Incident case file
Sign in to watchBisq v1 — Miner Fee Manipulation in Multisig Trading Protocol
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: TODO
Timeline: On May 1, 2026, an unknown attacker exploited a vulnerability in Bisq v1 trading protocol. The attacker used a fake Bisq v1 client to exploit insufficient validation on miner fees submitted by the trade initiator. By manipulating the miner fee parameter in multisig transactions, the attacker was able to divert funds from legitimate trades — the trade initiator could specify an arbitrarily high miner fee that would be deducted from the multisig deposit, effectively stealing from the counterparty. The Bisq team acknowledged the issue and offered affected users reimbursement in either BTC or BSQ tokens. Total losses amounted to approximately $858,000 (~11 BTC).
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)