Release notes
This is an important security update that fixes vulnerabilities identified during our recent security audit.
Updating to this version is required to continue trading.
Security
- Refund payouts require validated escrow evidence and authenticated claimant/agent authorization.
- Replayed refund receipts and cross-chain payout reservations are blocked.
- Refund transaction provenance, finality, receiver outputs, and transaction IDs are validated.
- Burning Man proposal inputs and address-list resources fail closed when invalid or obsolete.
- DAO readiness is revoked after checkpoint failure, and BSQ swap signatures require exact publication handoffs.
- Update to latest tor version
Trading
- Altcoin amounts honor registered precision and zero-rounded amounts are rejected.
- Deposit liveness handling uses broadcast evidence and configured explorer scope.
- Withdrawals complete after commit, obsolete mediation results are ignored, and unknown BTC fee receivers are rejected.
- Security deposits remain editable down to the minimum floor.
Reliability and Builds
- Shutdown sequencing is safer across JavaFX, network, Tor, broadcaster, and desktop components.
- Store checks avoid copying the full store.
- Reproducible Debian packaging, Docker builds, Gradle configuration cache, and Gradle 9.0.0 support are included.
Installation
macOS
Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:
<img src="https://github.com/user-attachments/assets/e058c34c-38f5-4329-8fc5-f48b3f2ba4dd" width="180"/>
Grant permissions by:
- run
sudo xattr -rd com.apple.quarantine /Applications/Bisq.appin a terminal (type Terminal in the Apple search box) - open
Bisqagain
More details can be found here.
Windows
For similar reasons you will get that warning at Windows: Windows protected your PC
- Click the
More infobutton when prompted - Click the
Run anywaybutton when prompted
More details can be found here.
Verify download
See the verification and installation instructions in the Bisq Wiki.