Hummingbot 2.17: Connectors, Unified Trading Routes, and Execution Updates
Summary
These release notes describe changes to Hummingbot’s client, Gateway, and related trading tools. Client updates include a Kalshi perpetual futures connector, a Gateway client aligned with unified trading routes, configurable slippage widening for order and liquidity-pool executors, and changes to executor configuration and backtest reporting. Gateway updates consolidate trading endpoints, add Meteora DAMM v2 support, allow wider Meteora DLMM liquidity ranges through multiple transactions, and update Orca Whirlpools integrations. The notes also list fixes for connector authentication, balances, liquidity positions, and swap execution.
Several operational changes matter to strategy users: Derive credentials must be reconfigured because key names changed, and older Gateway connector-specific routes have been removed. The release also describes security and data-handling changes, including authorization based on route behavior and decimal-string serialization for amounts. These are software release notes, not a strategy evaluation; they provide no trading performance results, and users should consult the release documentation for migration details before upgrading.
Key ideas
- The client adds a Kalshi perpetual futures connector and a configurable slippage ramp for executors.
- Gateway consolidates trading endpoints and adds support for Meteora DAMM v2 and wider DLMM positions.
- Derive users must reconnect because credential configuration keys changed.
- Older connector-specific Gateway routes are removed in favor of unified trading routes.
- The release includes execution, authentication, liquidity-position, and backtesting-related fixes but reports no strategy performance.
Tags
Full text
# Hummingbot v2.17.0 Release Notes
# Hummingbot v2.17.0 Release Notes
*Released on September 22, 2026*
| Repository | Description | GitHub Release | DockerHub Release |
|------------|-------------|----------------|-------------------|
| [Hummingbot Client](https://github.com/hummingbot/hummingbot) | Core Client | [`v2.17.0 changelog`](https://github.com/hummingbot/hummingbot/releases/tag/v2.17.0) | [`version-2.17.0`](https://hub.docker.com/r/hummingbot/hummingbot/tags?name=version-2.17.0) |
| [Gateway](https://github.com/hummingbot/gateway) | DEX Middleware | [`v2.17.0 changelog`](https://github.com/hummingbot/gateway/releases/tag/v2.17.0) | [`version-2.17.0`](https://hub.docker.com/r/hummingbot/gateway/tags?name=version-2.17.0) |
!!! note
Other Hummingbot repositories such as [Condor](https://github.com/hummingbot/condor) and [Hummingbot-API](https://github.com/hummingbot/hummingbot-api) follow a continuous deployment model without fixed version releases. Use the `main` branch for these repositories.
## How to Install / Update
- **Hummingbot Client**: See the [Hummingbot Client Quickstart](../installation/hummingbot-client.md) — upgrade to **v2.17.0** for the Kalshi perpetual connector, Gateway unified-route client, and executor slippage ramp. **Derive users must re-run `connect derive` / `connect derive_perpetual`** after this release (config keys renamed).
- **Gateway**: See the [Gateway Installation](../gateway/installation.md) guide — upgrade to **v2.17.0** for the unified `/trading` route surface, Meteora DAMM v2 AMM, and Orca Whirlpools SDK migration. Connector-scoped `/connectors/{dex}/{type}/*` paths are removed; call `/trading/{amm,clmm,router}/*` instead.
- **Condor + Hummingbot API**: See the [Condor Quickstart](../installation/condor.md) or full documentation at [condor.hummingbot.org](https://condor.hummingbot.org). Pull the latest `main` branches together — this cycle hardens Tailscale and MQTT broker auth, so mixed versions can fail to connect.
## 🏎️ Agent Builders Cup
The **Agent Builders Cup** is an agentic strategy hackathon run by Botcamp, our affiliated education company. Builders created Hummingbot V2 Controllers and Condor Agents, each exchange sponsor team selected its top two, and those agents go head to head in a livestreamed trading competition for a **\$20,000 total prize pool**.
The live trading finals are **October 6–8, 2026**, with winners announced October 9 at our Token2049 side event in Singapore. Sponsor teams: **[Orca](../exchanges/gateway/orca.md), [Derive](../exchanges/derive/index.md), [Gate](../exchanges/gate-io/index.md), [XRPL](../exchanges/xrpl.md), [Bitget](../exchanges/bitget/index.md), and [Meteora](../exchanges/gateway/meteora.md)**. See [botcamp.xyz/hackathons](https://www.botcamp.xyz/hackathons) for the schedule and livestream.
