Skip to content

Releases: bisq-network/bisq

v1.10.3

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 06 Jul 20:21
v1.10.3
292f438

Release notes

This is an important security update that closes several gaps in trade protocol validation, message authentication, and filter safety identified during our ongoing security audit.

Filter Safety

  • Filter-provided added BTC nodes and seed nodes are disabled because those fields are not currently covered by the filter signature.
  • Previously persisted filterProvidedBtcNodes and filterProvidedSeedNodes config values are ignored on startup.
  • Filter-provided BTC fee receiver addresses are temporarily ignored; DAO donation addresses and Burning Man receiver addresses remain active.

Trade And API Safety

  • The Core API rejects payment-start confirmation for trades that are already failed.
  • Buyer-side deposit/DPT processing checks that the peer deposit transaction matches the local transaction before wallet or trade-state mutation.
  • Delayed payout transactions must spend output zero of the matching deposit transaction.
  • Stale deposit confirmation callbacks are ignored when they refer to an older deposit transaction.

Message Authentication

  • Trade chat and ACK messages must be signed by the expected trade peer.
  • Dispute opening messages must be signed by the declared dispute opener.
  • Peer-opened dispute and dispute-result messages must be signed by the locally expected mediation, or refund agent.
  • Invalid messages are ignored before dispute, chat, or persistence state is mutated.

See full release notes at: https://github.com/bisq-network/bisq/tree/release/v1.10.3/release-notes/1.10.3

Installation

macOS

Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:

Grant permissions by:

  • run sudo xattr -rd com.apple.quarantine /Applications/Bisq.app in a terminal (type Terminal in the Apple search box)
  • open Bisq again

More details can be found here.

Windows

For similar reasons you will get that warning at Windows: Windows protected your PC

  • Click the More info button when prompted
  • Click the Run anyway button when prompted

More details can be found here.

Verify download

See the verification and installation instructions in the Bisq Wiki.

v1.10.2

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 19 Jun 02:13
v1.10.2
ff36958

Release notes

DAO Consensus Security

  • DAO merit validation is hardened at and after block 954_200.
  • V2 merit validation checks embedded merit issuances against DAO state compensation issuances, verifies signatures, ignores future merit, and prevents duplicate issuance tx IDs from contributing more than once.
  • Legacy merit behavior remains in place before block 954_200 for historical replay compatibility.

Arithmetic Hardening

  • DAO consensus arithmetic is height-gated: legacy arithmetic before block 954_200, exact V2 arithmetic at and after activation.
  • Exact arithmetic is applied to proposal quorum and threshold calculations, vote-result stake aggregation, majority-hash stake totals, issuance sum checks, and V2 weighted merit calculations.
  • A zero total-stake majority hash case is now rejected before division.

DAO Results And Tests

  • DAO result display calculations now use the result-phase height.
  • The cycle accepted-vote count now uses accepted votes instead of active votes.
  • Regression tests cover merit validation, activation boundaries, DAO arithmetic, proposal vote results, vote-result consensus, vote-result service aggregation, and legacy versus V2 weighted merit.

See full release notes at: https://github.com/bisq-network/bisq/tree/release/v1.10.2/release-notes/1.10.2

Installation

macOS

Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:

Grant permissions by:

  • run sudo xattr -rd com.apple.quarantine /Applications/Bisq.app in a terminal (type Terminal in the Apple search box)
  • open Bisq again

More details can be found here.

Windows

For similar reasons you will get that warning at Windows: Windows protected your PC

  • Click the More info button when prompted
  • Click the Run anyway button when prompted

More details can be found here.

Verify download

See the verification and installation instructions in the Bisq Wiki.

v1.10.1

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 29 May 01:01
5d93ef9

This release addresses concerns about the overly restrictive trade amount limits introduced in the previous release and fixes a bug affecting BSQ swap trades.

Release notes

Trading And Wallet Safety

  • Maximum trade limits were increased to 0.250 BTC.
  • The risk-based reduction factors for the 4 risk classes were changed from 1, 2, 4, 8 to 1, 2, 3, 4. This results in trade limits of up to 0.250 BTC for Altcoins and up to 0.0625 BTC for higher-risk fiat payment methods such as SEPA or Zelle.
  • Fixed a bug in BSQ swap fee validation and added additional validation checks.
  • Trade statistics validation was adjusted for the reduced trade limits introduced in the previous release.

