← Radar

Incident case file

Sign in to watch

Bisq v1 — Miner Fee Manipulation in Multisig Trading Protocol

Incident date May 1, 2026

0 views

Partially recoveredBitcoinSmart contract exploitCluster: BISQ-BTC-2026-05

Estimated loss

$858K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: TODO

Funds moved to: TODO
TODO

Timeline: On May 1, 2026, an unknown attacker exploited a vulnerability in Bisq v1 trading protocol. The attacker used a fake Bisq v1 client to exploit insufficient validation on miner fees submitted by the trade initiator. By manipulating the miner fee parameter in multisig transactions, the attacker was able to divert funds from legitimate trades — the trade initiator could specify an arbitrarily high miner fee that would be deducted from the multisig deposit, effectively stealing from the counterparty. The Bisq team acknowledged the issue and offered affected users reimbursement in either BTC or BSQ tokens. Total losses amounted to approximately $858,000 (~11 BTC).

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)