256 Foundation flags 41 issues in ASIC firmware audit, with risks centered on third-party builds
256 Foundation has launched its 256 Red Team security effort to audit ASIC miner firmware, according to a post shared by Bitcoin News on X. The group said it used reverse engineering, live traffic capture, and share-level reconciliation in its review process. The team reported that it has filed 41 issue reports covering stock Bitmain firmware as well as third-party options including LuxOS, VNISH, and Braiins OS. The issues identified include unauthenticated factory APIs, paths that can grant root access, default credentials, embedded vendor SSH keys, and update tools that cannot verify what is being installed. After decompiling Bitmain miner daemons and examining live connections, the researchers said they found no evidence of hashpower skimming, remote kill switches, or covert beacons in Bitmain’s stock firmware. They said the main concerns were concentrated in third-party “optimization” firmware instead. The researchers have sent three responsible disclosures to VNISH, Luxor, and Braiins, giving each party 30 days to respond before public disclosure. Future audits are planned for MicroBT, Canaan, Auradine, Bitdeer, and ePIC.








