Release notes v2.1.12
This is an important security update that fixes vulnerabilities identified during our recent security audit.
Updating to this version is required to continue trading.
Reputation Privacy and Integrity
- Account-age and signed-witness reputation is bound to proven ownership and the requesting Bisq 2 profile.
- Public reputation records use a nullifier and day bucket rather than raw witness identifiers and exact timestamps.
- Legacy and conflicting claims receive conservative scoring.
Bonded Roles
- Bonded-role registrations identify the exact accepted proposal and lockup transaction.
- Oracle-authored registrations are persisted, recovered, and revalidated against Bisq 1 DAO state.
- Bonded-reputation unlock status is committed to oracle signatures.
Bridge Reliability
- Bisq 1 bridge state recovery enforces contiguous blocks, handles gaps and duplicates, and replays buffered blocks after catch-up.
- RPC deadlines and fail-safe retry behavior prevent an unavailable bridge from blocking interactive services.
Note that there is an issue with the download target for Bisq-2.1.12.dmg now that both Intel and Apple Silicon macOS are supported.
To ensure that in-app updates work correctly for Apple Silicon users, we uploaded a copy of Bisq-aarch64-2.1.12.dmg under the filename Bisq-2.1.12.dmg.
As a result, users on Intel-based macOS may currently receive an incompatible version through the in-app download process and will need to download the correct Intel build manually.
We decided to address this issue in an upcoming feature release rather than delay this security-relevant release.
Installation
macOS
Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:

Grant permissions by:
- run
sudo xattr -rd com.apple.quarantine /Applications/Bisq2.appin a terminal (type Terminal in the Apple search box) - open
Bisq2again
More details can be found here.
Windows
For similar reasons you will get that warning at Windows: Windows protected your PC
- Click the
More infobutton when prompted - Click the
Run anywaybutton when prompted
More details can be found here.
Verify download
See the verification and installation instructions in the Bisq Wiki.