## 🐦 What's New - Hummingbot Client
### 🔌 New Connector (Kalshi Perpetual)
* **[Kalshi](https://kalshi.com)** – Perpetual connector for the USD-margined perpetual futures on Kalshi, the CFTC-regulated US exchange — its margin markets, not its event contracts (`KXBTCPERP` → `BTC-USD`). Full derivative lifecycle: RSA-PSS REST and WebSocket auth, order book and user streams, balances, positions, leverage, and funding. Resting close orders emulate `reduce_only` (Kalshi only accepts it on IOC) so a take-profit is cancelled once its position is gone. Also fixes shared `ExchangePyBase` order tracking so DNS/HTTP timeouts no longer count toward the lost-order limit.
See [Kalshi](../exchanges/kalshi/index.md) for documentation on how to use this connector.
**PRs:** [#8454](https://github.com/hummingbot/hummingbot/pull/8454) | [#8464](https://github.com/hummingbot/hummingbot/pull/8464)
### 🌉 Gateway Client: Unified Routes, Slippage Ramp & Commands
The client now matches Gateway's unified `/trading` surface. Token and pool methods send `chainNetwork` instead of separate `chain` + `network`, which had broken every Gateway executor after the Gateway-side change.
- **Slippage ramp** — `LPExecutorConfig` and `OrderExecutorConfig` gain `slippage_pct` / `slippage_multiplier` / `max_slippage_pct`, defaulting to a **0.05 → 0.25 → 1.25 → 5** ramp that widens only on `SLIPPAGE_EXCEEDED`. LP volume is now fees ÷ fee rate (flow that crossed the position) instead of capital deposited.
- **Token discovery** — `GatewayHttpClient.add_token_by_address` persists a token by mint/address through `POST /tokens/save/{address}`.
- **Trimmed `gateway` commands** — LP and trading actions (`gateway lp`, `pool`, `swap`, `token`) move to Gateway routes, Hummingbot API, and Condor. `gateway ping` folds into bare `gateway`. Remaining surface: `allowance`, `approve`, `balance`, `config`, `connect`, `generate-certs`, `list`. Autocomplete for chains, namespaces, and DEX names is also fixed.
**PRs:** [#8431](https://github.com/hummingbot/hummingbot/pull/8431) | [#8441](https://github.com/hummingbot/hummingbot/pull/8441) (**Thanks to [mlguys](https://github.com/mlguys)! 🙏**) | [#8438](https://github.com/hummingbot/hummingbot/pull/8438)
### 💧 LP Executor & Strategy V2
* **Configurable position refresh** — `LPExecutorConfig.position_refresh_interval` (default 1s) throttles on-chain position reads so multi-executor controllers don't flood RPC. Failed reads count toward the interval, so a 5xx cannot start a per-tick retry storm. ([#8446](https://github.com/hummingbot/hummingbot/pull/8446)). **Thanks to [mlguys](https://github.com/mlguys)! 🙏**
* **Standardized executor configs** — Executor config models are aligned across Order, Position, Grid, DCA, TWAP, XEMM, Arbitrage, and LP, with improved Hyperliquid order-cancel parsing. ([#8421](https://github.com/hummingbot/hummingbot/pull/8421))
* **Faster backtesting** — The controller's `executors_info` view is now active executors plus those that closed within a time window (default one hour), so a long grid backtest is no longer O(n²) in executor count. Executors created on the closing tick now appear in results. ([#8447](https://github.com/hummingbot/hummingbot/pull/8447))
### 🛠️ Connector Updates
* **Hyperliquid:** Auth now rejects a private key that does not derive to the supplied `api_address` at connect time, instead of showing "connected" and failing on every signed request ([#8212](https://github.com/hummingbot/hummingbot/pull/8212)). **Thanks to [ipezygj](https://github.com/ipezygj)! 🙏** Builder fee (HGP-87) resolves on the first order even when the connector is embedded and `start_network()` is skipped — so grid executors deployed from Condor carry the Foundation builder code ([#8417](https://github.com/hummingbot/hummingbot/pull/8417)).