UX And Settings

  • Updated the user agreement.
  • Trade rules are now shown when users create or take an offer for the first time.
  • Trade rules and the user agreement are now available from Settings → About.
  • The cold-storage reminder threshold is now configurable in preferences.

Release Process And CI

  • Debian package dependency generation now relaxes t64 dependencies while preserving the original constraint or qualifier on the non-t64 alternative.

See full release notes at: https://github.com/bisq-network/bisq/tree/release/v1.10.1/release-notes/1.10.1

Installation

macOS

Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:

Grant permissions by:

  • run sudo xattr -rd com.apple.quarantine /Applications/Bisq.app in a terminal (type Terminal in the Apple search box)
  • open Bisq again

More details can be found here.

Windows

For similar reasons you will get that warning at Windows: Windows protected your PC

  • Click the More info button when prompted
  • Click the Run anyway button when prompted

More details can be found here.

Verify download

See the verification and installation instructions in the Bisq Wiki.

v1.10.0

Choose a tag to compare

@HenrikJannsen HenrikJannsen released this 16 May 01:33
a33ece9

Bisq 1.10.0 follows the recent security incident with a focused hardening release that improves trade protocol security, network message validation, release verification, and hardening against supply chain attacks.

A detailed post-mortem covering the incident, investigation, impact assessment, and the security improvements introduced with this release will be published in the coming days on the Bisq webpage.

Note: As this release adds support for both Intel and Apple Silicon macOS binaries, the in-app download for macOS binaries will not work for this release. Please download, install, and verify the macOS binaries manually.

Release notes

Security Improvements

  • Hardened validation of trade protocol messages, deposit transactions, payout transactions, trade contract data, and peer-provided wallet data.
  • Improved protection against supply chain attacks by adding PGP signature verification to dependency resolution.
  • Updated Java, JavaFX, Tor, bitcoinj, and other dependencies to their latest stable versions.
  • Improved the build process with additional verification of the build toolchain.
  • Added Docker-based DAO and end-to-end trade tests to GitHub Actions. This work will continue over the coming weeks.

Security Improvements Affecting the Trading Experience

  • The maximum trade amount is now limited to 0.125 BTC.
  • Offers and trades are now restricted to a maximum price deviation of 25%.
  • Disabled XMR auto-confirmation. No issues have been identified, but a more in-depth security audit is planned for this area.
  • Removed the webcam library used for QR code scanning to reduce security risks. A more secure replacement will be introduced in the next release.
  • Removed dispute chat attachments and dispute log file transfers for security reasons.
  • Added a popup reminder advising users not to use the Bisq wallet as a long-term storage wallet when holding higher balances.

UX

  • Improved performance by updating JavaFX and Java versions.

Network And Runtime

  • The DAO full-node bitcoind RPC layer was migrated for Bitcoin Core 29.2 support, with updated bitcoind targets and reorg-test coverage.
  • Bundled DAO and network resource snapshots were refreshed for the release.

Deployment

  • macOS releases now support both Apple Silicon and Intel-based Macs.
  • The reproducible build system is now partially in place, though not yet applied to this release. The next release will fully benefit from it.

Installation

macOS

Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:

Grant permissions by:

  • run sudo xattr -rd com.apple.quarantine /Applications/Bisq.app in a terminal (type Terminal in the Apple search box)
  • open Bisq again

More details can be found here.

Windows

For similar reasons you will get that warning at Windows: Windows protected your PC

  • Click the More info button when prompted
  • Click the Run anyway button when prompted

More details can be found here.

Verify download

See the verification and installation instructions in the Bisq Wiki.

Context to the binary signing process used for that release:

Alejandro García (key ID E222AA02) built all binaries except the new aarch64 macOS target, as he does not yet have a VM configured for it. Therefore, Henrik Jannsen (key ID 387C8307) provided the aarch64 macOS binary and signed the binaries he received from Alejandro.

Our in-app verification tool does not currently support mixed keys or signatures. It reads the key ID specified in signingkey.asc and applies it uniformly to all binaries. For this reason, Henrik re-signed all binaries using his own key so that the verification process remains consistent and compatible with the current implementation.

Please note that both Alejandro García and Henrik Jannsen are official release managers for Bisq 1 and Bisq 2. Their public keys have been included in the source code for a long time and are distributed with the application to enable independent key verification and cross-checking.

The partial_signatures_by_E222AA02.zip contains the original signatures provided by Alejandro. User can use those to verify using key E222AA02.

