Vulnerability in Bisq found and disclosed

Haveno Core Team | 07 Jul 2021

In July 2021, while Haveno was in its infancy, we found a critical vulnerability in Bisq.

This issue allowed an attacker to harvest user payment information on Bisq. The information included:

All the data could have been harvested at no cost at all for the attacker. We don’t know how long Bisq has had this vulnerability for and if it was exploited. We know that it was probably not exploited at a large scale, or Bisq’s support team would have noticed a spike in support tickets.

We reported the vulnerability to Bisq and helped them patch it. They then released a patched version of their software, which fixed the problem (v1.7.0).

The disclosure on Haveno’s Twitter:

The disclosure on Bisq’s Twitter:

