MMashDiv

Bicrypto 6.8.2

1 October 2026

This release has upgrade notes. Read them before updating — they describe behaviour changes that need your attention.

SECURITYPAYMENTSACCOUNTSLICENSINGWALLETSTRADINGADMINMOBILEUPDATES

Core v6.8.2

Release Date: October 1, 2026 Tags: SECURITY, PAYMENTS, ACCOUNTS, LICENSING, WALLETS, TRADING, ADMIN, MOBILE, UPDATES

Overview

A security and money release. Update promptly — but read Upgrade Notes before you do. It closes a crafted listing filter that could corrupt the backend until it restarted, a sign-up path that let a stranger keep the password of an account its real owner later verified, API keys that kept working after their owner was deleted, and payment-provider confirmations that could credit a fiat deposit in the wrong currency, to the wrong deposit, or after you had rejected it.

The database changes at first start, licence checks are stricter, and sign-ups from throwaway email domains are refused from the moment you update.

Running Ecosystem or P2P? Their releases published with this one change things the moment the new build starts — read Ecosystem v6.5.6 and P2P Trading v6.4.1 before you update.

Update Instructions

pnpm updator

This release changes the database. pnpm updator starts the backend once before seeding, and that start applies the changes listed in Upgrade Notes. Nothing is dropped or renamed, and there is no separate migration command. The backend changes arrive with the restart; the screens arrive with the frontend rebuild that pnpm updator runs.

Published with this release, each with its own notes: Ecosystem v6.5.6, P2P Trading v6.4.1, Monero (XMR) Blockchain v6.2.1, Solana Blockchain v6.1.5, Tron Blockchain v6.1.7, Forex Investment v6.2.3, NFT Marketplace v6.3.3, Staking v6.2.7, Copy Trading v6.2.7, Futures Trading v6.2.7, Algo Trading Bots v6.1.0, Hummingbot Connector v6.2.2, ICO/STO/IDO v6.3.1, E-commerce v6.2.3, Web3 Wallet Trading v6.0.5, AI Support Agent v6.0.9, Chart Engine v1.1.8 and the new Instant Convert v6.0.0. Ecosystem, P2P, Staking, Copy Trading, Forex, ICO, E-commerce and Algo Trading Bots need this release; update them in the same window.


Upgrade Notes

The database changes at first start

The backend's start-up schema sync applies all of this when pnpm updator starts it. Nothing is dropped, renamed or rewritten.

  • 11 new tables (convert_…) belonging to the Instant Convert add-on are created on every install. They stay empty unless that add-on is used.
  • 9 new nullable columns on user, gateway_merchant, gateway_webhook, ico_token_offering, staking_batches, binary_ai_engine_action and binary_ai_engine_position, which nothing reads yet; gateway_merchant.apiKey and secretKey now allow NULL.
  • New values are appended to transaction.type, transaction_archive.type (CONVERT), admin_profit.type (CONVERT, CONVERT_HEDGE) and pool_backing_custody_read.kind. The admin Profit and Transaction lists and the customer's history gain a matching "Convert" filter option that matches nothing without that add-on.
  • If .env sets DB_SYNC="none", the backend applies none of this, and ordinary reads of the user table fail on the missing column until you apply the changes yourself. Apply them before starting 6.8.2.

A licence may ask to be activated again

Licence verification is stricter: a licence must be valid on the server it runs on, not merely present. An install whose platform and add-ons were activated from its own admin panel on this server has nothing to do. It is most likely to bite an install moved to another server, or whose hostname or hardware changed, since a product was activated.

  • After updating, open each licensed add-on's admin screen once. If you are sent to "Activate Your License" (/admin/system/license), enter that product's purchase code and press Activate License.
  • Until then, customers using that add-on are told it "requires a valid license", and Wallet Connect sign-in is refused. Staking, the Web3 Wallet swap, blockchains and exchange providers check the same way.
  • System → Extensions can still show such an add-on as licensed. Trust the redirect, not that list.

Sign-ups from throwaway email domains are refused at once

"Block Disposable Email Addresses" is on even on an install that never saved it, so new accounts on 67 built-in disposable-mail domains are refused from the first start. Existing accounts keep signing in.

  • To allow them, switch it off under System → Settings → Security → Registration.

Fiat payments that now wait for you instead of being credited

Two failure paths used to guess, and now stop and leave the decision to you. Neither can be listed from a screen; look for the log lines below.

  • A fiat deposit you had rejected, refunded or frozen that a provider's webhook then reports as paid credits nothing. The deposit's detail page shows the reason in its metadata ("… reported this deposit as paid while it was …; nothing was credited. Refund the payment to the customer, or credit it by hand …"), and the log carries a [CRITICAL] line.
  • A Paytm refund on a deposit made before this update that could have been misread is not applied. It is flagged on the deposit and logged as [CRITICAL] refund on <order> NOT applied.; reverse it by hand after checking the customer's wallet history.
  • This release does not find or repair deposits credited under the previous behaviour.