Relevant references:

  • github.com/bisq-network/bisq/tree/master/desktop/src/main/resources/keys
  • https://bisq.network/pubkey/E222AA02.asc
  • https://bisq.network/pubkey/387C8307.asc

The release process will be further improved in the next version through the introduction of reproducible builds.

v1.9.22

Choose a tag to compare

@HenrikJannsen HenrikJannsen released this 23 Dec 15:02
cf887dd

This is a hotfix release that applies the upstream BitcoinJ fix for the chainwork bug. The bug caused Bisq to stall at block height 928,895 because the field used to store the accumulated proof of work was too small. Henrik Jannsen, who is the release manager for Bisq 2, will now also be added as a release manager for Bisq 1.

If you experience any wallet-related issues, you may perform an SPV resync, although this should not be necessary.

Installation

macOS

Bisq does not use Apple's notarization process (see why).
For that reason you will see that (misleading) alert:

Grant permissions by:

  • run sudo xattr -rd com.apple.quarantine /Applications/Bisq.app in a terminal (type Terminal in the Apple search box)
  • open Bisq again

More details can be found here.

Windows

For similar reasons you will get that warning at Windows: Windows protected your PC

  • Click the More info button when prompted
  • Click the Run anyway button when prompted

More details can be found here.

Verify download

See the verification and installation instructions in the Bisq Wiki.

v1.9.21

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 26 Jun 19:46
v1.9.21
f50c5a4

A newer version is already available! Please don’t use this version anymore.

Release notes

Note: v1.9.21 is a hotfix for pre-release v1.9.20.

Improvements

  • Add 3 new bitcoin nodes
  • Updated dao datastores to speedup and improve resyncs
  • The burning man accounting sync got faster because we sort the blocks linearly. Before each time a block was added Bisq had to scan the list of blocks for duplicated and the last block.
  • Show a warning when a user tries to burn BSQ with a pre-image that contains leading or trailing spaces.
  • The backup zip file compession got faster and more reliable.

Bug fixes

  • Trading
    • An edge-case lead to failed trades where both traders couldn't agree on the correct burning man selection height. Now it works as it should.
    • Enforce the version check when an offer gets taken. Before we checked it at every step and users on older version couldn't mark a payment as sent or confirm it.
  • Add --useFullModeDaoMonitor to seednode setups. Without this option full nodes won't compute all dao hashes themselves.
  • The mediaton payout screen reflects the trade limit current now.
  • XMR subaddress
    • The XMR subaddress popup was shown to every user when they navigated to the payment account section. Now, we only show the popup when the user creates an XMR account or they have an existing non-subaddress account.
    • Fixed broken link to XMR subaddress documentation page
  • API
    • The PaymentAccountForm excludes the extraData field in PaymentAccounts now. Before this caused issues creating payment accounts.
    • We fixed a bug where the edit offer parser used the fixed price when a trigger price was used.

See all changes at https://github.com/bisq-network/bisq/milestone/88?closed=1 .

To verify this release please have a look at our wiki: https://bisq.wiki/Downloading_and_installing#Verify_installer_file

API

Starting with v1.9.0 you can use pre-built versions of the Bisq cli (bisq-cli-v1.9.21.zip) and Bisq daemon (bisq-daemon-v1.9.21.zip) to use Bisq without touching the user interface.

Just download the archives and extract them locally. You have to run the daemon to access the local Bisq daemon API endpoints.

To run daemon.jar on Mainnet:

$ java -jar daemon.jar --apiPassword=becareful

If you just want to control your headless daemon within your terminal you have to run the Bisq cli as well.

Again just download the bisq-cli archive and extract it locally.

To call getversion from cli.jar

$ java -jar cli.jar --password=becareful getversion

You can use the Bisq API to access local Bisq daemon API endpoints, which provide a subset of the Bisq Desktop application's feature set: check balances, transfer BTC and BSQ, create payment accounts, view offers, create and take offers, and execute trades.

The Bisq API is based on the gRPC framework, and any supported gRPC language binding can be used to call Bisq API endpoints.

You'll find in-depth documentation and examples under following link: https://bisq-network.github.io/slate/#introduction

Bisq gRPC API reference documentation example source code is hosted on GitHub at https://github.com/bisq-network/bisq-api-reference. Java and Python developers interested in bot development may find this Intellij project useful for running the existing examples, and writing their own bots.

For additional developer support please join Development - Bisq v1 on Matrix.

Known issues with installation

macOS:

We removed notarization from our build pipeline because of of the risk of Apple certification revocation (see #6341). Unfortunately this will require extra steps when installing Bisq on macOS.

