rules / HM011
HM011 deprecated-fhe-api LOW
Legacy TFHE / Gateway API in use
Why it matters
The `TFHE.*` library, `Gateway.requestDecryption` and `GatewayCaller` belong to pre-protocol fhEVM releases. They are no longer maintained, their security assumptions (a single trusted gateway) differ from the current KMS-verified flow, and code written against them will not compile against `@fhevm/solidity`.
Fix
Migrate to `import {FHE, euint64, externalEuint64} from "@fhevm/solidity/lib/FHE.sol";`, replace `TFHE.` with `FHE.`, and move decryption to `FHE.makePubliclyDecryptable` plus `FHE.checkSignatures` (or the relayer user-decrypt flow).
Check locally
homomorph scan . --rules HM011