Release notes
This is an important security update that fixes vulnerabilities identified during our recent security audit.
Updating to this version is required to continue trading and using BSQ and the Bisq DAO.
DAO and Network Integrity
- Canonical hash/signature encodings reduce ambiguity across DAO and P2P payloads.
- DAO block signatures, trusted providers, lite-node checks, checkpoints, and payload hash commitments are strengthened.
- BSQ block bridge delivery requires contiguous state and recovers gaps.
- Malformed decrypted votes are isolated per voter, while malformed merit can no longer remove a majority-committed blind vote.
- Proposal validation is consistent across startup and live nodes and applies to the entire activating cycle.
Reputation and Bonded Roles
- Account-age and signed-witness bridge validation is bound to ownership and trusted witness chains.
- Bonded-role registrations and lockups are checked against the correct proposal and collateral lifecycle.
- Merit issuance and Burning Man accounting receive additional integrity checks and refreshed release data.
Trading and Messaging
- Fiat buyer-account validation, deposit/DPT binding, support-message authentication, and dispute-agent authentication are hardened.
Credits to reporters of vulnerabilities
Installation
macOS
Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:

Grant permissions by:
- run
sudo xattr -rd com.apple.quarantine /Applications/Bisq.appin a terminal (type Terminal in the Apple search box) - open
Bisqagain
More details can be found here.
Windows
For similar reasons you will get that warning at Windows: Windows protected your PC
- Click the
More infobutton when prompted - Click the
Run anywaybutton when prompted
More details can be found here.
Verify download
See the verification and installation instructions in the Bisq Wiki.