256 Foundation audits Bitcoin mining machine firmware and reveals third-party risks
Bitcoin News posted on the X platform that the 256 Foundation has launched the 256 Red Team security project, which audits ASIC miner firmware through reverse engineering, real-time traffic capture, and reconciliation by share level. The team stated that 41 issue reports have been submitted regarding the original Bitmain firmware as well as third-party firmware such as LuxOS, VNISH, and Braiins OS.Identified issues include unauthenticated factory APIs, paths that allow root access, default credentials, built-in vendor SSH keys, and updaters that cannot verify installed content. After reverse engineering the Bitmain miner daemon and checking real-time connections, researchers reported that no evidence of hash power hijacking, remote kill switches, or hidden beacons was found in the original Bitmain firmware; the related risks are mainly concentrated in third-party "optimized" firmware.Researchers have submitted 3 responsible disclosures to VNISH, Luxor, and Braiins, granting each party 30 days to respond before public disclosure. MicroBT, Canaan, Auradine, Bitdeer, and ePIC will undergo follow-up audits.