The 256 Foundation said its 256 Red Team security review of ASIC miner firmware documented 41 issue reports across stock Bitmain software and widely used third-party alternatives, with the main hidden risks concentrated in third-party “optimization” firmware. Using reverse engineering, real-time traffic capture and share-level reconciliation, researchers said they found no evidence in Bitmain’s original firmware of hashrate skimming, a remote kill switch or covert beacons. The issues identified included unauthenticated factory APIs, paths to root access, default credentials, embedded vendor SSH keys and update tools that cannot verify what is being installed. The group said it sent three responsible disclosures to VNISH, Luxor and Braiins, gave them 30 days to respond, and plans follow-up audits of MicroBT, Canaan, Auradine, Bitdeer and ePIC.