* **Derive:** Config keys renamed to match session-key auth: `derive_api_key` → `derive_wallet_address`, `derive_api_secret` → `session_private_key`, `sub_id` → `subacct_id` (spot and perpetual, mainnet and testnet). **Breaking:** re-run `connect derive` / `connect derive_perpetual` — old YAML keys fail pydantic validation at password unlock and take down client startup. ([#8430](https://github.com/hummingbot/hummingbot/pull/8430))
* **XRPL:** Token balances no longer disappear when a market has no `trading_pair_symbol` (including the shipped `SOLO-XRP` default). ([#8448](https://github.com/hummingbot/hummingbot/pull/8448))
### Other Updates
* **[#8402](https://github.com/hummingbot/hummingbot/pull/8402)** – Updated the README exchange tables on `development` for the v2.16.0 connector lineup
* **[#8403](https://github.com/hummingbot/hummingbot/pull/8403)** – Refreshed the README on `master`, updating the exchange tables along with the Getting Started and Strategies sections
## 🌉 What's New - Gateway
### 🔀 Unified Trading Route Surface
Gateway's public API collapses from **182 paths to 54**. Trading type is now a path segment and the connector a parameter; `openapi.json` is generated from the route table without a running server.
| Was | Is |
|-----|-----|
| `/connectors/{dex}/{type}/*` (128 paths) | removed |
| `/trading/swap/{quote,execute}` | `/trading/router/{quote-swap,execute-quote,execute-swap}` |
| `/connectors/{dex}/{amm,clmm}/quote-swap` | `/trading/{amm,clmm}/quote-swap` |
| `/trading/amm/{add,remove}-liquidity` | `/trading/amm/{add,remove}` |
| `/chains/{solana,ethereum}/*` | `/chains/{chain}/*` |
**Security:** every route that signs is gated from what the route *does*, not a path allowlist — closing unauthenticated `POST /chains/ethereum/approve` (GHSA-r4q2-79mv-2355). Amounts serialize as decimal strings so JSON floats cannot round lamports. Unknown request keys are rejected instead of silently stripped.
**PRs:** [gateway #683](https://github.com/hummingbot/gateway/pull/683) | [hummingbot #8431](https://github.com/hummingbot/hummingbot/pull/8431) | [hummingbot-api #221](https://github.com/hummingbot/hummingbot-api/pull/221)
### 🌊 Meteora DAMM v2 (AMM) & Wide DLMM Ranges
Gateway adds **Meteora DAMM v2** (constant-product `cp-amm`) under `/trading/amm/*` as a second Meteora trading type alongside existing DLMM (`clmm`). Pool info, swap quote/execute, add/remove liquidity, and `create-pool` (requires an explicit `configAddress`; seed price defaults to the unified swap-router quote so new pools open on-market). Positions are NFTs: `remove` requires a `positionAddress`, and `add` without one opens a new position rather than topping up an existing one.
Meteora DLMM `openPosition` no longer rejects ranges wider than 70 bins. 70 is a **transaction** limit, not a position limit (`POSITION_MAX_LENGTH` is 1400). Wide ranges are chunked across transactions; `quote-liquidity` reports `positionCount` and `transactionCount` so callers see the cost before opening.
See [Meteora](../exchanges/gateway/meteora.md) and [Connectors](../gateway/connectors.md).
**PRs:** [#671](https://github.com/hummingbot/gateway/pull/671) | [#696](https://github.com/hummingbot/gateway/pull/696)
### 🐋 Orca Whirlpools SDK Migration
The Orca connector moves to `@orca-so/whirlpools` 8.x, client 7.x, core 3.x, and Solana Kit 5.x. Position closure is reward-complete and Token-2022-aware (fixes `ClosePositionNotEmpty` from uncollected rewards). Position, pool, mint, and tick-array reads come from one `getMultipleAccounts` snapshot so fee math no longer mixes slots.
