Open-source project
bisq-network/bisq avatar
bisq-network/bisq

Bisq: a bitcoin exchange with no custodian in the middle

A decentralized bitcoin exchange network. Bisq is a safe, private and decentralized way to exchange bitcoin for national currencies and other digital assets.

5,138 stars1,305 forksJavaAGPL-3.0

At a glance

What is it?
Bisq is a decentralized bitcoin exchange network: peer-to-peer trading of bitcoin for national currencies, multi-signature escrow instead of a custodian, and human arbitration for disputes. It is written in Java, licensed AGPL-3.0, and has shipped three releases since 2026-08-23.
Who is it for?
Run Bisq if exchanging bitcoin for national currencies without a custodian or an identity file matches what you want, and you accept that disputes are settled by human arbitration rather than a support desk. Stay with a regulated exchange when account recovery and institutional recourse matter more than custody-free trading.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 3 days ago.
What is it written in?
Mainly Java, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Multi-signature escrow instead of a middleman

Bisq exchanges bitcoin for national currencies and other digital assets over peer-to-peer networking, with multi-signature escrow standing where an exchange's custody account would stand. No third party holds funds, which is what non-custodial means here in practice, and when two peers cannot settle a trade themselves, a human arbitration system resolves the dispute. That combination, escrow plus arbitration, is the mechanism the project leads with, and it is the honest summary of what decentralizing an exchange requires: you cannot delete the trust function, so you distribute it into script and people. The counter-model is the centralized exchange, which holds both the funds and an identity file, and offers recourse in exchange. Bisq is written in Java and licensed AGPL-3.0.

The README installs nothing, the website does

Opening the repository expecting an install command gets you a redirect instead. The README's get-started section points to step-by-step instructions at bisq.network/get-started, and the introduction lives at bisq.network/intro as documentation and a video. That split is deliberate: users download from the website, and the GitHub tree serves contributors, for whom CONTRIBUTING.md and the developer docs under docs/README.md are the entry points. Anyone needing to audit what they run can still clone and build the Java sources, but the repository documents no user-facing install command, and inventing one would misstate where the project wants binaries to come from.

make assembles a mini Bisq network

For development, the Makefile builds what it calls a localnet, a complete and self-contained mini Bisq network for development and end-to-end testing. Requirements are explicit: a Linux, macOS or similar system with standard tools, bitcoind and bitcoin-cli installed (brew install bitcoin on macOS), and JDK 21 to build and run Bisq binaries. The first step is one command:

bash
make

The first pass takes a few minutes, and it leaves two artifacts behind: a scripts directory with desktop, seednode and statsnode launchers, and a .localnet directory holding the data directories for the regtest Bitcoin and Bisq nodes.

alice, bob, a mediator and two seednodes

The localnet directory layout names the participants in a trade: subdirectories appear for alice, bob, mediator, seednode, seednode2 and bitcoind. Two traders, one mediator, two seed nodes and a regtest Bitcoin node, so the arbitration role from the README is not an abstraction, it is a process you start during testing. Deployment happens through Gradle targets, each a long-running process meant for its own terminal window:

bash
./gradlew :startFirstRegtestBitcoind
./gradlew :startSecondRegtestBitcoind
./gradlew :startRegtestFirstSeednode

Running against regtest rather than mainnet means the mini network can create and move coins without value, which is what makes end-to-end trade testing sane.

A Gradle tree with a daemon, a CLI, REST and gRPC

The repository is a multi-module Gradle build, and the module names sketch the system. desktop/ is the graphical client, daemon/ and cli/ give it a headless and a command-line life, and restapi/ plus proto-grpc/ and proto/ expose programmatic surfaces, all sitting on core/, common/, p2p/ and persistence/. The network itself is made of the seednode/, statsnode/ and btcnodemonitor/ modules, with bridge/ and inventory/ alongside. Testing infrastructure gets its own layers: apitest/, regtest/ and the Makefile localnet. Two modules say something about operational seriousness: reproducible-build/ for verifying that released binaries match the sources, and updater/ for shipping them. Release notes live in their own directory, and docker/ plus a root bitcoind helper round out the deployment story.

CLAUDE.md, AGENTS.md and a dual-architecture report

Less common files at the root deserve a mention. CLAUDE.md and AGENTS.md are instructions for AI coding assistants, so agent-assisted contribution is anticipated rather than accidental, and CODEOWNERS formalizes who reviews what. SECURITY.md gives security contact and process, standard for software that moves money. One file is unusual anywhere: macos-dual-architecture-support-report.md sits at the top level, a committed report on supporting both macOS architectures, evidence that platform support is tracked as a first-class concern rather than an issue-label afterthought. The .github directory and .editorconfig and .gitattributes keep the collaboration machinery conventional.

Three releases since late August, AGPL on top

Activity is current: v1.10.6 was tagged on 2026-08-23, v1.10.7 on 2026-08-25, v1.10.8 on 2026-09-16, and the last push came on 2026-09-27. Patch-level cadence on a live exchange network reads as maintenance under real traffic rather than feature churn, and release-notes/ exists so each step is documented. The licence is AGPL-3.0, strong copyleft: anyone offering the software as a network service owes users the corresponding source, a clause anyone embedding or modifying Bisq should read in the LICENSE file itself, since this is engineering commentary and not legal advice.

Editorial conclusion

Run Bisq if exchanging bitcoin for national currencies without a custodian or an identity file matches what you want, and you accept that disputes are settled by human arbitration rather than a support desk. Stay with a regulated exchange when account recovery and institutional recourse matter more than custody-free trading. Before trading, read the intro and get-started guides at bisq.network, and check the release you download against the project's reproducible build process.

Frequently asked questions

How does Bisq work?

Bisq uses peer-to-peer networking and multi-signature escrow so two parties can trade bitcoin for national currencies without a third party holding funds. It is non-custodial, and a human arbitration system resolves disputes.

Is the Bisq network safe?

The project describes Bisq as a safe, private and decentralized way to exchange bitcoin. Funds sit in multi-signature escrow rather than with a custodian, and disputes go to human arbitration; the README itself does not analyze risks.

Does Bisq require KYC?

The README does not mention any identity verification process. It presents Bisq as private and non-custodial, exchanging bitcoin for national currencies and other digital assets without a third party.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/bisq-network-bisq.svg)](https://hysenlabs.com/projects/bisq-network-bisq)