# Update 3 about Bisq Exploit response

**URL:** <https://bisq.community/t/update-3-about-bisq-exploit-response/13738>\
**Category:** Uncategorized\
**Created:** [May 13, 2026, 7:54am UTC](https://bisq.community/t/update-3-about-bisq-exploit-response/13738 "2026-05-13T07:54:54Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![hardheadarea](https://bisq.community/letter_avatar/hardheadarea/32/5_5575768a8748004e209b776fc1b2916d.png) [@hardheadarea](https://bisq.community/u/hardheadarea)\
**Post date:** [May 13, 2026, 8:48pm UTC](https://bisq.community/t/update-3-about-bisq-exploit-response/13738/4 "2026-05-13T20:48:06Z")

</div>

Why would Alejandro’s key not work? This is the potential crisis I hope to see you guys avoid. Since _only_ Alejandro’s key has been used for recent releases, switching to a different key is going to be an indication of a compromise. It’s not enough to have “some key” sign the release, it’s very important to have consistent chain. If any key other than B493319106CC3D1F252E19CBF806F422E222AA02 signs the new release, it is 0.00% “covered. That’s how PGP/GPG and trust works.

---

_[View the full topic](https://bisq.community/t/update-3-about-bisq-exploit-response/13738)._