**PRs:** [#676](https://github.com/hummingbot/gateway/pull/676) | [#687](https://github.com/hummingbot/gateway/pull/687) | **Thanks to [mlguys](https://github.com/mlguys)! 🙏**
### Other Updates
* **[#675](https://github.com/hummingbot/gateway/pull/675)** – Fixed Uniswap CLMM `execute-swap` reverting with "Too little received" by clearing `sqrtPriceLimitX96`, which had capped every swap at its own average execution price and turned normal price impact into a failed, gas-burning transaction (slippage already comes from `amountOutMinimum`)
* **[#695](https://github.com/hummingbot/gateway/pull/695)** – Fixed swap responses to report confirmed on-chain amounts, returned complete CLMM position listings, resolved Raydium positions from an address instead of requiring custody of the wallet key, and corrected the CoinGecko Demo and Pro onchain endpoints
* **[#703](https://github.com/hummingbot/gateway/pull/703)** – Fixed the default wallet to resolve from the chain a request names, so an EVM swap no longer inherited the Solana default address and failed validation
* **[#677](https://github.com/hummingbot/gateway/pull/677)** – Switched the Docker buildx workflow to build images on every push to `main` / `development`, not only on merged pull requests
## 🦅 What's New - Condor and Hummingbot API
### 🤖 New Condor Agents
This cycle ships a set of ready-to-run trading agents — CLMM LP, HIP-3 funding, XRPL CLOB, Derive flow, Meteora launch LP, and adaptive grids:
* **Solana DEX LP Expert** — autonomous CLMM liquidity on Meteora / Orca / Raydium: scan GeckoTerminal by fee yield, size into slots, place LP Executors, recycle out-of-range idle capital. ([#162](https://github.com/hummingbot/condor/pull/162))
* **Delta-Neutral Funding Agent** — HIP-3 (`XYZ:` issuer perps on Hyperliquid) carry: two `pmm_mister` controllers, beta-weighted long/short so net delta ≈ 0, leaned to the funding-favorable side. ([#165](https://github.com/hummingbot/condor/pull/165))
* **XRPL CLOB Market Maker** — on-ledger maker for RLUSD/XRP that quotes tighter than AMM pool fees so pathfinding routes takers to the CLOB; fair value from a CEX, not on-ledger. ([#176](https://github.com/hummingbot/condor/pull/176))
* **Derive Perp Smart-Money Flow Agent** — directional LONG/SHORT on `derive_perpetual` from cross-market capital-flow plus a Solana on-chain pulse. ([#178](https://github.com/hummingbot/condor/pull/178))
* **Meteora Launch LP** — early LP on tokens graduating into DAMM v2, with mint/freeze-authority and holder-concentration gates, plus a chain-agnostic `manage_amm` tool. ([#192](https://github.com/hummingbot/condor/pull/192))
* **Adaptive Grid Trader** — grid whose range comes from measured ATR, re-leaned hourly, with `limit_price` as the known worst-case exit. ([#179](https://github.com/hummingbot/condor/pull/179))
See [Condor](../condor/index.md) for documentation.
### 📈 DEX Trade Panel
The Condor web dashboard trade panel now treats a Gateway network like a CEX: pick a DEX venue, chart the pool, and manage LP positions. Venue traits (order book? LP? which strategies?) come from the API instead of a CEX/DEX boolean. Follow-up polish shares the default server with Telegram and warns on Meteora's bin cap before Gateway rejects the open.
**PRs:** [#203](https://github.com/hummingbot/condor/pull/203) | [#214](https://github.com/hummingbot/condor/pull/214) | [hummingbot-api #206](https://github.com/hummingbot/hummingbot-api/pull/206)
### 🧠 Agent Runtime, Primitives & Custom LLMs
* **Custom OpenAI-compatible endpoints** — Venice, Together, Fireworks, vLLM, or LM Studio work as a first-class model source across Telegram, the web dashboard, and agent consults/loops. Endpoints live in `config.yml`; agent keys are `custom@<endpoint>:<model-id>`. ([#175](https://github.com/hummingbot/condor/pull/175))
* **General agent upgrade** — finished background tasks stream back into the chat that started them; Telegram conversations and agent bindings survive respawn; shared skill/routine library (`routine_cookbook`, `backtest_flow`, `self_improve`); backtesting on one surface. ([#194](https://github.com/hummingbot/condor/pull/194))
* **Discoverable primitives** — `catalog()` / `describe()` / `call_routine()` index fetchers and routines from the live code so agents can find and compose them without guessing imports. ([#217](https://github.com/hummingbot/condor/pull/217))
* **Orphaned CLMM recovery** — `manage_clmm` plus `manage_executors` `orphaned` / `resolve_orphan` actions, so a terminal LP executor still holding an on-chain position is visible and recoverable instead of minting a second one. ([#204](https://github.com/hummingbot/condor/pull/204))
### 🔒 Tailscale, MQTT & Broker Hardening
Condor and Hummingbot API close the remaining public-bind gaps from the [v2.15.1 Tailscale work](2.15.1.md#tailscale-security):
- **Postgres and EMQX bind `127.0.0.1` only.** Docker no longer publishes them on all interfaces ahead of the host firewall.
