# Update 4 about Bisq Exploit response

**URL:** <https://bisq.community/t/update-4-about-bisq-exploit-response/13742>\
**Category:** Uncategorized\
**Created:** [May 15, 2026, 8:48am UTC](https://bisq.community/t/update-4-about-bisq-exploit-response/13742 "2026-05-15T08:48:20Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![HenrikJannsen](https://bisq.community/letter_avatar/henrikjannsen/32/5_5575768a8748004e209b776fc1b2916d.png) [@HenrikJannsen](https://bisq.community/u/HenrikJannsen)\
**Post date:** [May 17, 2026, 2:22am UTC](https://bisq.community/t/update-4-about-bisq-exploit-response/13742/5 "2026-05-17T02:22:14Z")

</div>

### Context to the binary signing process used for that release:

Alejandro García (key ID E222AA02) built all binaries except the new aarch64 macOS target, as he does not yet have a VM configured for it. Therefore, Henrik Jannsen (key ID 387C8307) provided the aarch64 macOS binary and signed the binaries he received from Alejandro.

Our in-app verification tool does not currently support mixed keys or signatures. It reads the key ID specified in `signingkey.asc` and applies it uniformly to all binaries. For this reason, Henrik re-signed all binaries using his own key so that the verification process remains consistent and compatible with the current implementation.

Please note that both Alejandro García and Henrik Jannsen are official release managers for Bisq 1 and Bisq 2. Their public keys have been included in the source code for a long time and are distributed with the application to enable independent key verification and cross-checking.

The partial\_signatures\_by\_E222AA02.zip contains the original signatures provided by Alejandro. Users can use those to verify the binaries (except aarch64 macOS) using key E222AA02.

Relevant references:

- `github.com/bisq-network/bisq/tree/master/desktop/src/main/resources/keys`
- `https://bisq.network/pubkey/E222AA02.asc`
- `https://bisq.network/pubkey/387C8307.asc`

The release process will be further improved in the next version through the introduction of reproducible builds.

I added that note to the release page and the partial\_signatures\_by\_E222AA02.zip file to the assets. Hope that explains and resolves the confusion.

> **[Release v1.10.0 · bisq-network/bisq](https://github.com/bisq-network/bisq/releases/tag/v1.10.0)**
>
> Bisq 1.10.0 follows the recent security incident with a focused hardening release that improves trade protocol security, network message validation, release verification, and hardening against supp...

---

_[View the full topic](https://bisq.community/t/update-4-about-bisq-exploit-response/13742)._
