Bitcoin Miners Found Running Firmware with 41 Vulnerabilities
The 256 Foundation conducted its first firmware security audit of Bitcoin miners and found 41 vulnerabilities in third-party software.
The audit, which was part of the foundation's mission to create a fully open Bitcoin mining ecosystem, focused on stock firmware on Bitmain's S19j Pro and S21 miners, as well as several widely used third-party firmware alternatives.
Stock Bitmain firmware showed no evidence of hashrate skimming or other malicious behaviors, but the third-party options introduced new attack vectors. The audit found default fleet credentials that were never rotated, vendor SSH keys baked directly into firmware images, and unauthenticated factory APIs that exposed local root access without requiring a password.
The 256 Foundation submitted coordinated disclosures to VNISH, Luxor, and Braiins with a 30-day window to address the findings before technical specifics are made public. The audit demonstrates the importance of open-source firmware and the need for miners to inspect, modify, and verify every layer of their mining infrastructure.
The findings also carry weight at the network level, as Bitcoin's security model depends on hashrate being distributed across many independent operators with genuinely independent infrastructure.