- **Tailscale is exclusive.** Enabling it binds the API and Condor dashboard to loopback and proxies through `tailscale serve`, instead of joining the tailnet while port 8000 stayed public.
- **MQTT requires authentication.** The EMQX broker no longer accepts anonymous `hbot/#` subscribe or `hbot/<id>/stop` publish. Existing Linux deploys that came up with zero broker accounts need `make emqx-auth-reset`.
- **`make doctor`** checks deps, `.env`, model readiness, dashboard bind, and API/broker connectivity. Condor delegates hummingbot-api setup instead of rewriting `.env`.
See the [Tailscale guide](../hummingbot-api/tailscale.md).
**PRs:** [condor #213](https://github.com/hummingbot/condor/pull/213) | [condor #231](https://github.com/hummingbot/condor/pull/231) | [hummingbot-api #220](https://github.com/hummingbot/hummingbot-api/pull/220) | [hummingbot-api #222](https://github.com/hummingbot/hummingbot-api/pull/222) | [hummingbot-api #225](https://github.com/hummingbot/hummingbot-api/pull/225) | [hummingbot-api #229](https://github.com/hummingbot/hummingbot-api/pull/229)
### Other Updates
* **[condor #172](https://github.com/hummingbot/condor/pull/172)** – Fixed agent startup failing on an unquoted numeric MCP username or password in `config.yml`, which had broken LM Studio and other pydantic-ai backends
* **[condor #180](https://github.com/hummingbot/condor/pull/180)** – Added ticker volume to the web dashboard trade page
* **[condor #196](https://github.com/hummingbot/condor/pull/196)** – Fixed the executor risk gate to measure planned exposure in quote units, instead of counting a base-token `amount` as quote and rejecting valid executors **Thanks to [mlguys](https://github.com/mlguys)! 🙏**
* **[condor #200](https://github.com/hummingbot/condor/pull/200)** – Fixed the risk gate to accept `controller_id` as a top-level argument as well as inside `executor_config`, unblocking executor creates on the Derive Perp Smart-Money Flow agent
* **[condor #205](https://github.com/hummingbot/condor/pull/205)** – Added the user feedback survey to the README
* **[condor #224](https://github.com/hummingbot/condor/pull/224)** – Hardened sharing: matched BIP-39 recovery phrases regardless of separator, fixed outbox unshare, flush, and off-switch handling, and added secret redaction at ingress
* **[condor #240](https://github.com/hummingbot/condor/pull/240)** – Completed a 114-item security, correctness, and performance sweep, including owner-scoped reports, live share revocation, and moving Gateway infrastructure off the agent surface
* **[hummingbot-api #202](https://github.com/hummingbot/hummingbot-api/pull/202)** – Added compression to bot data payloads
* **[hummingbot-api #204](https://github.com/hummingbot/hummingbot-api/pull/204)** – Fixed controller config class resolution and removed the deprecated stat-arb controller
* **[hummingbot-api #205](https://github.com/hummingbot/hummingbot-api/pull/205)** – Improved backtesting storage by archiving results to disk instead of holding them in memory
* **[hummingbot-api #215](https://github.com/hummingbot/hummingbot-api/pull/215)** – Improved Gateway certificate generation and fixed order book validation when registering trading pairs
* **[hummingbot-api #221](https://github.com/hummingbot/hummingbot-api/pull/221)** – Adopted Gateway's unified route surface, and recorded landed reverts and position rent on LP and swap executor events
* **[hummingbot-api #223](https://github.com/hummingbot/hummingbot-api/pull/223)** – Added the human-readable field prompt to the connector `config-map` endpoint, so clients no longer had to invent their own labels for credential forms
* **[hummingbot-api #226](https://github.com/hummingbot/hummingbot-api/pull/226)** – Added executor performance as a first-class read surface (`GET /performance/history` and `/latest`), so an executor's PnL survived a restart instead of being booked at zero
* **[hummingbot-api #234](https://github.com/hummingbot/hummingbot-api/pull/234)** – Fixed order-history search to page by a real keyset cursor, instead of returning the same `"0:"` cursor and looping on page one foreverShown in full with attribution under the source's licence. Licence: Apache-2.0
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.