-improvement-proposals#1560
- Found while opening a Sepolia ↔ Hedera CLPR Channel: the same call failed at every gas limit from 5.6M to 15M
- Implementation: Evidence on Hedera testnet — Write-up of the failed transactions that exposed the cap
- Implementation: LFDT-CLPR/clpr-smart-contracts#37 — Documents the cap for large-calldata verifiers
- Implementation: LFDT-CLPR/clpr-smart-contracts#38 — Staged verifier input that stays under the cap
- Read the full proposal · Pull request
Intent-based cross-ledger settlement on CLPR. Users sign the outcome they want, competing solvers fill it, and a CLPR-proven receipt releases escrow exactly once. Solvers can then net their inventory in a collateralized clearing layer.
- Submitted 2026-09-02
- Read the full proposal · Pull request
One asset identity, transfer envelope and adapter interface for moving fungible assets over CLPR. It covers issuer burn/mint, lock/mint and lock/release modes, with auditable supply accounting so assets don't fragment into incompatible wrapped copies.
- Submitted 2026-09-02
- Read the full proposal · Pull request
Machine-readable security profiles and value guards for financial apps on CLPR. A profile pins the exact ledgers, verifiers and finality rules an app relies on. A value guard enforces per-message, in-flight and time-window limits.
- Submitted 2026-09-02
- Read the full proposal · Pull request
Contribution: HIP-1535: harden channel identity and emergency recovery (HIP-1261)
Proposed amendments to HIP-1535 (CLPR) on Channel identity and emergency recovery. Pull request #1543, 2026-09-02, +824 / −1 lines.
timeline
title Hiero Improvement Proposals submitted by ColdAI
2026-08-31 : HBAR vaulted balances (#1539)
2026-09-02 : CLPR intent settlement (#1546) : CLPR canonical asset transfer (#1545) : CLPR financial security profiles (#1544) : HIP-1535 amendments (#1543)
2026-09-09 : HCPQ – ML-DSA-44 signatures (#1550)
2026-10-05 : Contract trace data limit (#1560)
2026-10-07 : Lightsphere (#1563)
- Grounded in something that happened. Each proposal starts from a problem we hit while building: a contract that failed at every gas limit, a key-rotation hazard found in review, a double payout found by a fuzz test. The evidence goes in the Motivation section, with transaction links where there are any.
- Implementation before approval. Where we can, we build the reference implementation while the HIP is still a draft, because building it changes the specification. For Lightsphere, it found two design flaws in the first draft. For HCPQ, it produced cross-language conformance vectors.
- Measured, not estimated. Gas, sizes and throughput figures come from a test, a fixture or a published report that anyone can re-run.
- Optional by default. New behaviour is opt-in, and each HIP says what happens on a network that does not adopt it, as HIP-1's Network Optionality section asks.
- Signed and certified. Every commit carries a Developer Certificate of Origin sign-off and a cryptographic signature.
| Path | What it holds |
|---|---|
proposals/ |
A snapshot of each HIP's text as of its pull request's latest commit, with relative links rewritten to that commit |
data/hips.json |
Generated index: status, category, dates, reviews and links for every pull request |
data/curated.json |
Hand-written summaries, themes, highlights and implementation links |
scripts/sync.mjs |
Fetches every HIP pull request by our authors from the GitHub API, writes the snapshots and the index, and regenerates the marked sections of this README |
A scheduled workflow runs the sync every day and commits any change, so status changes, reviews and new revisions show up here without anyone editing by hand. To run it yourself:
GITHUB_TOKEN=$(gh auth token) node scripts/sync.mjsTo add a new proposal, open it in the Hiero repository. The next sync picks it up. Then add its summary and theme
to data/curated.json.
The HIP texts are © their authors and licensed under the Apache License 2.0, as in the Hiero repository. Everything else here is also Apache-2.0.
Maintained by ColdAI, a frontier R&D lab building agentic AI and distributed-ledger systems.