Please follow the guide at https://support.apple.com/en-us/HT202491 in the section If you want to open an app that hasn’t been notarized or is from an unidentified developer

If you are running already macOS Ventura (13.0+) you need to do following to be able to start Bisq:

enter following command in Apple Terminal sudo xattr -rd com.apple.quarantine /Applications/Bisq.app
hit enter and you will be prompted to enter your password to be able to execute the command as super user
After running this successfully you should be able to start Bisq as always.

Windows:

We removed the developer code signing because of the same reason as with Apple.
For Windows you just have to ignore the warning after you have verified the installation file yourself and proceed with the installation.

There is a known issue with Anti Virus software. We got several reports from users running into different problems. Either the AV software blocks Bisq or Tor, delete files in the data directory [2] or app directory [1]) or cause such a long delay at startup that Tor gets terminated and a file remains locked which can cause that Bisq cannot be started afterwards. To resolve that you need to restart Windows then the lock get released. We are working on solutions to fix those issues.

If you use Crypto currencies on your Windows system be aware that Windows is much more vulnerable to malware than Linux or OSX. Consider to use a dedicated non-Windows system when dealing with cryptocurrencies.

[1] Application directory (contains application installation files):
C:\Users<username>\AppData\Local\Bisq

[2] Data directory (contains all Bisq data including wallet):
C:\Users<username>\AppData\Roaming\Bisq\btc_mainnet\tor (you can delete everything except the hiddenservice directory)

Linux:

Hint for Debian users:
If you have problems starting Bisq on Debian use: /opt/bisq/bin/Bisq

If your Linux distro does not support .deb files please follow this instruction:

cd ~/Downloads  
mkdir tmp  
cd tmp   
ar x ../Bisq-64bit-1.9.21.deb  
sudo tar Jxvf data.tar.xz  
sudo cp -rp opt/Bisq /opt/

That instruction is not tested on many different distros. If you encounter problems please report it in a Github issue so we can improve it.

Credits

Thanks to everyone who directly contributed to this release:

As well as to everyone that helped with translations on Transifex.

v1.9.20

v1.9.20 Pre-release
Pre-release

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 25 Jun 00:03
v1.9.20
ca404d6

A newer version is already available! Please don’t use this version anymore.

Release notes

Improvements

  • Add 3 new bitcoin nodes
  • Updated dao datastores to speedup and improve resyncs
  • The burning man accounting sync got faster because we sort the blocks linearly. Before each time a block was added Bisq had to scan the list of blocks for duplicated and the last block.
  • Show a warning when a user tries to burn BSQ with a pre-image that contains leading or trailing spaces.
  • The backup zip file compession got faster and more reliable.

Bug fixes

  • Trading
    • An edge-case lead to failed trades where both traders couldn't agree on the correct burning man selection height. Now it works as it should.
    • Enforce the version check when an offer gets taken. Before we checked it at every step and users on older version couldn't mark a payment as sent or confirm it.
  • Add --useFullModeDaoMonitor to seednode setups. Without this option full nodes won't compute all dao hashes themselves.
  • The mediaton payout screen reflects the trade limit current now.
  • XMR subaddress
    • The XMR subaddress popup was shown to every user when they navigated to the payment account section. Now, we only show the popup when the user creates an XMR account or they have an existing non-subaddress account.
    • Fixed broken link to XMR subaddress documentation page
  • API
    • The PaymentAccountForm excludes the extraData field in PaymentAccounts now. Before this caused issues creating payment accounts.
    • We fixed a bug where the edit offer parser used the fixed price when a trigger price was used.

See all changes at https://github.com/bisq-network/bisq/milestone/88?closed=1 .

To verify this release please have a look at our wiki: https://bisq.wiki/Downloading_and_installing#Verify_installer_file

API

Starting with v1.9.0 you can use pre-built versions of the Bisq cli (bisq-cli-v1.9.20.zip) and Bisq daemon (bisq-daemon-v1.9.20.zip) to use Bisq without touching the user interface.

Just download the archives and extract them locally. You have to run the daemon to access the local Bisq daemon API endpoints.

To run daemon.jar on Mainnet:

$ java -jar daemon.jar --apiPassword=becareful

If you just want to control your headless daemon within your terminal you have to run the Bisq cli as well.

Again just download the bisq-cli archive and extract it locally.

To call getversion from cli.jar

$ java -jar cli.jar --password=becareful getversion

You can use the Bisq API to access local Bisq daemon API endpoints, which provide a subset of the Bisq Desktop application's feature set: check balances, transfer BTC and BSQ, create payment accounts, view offers, create and take offers, and execute trades.

