# Bisq 1.10.0 is released!

**URL:** <https://bisq.community/t/bisq-1-10-0-is-released/13746>\
**Category:** Uncategorized\
**Created:** [May 16, 2026, 3:14am UTC](https://bisq.community/t/bisq-1-10-0-is-released/13746 "2026-05-16T03:14:47Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![HenrikJannsen](https://bisq.community/letter_avatar/henrikjannsen/32/5_5575768a8748004e209b776fc1b2916d.png) [@HenrikJannsen](https://bisq.community/u/HenrikJannsen)\
**Post date:** [May 16, 2026, 3:14am UTC](https://bisq.community/t/bisq-1-10-0-is-released/13746/1 "2026-05-16T03:14:47Z")

</div>

# Bisq 1.10.0 is released!

This release focuses on security hardening following the recent security incident and includes major improvements to trade protocol validation, network message handling, release verification, and protection against supply chain attacks.

Please download the new app from inside your Bisq application which includes automated verifications or download and verify manually at:

> **[Release v1.10.0 · bisq-network/bisq](https://github.com/bisq-network/bisq/releases/tag/v1.10.0)**
>
> Bisq 1.10.0 follows the recent security incident with a focused hardening release that improves trade protocol security, network message validation, release verification, and hardening against supp...

A full post-mortem covering the incident, investigation, impact assessment, and all security improvements will be published on the Bisq website in the coming days.

## Reimbursement for affected traders

A proposal has been published and if it gets accepted by the DAO in the upcoming voting cycle it will lead to a timely, full refund in Bitcoin.

> <https://github.com/bisq-network/proposals/issues/481>
>
> \# Proposal for Refunds to Victims of the May 1st Bisq 1 Trade Protocol Incident
> …
> An anonymous group (referred to here as the “Refund Angels” or “RA”) has agreed to advance the refunds for victims affected by the May 1st Bisq 1 trade protocol incident.
> 
> Victims will be reimbursed after:
> 
> \* the DAO cycle voting has concluded and this proposal has been accepted, and
> \* the arbitrator has confirmed their eligibility for reimbursement.
> 
> This approach enables Bisq to compensate victims quickly, in full, and directly in BTC.
> 
> The more complex and time-consuming discussion regarding how — and at which BSQ/BTC exchange rate — the Refund Angels will later be reimbursed by the DAO will be deferred to the next DAO cycle, as no consensus has yet been reached on that matter.
> 
> Importantly, this is primarily an internal DAO discussion and does not affect the victims’ ability to receive timely refunds.

## Release notes:

# Security Improvements

- Hardened validation of trade protocol messages, deposit transactions, payout transactions, trade contract data, and peer-provided wallet data.
- Improved protection against supply chain attacks by adding PGP signature verification to dependency resolution.
- Updated Java, JavaFX, Tor, bitcoinj, and other dependencies to their latest stable versions.
- Improved the build process with additional verification of the build toolchain.
- Added Docker-based DAO and end-to-end trade tests to GitHub Actions. This work will continue over the coming weeks.

# Security Improvements Affecting the Trading Experience

- The maximum trade amount is now limited to `0.125 BTC`.
- Offers and trades are now restricted to a maximum price deviation of `25%`.
- Disabled XMR auto-confirmation. No issues have been identified, but a more in-depth security audit is planned for this area.
- Removed the webcam library used for QR code scanning to reduce security risks. A more secure replacement will be introduced in the next release.
- Removed dispute chat attachments and dispute log file transfers for security reasons.
- Added a popup reminder advising users not to use the Bisq wallet as a long-term storage wallet when holding higher balances.

# UX

- Improved performance by updating JavaFX and Java versions.

# Deployment

- macOS releases now support both Apple Silicon and Intel-based Macs.
- The reproducible build system is now partially in place, though not yet applied to this release. The next release will fully benefit from it.

Thank you to everyone who helped review, test, investigate, and support the project.

---

<div class="post-metadata">

**Author:** ![MnM](https://bisq.community/user_avatar/bisq.community/mnm/32/257_2.png) [@MnM](https://bisq.community/u/MnM)\
**Post date:** [May 16, 2026, 6:45am UTC](https://bisq.community/t/bisq-1-10-0-is-released/13746/2 "2026-05-16T06:45:28Z")

</div>



---

<div class="post-metadata">

**Author:** ![zlatamineral](https://bisq.community/letter_avatar/zlatamineral/32/5_5575768a8748004e209b776fc1b2916d.png) [@zlatamineral](https://bisq.community/u/zlatamineral)\
**Post date:** [May 16, 2026, 2:09pm UTC](https://bisq.community/t/bisq-1-10-0-is-released/13746/3 "2026-05-16T14:09:29Z")

</div>

👏 👏 👏 💚💚💚

Question, re: “Removed dispute chat attachments and dispute log file transfers for security reasons.”

How is one expected to supply evidentiary documentation for disputes?

---

<div class="post-metadata">

**Author:** ![suddenwhipvapor](https://bisq.community/user_avatar/bisq.community/suddenwhipvapor/32/3291_2.png) [@suddenwhipvapor](https://bisq.community/u/suddenwhipvapor)\
**Post date:** [May 16, 2026, 7:24pm UTC](https://bisq.community/t/bisq-1-10-0-is-released/13746/4 "2026-05-16T19:24:11Z")

</div>

any file sharing service will work, one that I personally often suggest is temp.sh but also dropbox share links work well on tor browser

---

<div class="post-metadata">

**Author:** ![noremote](https://bisq.community/letter_avatar/noremote/32/5_5575768a8748004e209b776fc1b2916d.png) [@noremote](https://bisq.community/u/noremote)\
**Post date:** [May 16, 2026, 10:31pm UTC](https://bisq.community/t/bisq-1-10-0-is-released/13746/6 "2026-05-16T22:31:36Z")

</div>

The PGP key used to sign this release is not the same as the one used to sign previous releases. That’s very sketchy. Can you ask Alejandro to sign this? If not, then why is a different team releasing the post-exploit software? That’s a _big big big_ red flag.

---

<div class="post-metadata">

**Author:** ![suddenwhipvapor](https://bisq.community/user_avatar/bisq.community/suddenwhipvapor/32/3291_2.png) [@suddenwhipvapor](https://bisq.community/u/suddenwhipvapor)\
**Post date:** [May 17, 2026, 1:21pm UTC](https://bisq.community/t/bisq-1-10-0-is-released/13746/8 "2026-05-17T13:21:01Z")

</div>

Your concern was already posted (and replied to) [here](https://bisq.community/t/update-4-about-bisq-exploit-response/13742/5)
