RADIX WikiRADIX Wiki

Two development workstreams the DAO could fund early: a rehearsal of a mainnet protocol upgrade, and a MetaMask Snap that would let Radix reach people through the wallet they already run. Both began as forum threads in January 2026. Neither has been formalised, and between them they run to seven posts.

The dry-run protocol upgrade

talesofbeem opened the dry-run thread on 25 January 2026 with the problem underneath it: most of the developers who built the protocol have moved on, and anyone who wants to change the Radix Engine needs to know they can test that change against a running network first. The proposal is to complete a protocol upgrade end to end, relearning the stack in the process, on an upgrade whose payload does not matter.

projectShift gave the rehearsal its shape in the same thread. Change the protocol's moniker and nothing else, then plant two faults on purpose: a comment marking where the bug is, and something that halts the network. The exercise then tests debugging, rollback and redeployment rather than the happy path alone. talesofbeem agreed to fold monitoring and a halted network into the write-up. The thread has stood at three posts since that day.

The MetaMask Snap

The Snap thread opened three days earlier, on 22 January 2026, and its argument is about where effort goes. Maintaining one exclusive Radix wallet spends the Foundation's resources against a field of more than 130 web3 wallets, while Sui, Cosmos, Starknet and Near reach MetaMask users through snaps instead. Jon-Eric Cook proposed hardware-wallet support as the step after, and the author agreed it could be the next integration.

The author was explicit that the thread is not a proposal: he opened it for comment and left formalising it through on-chain governance to any developer who wanted to take it up. Nobody has. MetaMask's allowlist registry carried 186 verified snaps when this page was checked on 28 August 2026 and none of them is Radix's, so what this card needs is a package and a champion rather than a decision.

The rehearsal was overtaken by the real thing (11 September 2026)

The dry-run thread's premise is that nobody left on the network has taken a protocol upgrade through end to end, so the next person to change the engine should practise on an upgrade whose payload does not matter. On 11 September 2026 the upgrade that mattered went first. Eagle Ray enacted at the start of epoch 339,898 to close the engine flaw behind the Hyperlane asset drain, and it is the only protocol update in Radix's mainnet history that enacts on an epoch number rather than on a validator readiness signal.

Each element projectShift specified for the exercise has a counterpart in what actually happened, which is why the comparison is worth making rather than a coincidence. A running network to test against: the node runner coordinating the release told the developer group the sequence had been “testing extensively over the last days/week” on test networks. A fault planted on purpose: a VaultDrainer blueprint that had been “hammering on the unpatched test networks, The moratorium and the enacted network”. A halted network to recover from: mainnet, which produced no round for 254 hours. The fix was then proved against mainnet itself rather than against a rehearsal of it — the blueprint was published to mainnet at 12:35 UTC and the call that drains a vault was refused, permanently rejected with the new SystemError::InvalidInvokeAccess.

For this card the consequence is narrow and it favours one deliverable over the others. Rehearsing the mechanics is worth less now, because the mechanics have been exercised under real load by the people who would have run the rehearsal. Writing the result up is worth more, because the process the next upgrade follows now has a worked mainnet precedent instead of a hypothetical one, and that precedent currently exists only as Telegram messages and a commit history. The Radix Accountability Council asked for a few days before it publishes a report when it announced the restart at 14:37 UTC; that report is the nearest thing to the write-up this card asks for, and it is not the DAO's. The MetaMask Snap half of the card is untouched by any of it.

Deliverables

  • Fund and run one protocol upgrade end to end, moniker only, with a deliberate liveness break to exercise debugging and rollback.
  • Write up the result as the process the next real upgrade follows.
  • Build, publish and maintain a Radix MetaMask Snap, and take it through the allowlist.

Dependencies & cross-references

Sources

HydrateLast updated Sep 21, 2026v1.2.16 revisionsVerified Sep 11, 2026