The Bisq API is based on the gRPC framework, and any supported gRPC language binding can be used to call Bisq API endpoints.

You'll find in-depth documentation and examples under following link: https://bisq-network.github.io/slate/#introduction

Bisq gRPC API reference documentation example source code is hosted on GitHub at https://github.com/bisq-network/bisq-api-reference. Java and Python developers interested in bot development may find this Intellij project useful for running the existing examples, and writing their own bots.

For additional developer support please join Development - Bisq v1 on Matrix.

Known issues with installation

macOS:

We removed notarization from our build pipeline because of of the risk of Apple certification revocation (see #6341). Unfortunately this will require extra steps when installing Bisq on macOS.

Please follow the guide at https://support.apple.com/en-us/HT202491 in the section If you want to open an app that hasn’t been notarized or is from an unidentified developer

If you are running already macOS Ventura (13.0+) you need to do following to be able to start Bisq:

enter following command in Apple Terminal sudo xattr -rd com.apple.quarantine /Applications/Bisq.app
hit enter and you will be prompted to enter your password to be able to execute the command as super user
After running this successfully you should be able to start Bisq as always.

Windows:

We removed the developer code signing because of the same reason as with Apple.
For Windows you just have to ignore the warning after you have verified the installation file yourself and proceed with the installation.

There is a known issue with Anti Virus software. We got several reports from users running into different problems. Either the AV software blocks Bisq or Tor, delete files in the data directory [2] or app directory [1]) or cause such a long delay at startup that Tor gets terminated and a file remains locked which can cause that Bisq cannot be started afterwards. To resolve that you need to restart Windows then the lock get released. We are working on solutions to fix those issues.

If you use Crypto currencies on your Windows system be aware that Windows is much more vulnerable to malware than Linux or OSX. Consider to use a dedicated non-Windows system when dealing with cryptocurrencies.

[1] Application directory (contains application installation files):
C:\Users<username>\AppData\Local\Bisq

[2] Data directory (contains all Bisq data including wallet):
C:\Users<username>\AppData\Roaming\Bisq\btc_mainnet\tor (you can delete everything except the hiddenservice directory)

Linux:

Hint for Debian users:
If you have problems starting Bisq on Debian use: /opt/bisq/bin/Bisq

If your Linux distro does not support .deb files please follow this instruction:

cd ~/Downloads  
mkdir tmp  
cd tmp   
ar x ../Bisq-64bit-1.9.20.deb  
sudo tar Jxvf data.tar.xz  
sudo cp -rp opt/Bisq /opt/

That instruction is not tested on many different distros. If you encounter problems please report it in a Github issue so we can improve it.

Credits

Thanks to everyone who directly contributed to this release:

As well as to everyone that helped with translations on Transifex.

v1.9.19

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 03 Feb 23:58
v1.9.19
77d2179

A newer version is already available! Please don’t use this version anymore.

Release notes

Improvements

Bug fixes

See https://github.com/bisq-network/bisq/milestone/86?closed=1 for more details.

To verify this release please have a look at our wiki: https://bisq.wiki/Downloading_and_installing#Verify_installer_file

API

Starting with v1.9.0 you can use pre-built versions of the Bisq cli (bisq-cli-v1.9.19.zip) and Bisq daemon (bisq-daemon-v1.9.19.zip) to use Bisq without touching the user interface.

Just download the archives and extract them locally. You have to run the daemon to access the local Bisq daemon API endpoints.

To run daemon.jar on Mainnet:

$ java -jar daemon.jar --apiPassword=becareful

If you just want to control your headless daemon within your terminal you have to run the Bisq cli as well.

Again just download the bisq-cli archive and extract it locally.

To call getversion from cli.jar

$ java -jar cli.jar --password=becareful getversion

You can use the Bisq API to access local Bisq daemon API endpoints, which provide a subset of the Bisq Desktop application's feature set: check balances, transfer BTC and BSQ, create payment accounts, view offers, create and take offers, and execute trades.

The Bisq API is based on the gRPC framework, and any supported gRPC language binding can be used to call Bisq API endpoints.

You'll find in-depth documentation and examples under following link: https://bisq-network.github.io/slate/#introduction

Bisq gRPC API reference documentation example source code is hosted on GitHub at https://github.com/bisq-network/bisq-api-reference. Java and Python developers interested in bot development may find this Intellij project useful for running the existing examples, and writing their own bots.

