Bisq changed who could move escrowed funds

On October 29, 2019, Bisq released version 1.2.0 with a redesigned protocol for peer-to-peer bitcoin trades. The project’s dated announcement and signed GitHub release record both identify the central change: deposit funds moved from a 2-of-3 multisignature escrow, in which an arbitrator held the third key, to a 2-of-2 escrow controlled only by the two traders.

That was more than a software housekeeping change. Bisq was trying to reduce the authority concentrated in its dispute resolvers while preserving a path for handling trades that stalled or became contested. Under the new design, traders also signed a time-locked transaction directing the escrowed funds to an address selected through the Bisq DAO. Either trader could publish it after 10 days for an altcoin trade or 20 days for a fiat trade.

The release described a three-stage dispute process. Traders would first use private, end-to-end encrypted chat. If they could not agree, a bonded mediator could review the case and recommend a payout, but could not impose it. Arbitration came only after the time-locked transaction was published; an arbitrator could then reimburse a trader personally and seek repayment from the Bisq DAO. The project said arbitration was intended to become exceptional rather than routine.

Why the escrow change mattered

The verified fact is narrow: the third key was removed from version 1.2.0’s escrow design. Bisq’s broader claims—that the arrangement reduced trust, improved privacy and scaled dispute resolution—were the project’s contemporaneous assessment, not independently measured outcomes on October 29, 2019.

Even with that qualification, the architecture mattered. A peer-to-peer exchange could not fully support a decentralization claim if a designated third party retained signing power over every trade deposit. Removing that key reduced one form of custody-like control and narrowed the damage a compromised or malicious arbitrator could directly cause. It also shifted risk elsewhere: deadlocked trades now depended on a time lock, DAO-defined address and reimbursement process rather than a third signature.

Account signing answered a separate fraud problem

Version 1.2.0 also introduced account signing for payment methods exposed to chargeback risk. Bisq said stolen-bank-account scams earlier in 2019 had prompted a temporary 0.01 BTC buying limit for affected fiat accounts. Under the initial signing model, a user with an unsigned account had to buy bitcoin from a user with a signed account. If no chargeback or other problem emerged during the following 30 days, the buyer’s account could be signed and the 0.01 BTC restriction lifted.

The rule did not apply to selling limits in the same way. Bisq also listed exceptions for payment methods without chargeback risk and for markets outside USD, EUR, CAD, GBP, AUD and BRL. Account signing was therefore a network-specific reputation control, not identity verification and not proof that a payment account was safe.

What users knew on October 29

The migration itself carried operational risk. Bisq instructed existing users to finish trades and disputes and disable open offers before updating. It warned that unfinished cases could require manual arbitrator payouts and that downgrading to version 1.1.7 would not repair the situation. Those cautions limit any claim that the release instantly made trading safer or easier.

No verified price or volume series establishes a market reaction to version 1.2.0, so this reconstruction makes none. Its significance was institutional and technical: Bisq redistributed control inside a live bitcoin-fiat trading system while trying to contain chargeback fraud without conventional account screening.

Later context

On April 8, 2020, Bisq disclosed that attackers had exploited a flaw related to the time-locked payout address, affecting seven victims and approximately 3 BTC and 4,000 XMR. The project said version 1.3.0 corrected the flaw. That later event does not change what was announced on October 29, 2019, but it shows that removing a trusted key did not eliminate protocol risk; it changed the system’s risk surface.

Primary sourceBisq v1.2 launch announcement

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.