you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 13 min ago 255 onions tracked
home / news / tor network
09 August 2026 tor network 4 min read

Arti gains ground: why the Rust rewrite of Tor matters more than ever

In 2021 the tor project did something unusual for an organization that prizes stability: it announced a ground-up rewrite of its core client in Rust. Skeptics predicted a decade of yak-shaving. Instead, arti has quietly become the most important thing happening in tor development.

Why memory safety is the whole point

The C implementation dates back to 2001, and its age shows in the bug tracker. Buffer overflows, use-after-free errors and NULL dereferences have fueled a steady drip of security advisories across two decades. Each one gets patched. None of them stop being possible. Rust closes those doors at compile time. As the project put it when unveiling the rewrite, code that compiles without being marked unsafe should make large categories of bugs outright impossible to write (tor project blog). For anonymity software, where a single memory disclosure could deanonymize a user, that is not a nice-to-have - it is the core argument.

From side project to production client

Arti began in 2020 as a personal experiment by longtime tor developer Nick Mathewson, backed early on by Zcash Open Major Grants funding. The original idea was to swap out C tor piece by piece, but the codebase proved too entangled for incremental surgery. A clean rewrite was the pragmatic answer. Version 1.0.0 shipped in September 2022 and was declared ready for production use as an embedding library, bringing key-wiping from memory, channel padding against traffic analysis and hardened bootstrapping diagnostics (release announcement). By October 2024, version 1.3.0 had achieved parity on most major client features (tor project).

Where the transition actually stands

The project's published milestones are explicit about the endgame: once arti matches the C client, client-side use of the C implementation gets deprecated, then held in maintenance mode to give everyone time to migrate (gitlab milestones). The current state of play looks roughly like this:
  • Linux distributions package arti alongside classic tor
  • A JSON-based RPC interface is replacing the legacy control port
  • Congestion control and flow control are now considered stable
  • Relay and directory authority support remain under active development
No hard cutover date exists, and that is honest engineering rather than hesitation. Swapping the client used by millions of people is not something anyone should rush.

What 24/7 monitoring actually notices

Running continuous checks against both implementations surfaces differences a casual user never sees. Early arti builds rotated circuits on slightly different schedules, handled SOCKS authentication edge cases differently and emitted errors in shapes that tripped parsers written for the C daemon's output. None of it broke anything fundamental. The protocol is identical, so an arti client blends into the tor network like any other. But monitoring dashboards notice rhythm, and arti's rhythm took a few releases to settle into something familiar. Error messages are where the new implementation genuinely shines. When bootstrapping stalls mid-connection, arti explains why in plain language instead of a cryptic status code - the payoff of the stress-testing regime the developers built before calling 1.0.0 production-ready.

Relays go last, so operators should plan accordingly

For relay operators, the short answer today is: nothing changes yet. Running arti as a relay or directory authority is still unsupported, although the 2.x series shows steady progress on relay channels, circuit reactors and authority functionality (2.3.0 release notes). That ordering makes sense. Relays carry traffic for strangers, run for months without restarts and interact with consensus machinery that the C implementation has refined for decades. Client-side adoption will finish years before the relay fleet moves. Sensible operators are testing arti in staging environments right now, while rough edges are still cheap to fix.
Arti is the future that finally showed up - politely, and ahead of expectations.

Should you switch today?

If you build software that embeds tor, yes - arti is the better foundation and the only one receiving new investment. If you simply browse, there is no urgency: tor browser still bundles the battle-tested C daemon and will for some time. Practical walkthrough material lives in our tor setup guide. Either way, keep one eye on arti. The client you will be running in 2030 is already taking shape, written in a language where entire categories of disaster cannot compile.

more notes

all news ›