For additional developer support please join Development - Bisq v1 on Matrix.

Known issues with installation

macOS:

We removed notarization from our build pipeline because of of the risk of Apple certification revocation (see #6341). Unfortunately this will require extra steps when installing Bisq on macOS.

Please follow the guide at https://support.apple.com/en-us/HT202491 in the section If you want to open an app that hasn’t been notarized or is from an unidentified developer

If you are running already macOS Ventura (13.0+) you need to do following to be able to start Bisq:

enter following command in Apple Terminal sudo xattr -rd com.apple.quarantine /Applications/Bisq.app
hit enter and you will be prompted to enter your password to be able to execute the command as super user
After running this successfully you should be able to start Bisq as always.

Windows:

We removed the developer code signing because of the same reason as with Apple.
For Windows you just have to ignore the warning after you have verified the installation file yourself and proceed with the installation.

There is a known issue with Anti Virus software. We got several reports from users running into different problems. Either the AV software blocks Bisq or Tor, delete files in the data directory [2] or app directory [1]) or cause such a long delay at startup that Tor gets terminated and a file remains locked which can cause that Bisq cannot be started afterwards. To resolve that you need to restart Windows then the lock get released. We are working on solutions to fix those issues.

If you use Crypto currencies on your Windows system be aware that Windows is much more vulnerable to malware than Linux or OSX. Consider to use a dedicated non-Windows system when dealing with cryptocurrencies.

[1] Application directory (contains application installation files):
C:\Users<username>\AppData\Local\Bisq

[2] Data directory (contains all Bisq data including wallet):
C:\Users<username>\AppData\Roaming\Bisq\btc_mainnet\tor (you can delete everything except the hiddenservice directory)

Linux:

Hint for Debian users:
If you have problems starting Bisq on Debian use: /opt/bisq/bin/Bisq

If your Linux distro does not support .deb files please follow this instruction:

cd ~/Downloads  
mkdir tmp  
cd tmp   
ar x ../Bisq-64bit-1.9.19.deb  
sudo tar Jxvf data.tar.xz  
sudo cp -rp opt/Bisq /opt/

That instruction is not tested on many different distros. If you encounter problems please report it in a Github issue so we can improve it.

Credits

Thanks to everyone who directly contributed to this release:

A special thanks to our first time contributor:

As well as to everyone that helped with translations on Transifex.

v1.9.18

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 22 Nov 21:11
v1.9.18
b3f44d2

A newer version is already available! Please don’t use this version anymore.

Release notes

Some users aren't getting enough connections to the bitcoin network and can't therefore broadcast transactions. This hot-fix release resolves these connectivity issues and improves the reliability of the network.

See https://github.com/bisq-network/bisq/milestone/87?closed=1 for more details.

Verification

For a detailed description on how to verify your Bisq installer please have a look at our wiki: https://bisq.wiki/Downloading_and_installing#Verify_installer_file

Url of the signing key (Alejandro García): https://bisq.network/pubkey/E222AA02.asc
Full fingerprint: B493 3191 06CC 3D1F 252E 19CB F806 F422 E222 AA02

Import the key:
curl https://bisq.network/pubkey/E222AA02.asc | gpg --import
GPG prints a confusion warning: "This key is not certified with a trusted signature!" - See https://serverfault.com/questions/569911/how-to-verify-an-imported-gpg-key for background information what it means.

How to verify signatures?
gpg --digest-algo SHA256 --verify BINARY{.asc*,}
Replace BINARY with the file you downloaded (e.g. Bisq-1.9.16.dmg)

Verify jar file inside binary:
You can verify on OSX the jar file with:
shasum -a256 [PATH TO BISQ APP]/Bisq.app/Contents/app/desktop-1.9.16-all.jar
The output need to match the value from the Bisq-1.9.16.jar.txt file.

There are three hashes within the Bisq-1.9.16.jar.txt file (macOS, Windows, Linux).
If you want to reproduce and verify the hash of the jar file locally, you need to do so on Windows or Linux using Java 15.0.9 and the v1.9.16 release tag. Because of the signing and notarization process that requires the developer certificate used for the build on macOS it is not possible to create the same jar on macOS.

API

Starting with v1.9.0 you can use pre-built versions of the Bisq cli (bisq-cli-v1.9.16.zip) and Bisq daemon (bisq-daemon-v1.9.16.zip) to use Bisq without touching the user interface.

Just download the archives and extract them locally. You have to run the daemon to access the local Bisq daemon API endpoints.

