Bitcoin Mining Firmware Exposed: 41 Vulnerabilities Uncovered
A security audit conducted by The 256 Foundation has uncovered 41 vulnerabilities in popular third-party firmware used for Bitcoin mining. These flaws, which include default credentials and unauthenticated APIs, pose risks to mining operators and the network's overall security.
The foundation tested a range of firmware, including LuxOS, VNISH, and Braiins OS, but found no malicious behavior in Bitmain's stock firmware. The audit was prompted by concerns over the potential for vulnerabilities in these third-party solutions, which are widely used in the industry.
The 256 Foundation has given vendors a 30-day deadline to address these issues, emphasizing the need for transparency and security in mining software to protect operators and maintain Bitcoin's decentralized integrity.