The 256 Foundation published results from its inaugural Red Team security audit of Bitcoin mining firmware, finding 41 vulnerabilities in popular third-party firmware alternatives (LuxOS, VNISH, Braiins OS) while stock Bitmain firmware for the S19j Pro and S21 models came back clean. The audit documented critical issues including default fleet credentials that are never rotated, vendor SSH keys baked into firmware images, unauthenticated factory APIs exposing local root access, and firmware update mechanisms that skip cryptographic verification. The foundation submitted coordinated disclosures to the three affected vendors with a 30-day window before publishing technical specifics. These findings highlight the risks of closed-source firmware on hardware accounting for roughly 90% of the Bitcoin mining market.
Source: Read the original article