To run daemon.jar on Mainnet:

$ java -jar daemon.jar --apiPassword=becareful

If you just want to control your headless daemon within your terminal you have to run the Bisq cli as well.

Again just download the bisq-cli archive and extract it locally.

To call getversion from cli.jar

$ java -jar cli.jar --password=becareful getversion

You can use the Bisq API to access local Bisq daemon API endpoints, which provide a subset of the Bisq Desktop application's feature set: check balances, transfer BTC and BSQ, create payment accounts, view offers, create and take offers, and execute trades.

The Bisq API is based on the gRPC framework, and any supported gRPC language binding can be used to call Bisq API endpoints.

You'll find in-depth documentation and examples under following link: https://bisq-network.github.io/slate/#introduction

Bisq gRPC API reference documentation example source code is hosted on GitHub at https://github.com/bisq-network/bisq-api-reference. Java and Python developers interested in bot development may find this Intellij project useful for running the existing examples, and writing their own bots.

For additional developer support please join Development - Bisq v1 on Matrix.

Known issues with installation

macOS:

We removed notarization from our build pipeline because of of the risk of Apple certification revocation (see #6341). Unfortunately this will require extra steps when installing Bisq on macOS.

Please follow the guide at https://support.apple.com/en-us/HT202491 in the section If you want to open an app that hasn’t been notarized or is from an unidentified developer

If you are running already macOS Ventura (13.0+) you need to do following to be able to start Bisq:

enter following command in Apple Terminal sudo xattr -rd com.apple.quarantine /Applications/Bisq.app
hit enter and you will be prompted to enter your password to be able to execute the command as super user
After running this successfully you should be able to start Bisq as always.

Windows:

We removed the developer code signing because of the same reason as with Apple.
For Windows you just have to ignore the warning after you have verified the installation file yourself and proceed with the installation.

There is a known issue with Anti Virus software. We got several reports from users running into different problems. Either the AV software blocks Bisq or Tor, delete files in the data directory [2] or app directory [1]) or cause such a long delay at startup that Tor gets terminated and a file remains locked which can cause that Bisq cannot be started afterwards. To resolve that you need to restart Windows then the lock get released. We are working on solutions to fix those issues.

If you use Crypto currencies on your Windows system be aware that Windows is much more vulnerable to malware than Linux or OSX. Consider to use a dedicated non-Windows system when dealing with cryptocurrencies.

[1] Application directory (contains application installation files):
C:\Users<username>\AppData\Local\Bisq

[2] Data directory (contains all Bisq data including wallet):
C:\Users<username>\AppData\Roaming\Bisq\btc_mainnet\tor (you can delete everything except the hiddenservice directory)

Linux:

Hint for Debian users:
If you have problems starting Bisq on Debian use: /opt/bisq/bin/Bisq

If your Linux distro does not support .deb files please follow this instruction:

cd ~/Downloads  
mkdir tmp  
cd tmp   
ar x ../Bisq-64bit-1.9.16.deb  
sudo tar Jxvf data.tar.xz  
sudo cp -rp opt/Bisq /opt/

That instruction is not tested on many different distros. If you encounter problems please report it in a Github issue so we can improve it.

Credits

Thanks to everyone who directly contributed to this release:

A special thanks to our first time contributor:

As well as to everyone that helped with translations on Transifex.

v1.9.17

Choose a tag to compare

@alejandrogarcia83 alejandrogarcia83 released this 24 Jun 02:29
v1.9.17
5a2bc54

A newer version is already available! Please don’t use this version anymore.

Release notes

Major Changes:

  • Improve network resilience and stability
  • Add getdaostatus API, expose failed trades in API, and support XMR auto conf in API
  • Buyers can pay using SEPA QR codes
  • Restore QR code scanner for mobile notification app pairing

See https://github.com/bisq-network/bisq/milestone/84?closed=1 for more details.

Improvements

Bug fixes

Verification

For a detailed description on how to verify your Bisq installer please have a look at our wiki: https://bisq.wiki/Downloading_and_installing#Verify_installer_file

Url of the signing key (Alejandro García): https://bisq.network/pubkey/E222AA02.asc
Full fingerprint: B493 3191 06CC 3D1F 252E 19CB F806 F422 E222 AA02

Import the key:
curl https://bisq.network/pubkey/E222AA02.asc | gpg --import
GPG prints a confusion warning: "This key is not certified with a trusted signature!" - See https://serverfault.com/questions/569911/how-to-verify-an-imported-gpg-key for background information what it means.

