256 Foundation has launched its 256 Red Team security effort to audit ASIC miner firmware, according to a post shared by Bitcoin News on X. The group said it used reverse engineering, live traffic capture, and share-level reconciliation in its review process.
The team reported that it has filed 41 issue reports covering stock Bitmain firmware as well as third-party options including LuxOS, VNISH, and Braiins OS. The issues identified include unauthenticated factory APIs, paths that can grant root access, default credentials, embedded vendor SSH keys, and update tools that cannot verify what is being installed.
After decompiling Bitmain miner daemons and examining live connections, the researchers said they found no evidence of hashpower skimming, remote kill switches, or covert beacons in Bitmain’s stock firmware. They said the main concerns were concentrated in third-party “optimization” firmware instead.
The researchers have sent three responsible disclosures to VNISH, Luxor, and Braiins, giving each party 30 days to respond before public disclosure. Future audits are planned for MicroBT, Canaan, Auradine, Bitdeer, and ePIC.
256 Foundation has launched the 256 Red Team security project to audit ASIC miner firmware, according to a post from Bitcoin News on X. The group said its review combines reverse engineering, live traffic capture, and share-level reconciliation.
The team said it has submitted 41 issue reports covering stock Bitmain firmware and third-party firmware including LuxOS, VNISH, and Braiins OS. The problems identified include unauthenticated factory APIs, paths that can provide root access, default credentials, embedded vendor SSH keys, and update tools that cannot verify the contents being installed.
No evidence of hashpower skimming found in stock Bitmain firmware
After decompiling Bitmain miner daemons and checking live connections, the researchers said they found no evidence of hashpower skimming, remote kill switches, or covert beacons in Bitmain’s stock firmware. They added that the main risks were concentrated in third-party “optimization” firmware.
Responsible disclosure process is underway
The researchers said they have sent three responsible disclosures to VNISH, Luxor, and Braiins, giving each party 30 days to respond before the findings are made public. Follow-up audits are set to cover MicroBT, Canaan, Auradine, Bitdeer, and ePIC.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.