Bitcoin News said in a post on X that 256 Foundation has launched the 256 Red Team, a security effort focused on auditing ASIC miner firmware. The project uses reverse engineering, live traffic capture, and share-level reconciliation to inspect firmware behavior.
According to the team, it has filed 41 issue reports covering Bitmain’s stock firmware as well as third-party options including LuxOS, VNISH, and Braiins OS. Reported findings include unauthenticated factory APIs, paths that can lead to root access, default credentials, embedded vendor SSH keys, and update mechanisms that cannot verify what is being installed.
After decompiling Bitmain’s miner daemon and reviewing live connections, researchers said they found no evidence in Bitmain’s original firmware of hashrate skimming, a remote kill switch, or covert beacons. They said the main risks were concentrated in third-party “optimization” firmware. The team has also sent three responsible disclosures to VNISH, Luxor, and Braiins, giving each party 30 days to respond before public disclosure. MicroBT, Canaan, Auradine, Bitdeer, and ePIC are set for later audits.
ChainCatcher reported that Bitcoin News said in an X post that 256 Foundation has launched the 256 Red Team, a security project created to audit ASIC miner firmware. The review work includes reverse engineering, live traffic capture, and share-level reconciliation.
The team said it has submitted 41 issue reports involving Bitmain’s stock firmware and third-party firmware including LuxOS, VNISH, and Braiins OS.
Issues identified in the review
The reported problems include unauthenticated factory APIs, paths that can provide root access, default credentials, embedded vendor SSH keys, and updater tools that cannot verify the contents being installed.
Findings on Bitmain’s original firmware
After decompiling Bitmain’s miner daemon and examining live connections, researchers said they found no evidence in Bitmain’s original firmware of hashrate skimming, a remote kill switch, or covert beacons. The security concerns, they said, were mainly concentrated in third-party “optimization” firmware.
Responsible disclosure timeline
Researchers have sent three responsible disclosures to VNISH, Luxor, and Braiins, and gave each party 30 days to respond before the findings are made public.
MicroBT, Canaan, Auradine, Bitdeer, and ePIC will be included in later audits.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.