How to verify signatures?
gpg --digest-algo SHA256 --verify BINARY{.asc*,}
Replace BINARY with the file you downloaded (e.g. Bisq-1.9.16.dmg)

Verify jar file inside binary:
You can verify on OSX the jar file with:
shasum -a256 [PATH TO BISQ APP]/Bisq.app/Contents/app/desktop-1.9.16-all.jar
The output need to match the value from the Bisq-1.9.16.jar.txt file.

There are three hashes within the Bisq-1.9.16.jar.txt file (macOS, Windows, Linux).
If you want to reproduce and verify the hash of the jar file locally, you need to do so on Windows or Linux using Java 15.0.9 and the v1.9.16 release tag. Because of the signing and notarization process that requires the developer certificate used for the build on macOS it is not possible to create the same jar on macOS.

API

Starting with v1.9.0 you can use pre-built versions of the Bisq cli (bisq-cli-v1.9.16.zip) and Bisq daemon (bisq-daemon-v1.9.16.zip) to use Bisq without touching the user interface.

Just download the archives and extract them locally. You have to run the daemon to access the local Bisq daemon API endpoints.

To run daemon.jar on Mainnet:

$ java -jar daemon.jar --apiPassword=becareful

If you just want to control your headless daemon within your terminal you have to run the Bisq cli as well.

Again just download the bisq-cli archive and extract it locally.

To call getversion from cli.jar

$ java -jar cli.jar --password=becareful getversion

You can use the Bisq API to access local Bisq daemon API endpoints, which provide a subset of the Bisq Desktop application's feature set: check balances, transfer BTC and BSQ, create payment accounts, view offers, create and take offers, and execute trades.

The Bisq API is based on the gRPC framework, and any supported gRPC language binding can be used to call Bisq API endpoints.

You'll find in-depth documentation and examples under following link: https://bisq-network.github.io/slate/#introduction

Bisq gRPC API reference documentation example source code is hosted on GitHub at https://github.com/bisq-network/bisq-api-reference. Java and Python developers interested in bot development may find this Intellij project useful for running the existing examples, and writing their own bots.

For additional developer support please join Development - Bisq v1 on Matrix.

Known issues with installation

macOS:

We removed notarization from our build pipeline because of of the risk of Apple certification revocation (see #6341). Unfortunately this will require extra steps when installing Bisq on macOS.

Please follow the guide at https://support.apple.com/en-us/HT202491 in the section If you want to open an app that hasn’t been notarized or is from an unidentified developer

If you are running already macOS Ventura (13.0+) you need to do following to be able to start Bisq:

enter following command in Apple Terminal sudo xattr -rd com.apple.quarantine /Applications/Bisq.app
hit enter and you will be prompted to enter your password to be able to execute the command as super user
After running this successfully you should be able to start Bisq as always.

Windows:

We removed the developer code signing because of the same reason as with Apple.
For Windows you just have to ignore the warning after you have verified the installation file yourself and proceed with the installation.

There is a known issue with Anti Virus software. We got several reports from users running into different problems. Either the AV software blocks Bisq or Tor, delete files in the data directory [2] or app directory [1]) or cause such a long delay at startup that Tor gets terminated and a file remains locked which can cause that Bisq cannot be started afterwards. To resolve that you need to restart Windows then the lock get released. We are working on solutions to fix those issues.

If you use Crypto currencies on your Windows system be aware that Windows is much more vulnerable to malware than Linux or OSX. Consider to use a dedicated non-Windows system when dealing with cryptocurrencies.

[1] Application directory (contains application installation files):
C:\Users<username>\AppData\Local\Bisq

[2] Data directory (contains all Bisq data including wallet):
C:\Users<username>\AppData\Roaming\Bisq\btc_mainnet\tor (you can delete everything except the hiddenservice directory)

Linux:

Hint for Debian users:
If you have problems starting Bisq on Debian use: /opt/bisq/bin/Bisq

If your Linux distro does not support .deb files please follow this instruction:

cd ~/Downloads  
mkdir tmp  
cd tmp   
ar x ../Bisq-64bit-1.9.16.deb  
sudo tar Jxvf data.tar.xz  
sudo cp -rp opt/Bisq /opt/

That instruction is not tested on many different distros. If you encounter problems please report it in a Github issue so we can improve it.

Credits

Thanks to everyone who directly contributed to this release:

A special thanks to our first time contributor:

As well as to everyone that helped with translations on Transifex.