Solana on devnet or testnet: repair existing addresses

Only for installs whose SOL_NETWORK is devnet or testnet. Addresses created before the update keep their wrong "mainnet" label, and the wallet page reports them as unable to receive deposits.

  • From the project root, run pnpm fix:sol-wallet-network to see what it would change, then pnpm fix:sol-wallet-network:apply. It refuses to run unless SOL_NETWORK is exactly mainnet, testnet or devnet, and writes a backup and an undo.sql into a fix-sol-wallet-network-<time> folder in backend/ before its first change. No restart is needed.

If sign-in, wallet statistics or user deletion started failing for no reason

  • These were the visible effects of the listing-filter issue: errors such as this._customSetters[key].call is not a function, Getter must be a function or Schema compilation failed: … must be object,boolean, appearing together in unrelated places.
  • Updating and restarting clears them. A restart alone clears them too, but without this release the same request can bring them back.

The mobile app shows Market News only once both halves are updated

  • The app's tile list is filtered by the module list this backend sends, so the Market News tile in mobile 5.3.9 appears only on a backend running this release or later. On an older backend 5.3.9 still reaches the news screen from the newspaper button on the Markets tab.

Added

Sign-up can refuse throwaway and listed email domains

Email verification does not stop an account farm that uses a temp-mail service: those services receive mail, so the accounts verify. One live install was farmed this way.

  • Added "Block Disposable Email Addresses" (on by default) and "Blocked Email Domains" (your own list, one domain per line, empty by default) under System → Settings → Security → Registration. A new account on one of 67 built-in disposable-mail domains, or on a domain you list, is refused by the email form and the Google button alike, subdomains included, with "Registrations from this email provider are not accepted. Please use a different email address." Existing accounts on those domains keep signing in.

Market news is its own module

  • Added a news module to the list the mobile app reads, core and unconditional: the news route is public, needs no add-on and answers on every install, so nothing gates it.

The Pro trade layout's Orders panel can be made taller

  • Added a separator above the Orders panel in the Pro trade layout. The panel was fixed at about two rows on a 1080p screen; it can now be dragged or resized from the keyboard, the height is remembered in the browser, and applying a layout preset resets it.

Maintenance commands

  • Added pnpm fix:sol-wallet-network and pnpm fix:sol-wallet-network:apply (from the project root), described under Upgrade Notes, and pnpm repair:p2p-price-wallet-type with its :apply form (from backend/, needs the backend source and development dependencies, optional; see P2P Trading v6.4.1). The plain form of each only reports; the :apply form writes.

Changed

Licence checks are stricter

  • Changed licence verification for the platform, add-ons, blockchains, exchange providers and Wallet Connect: a licence now has to be valid on the server it runs on, not merely present. See Upgrade Notes.

Payment providers

  • Changed the Paystack status check to verify the amount and currency Paystack reports before crediting, as the return-page confirmation already did.

Scheduled jobs

  • Changed the scheduler's job list to show four Instant Convert settlement jobs on every install. Without that add-on they do nothing when they run, and the start-up line saying they were kept because customers are owed money does not apply.

Pool backing

  • Changed the Pool backing page for small screens: below 1024 px settlements and obligations are cards with their actions visible; a settlement's actions sit in one Resolve menu; statuses, sides and directions read as words instead of internal codes; the breakdown behind a figure opens with a tap; a settlement's proof is listed as labelled facts with the raw record folded away; and recording an external movement offers the reconciled currencies to pick from.
  • Changed Pool backing times to UTC, labelled as such, instead of the browser's own time zone, and figures are grouped by thousands.

Licence attestations work in licences

  • Changed Licence attestations (the screen that decides which regulated features the mobile app shows per country) to one row per licence, with a switch for each feature it covers and a country picker instead of a typed code. Existing records are shown grouped into licences, and nothing has to be re-entered or is changed in the database. Withdrawing, restoring or deleting a row now applies to the whole licence; use Edit to switch one feature off.

Admin settings pages

  • Changed the admin settings pages: category headings no longer repeat "Settings", counts include only the settings shown, the category chips on phones and tablets no longer cut off the last categories, and long titles wrap beside their icon.
  • Changed documentation links on the update screen, in the installer's closing message and in .env.example to the current documentation instead of the retired V5 site.

The blog is called the blog

  • Changed the mobile module title for the blog from "News & analysis" to "Blog". The same title on the app's home tile had it opening the blog under a label promising the news feed.

A provider-managed install is told before the update runs

  • Changed the update check to report when VENDOR_MANAGED_UPDATES is on, and Admin → Extensions → Update all add-ons to stop there with the provider's message instead of attempting every add-on and failing each one. Checking for updates still works and still lists what is available.
  • Changed the header on add-on and section pages (P2P, staking, forex, finance, KYC, blog and the rest) to keep the site's main menu, with the section's own links in a second row on wide screens and a labelled block of the mobile menu. The section's links used to replace the main menu, so visitors had to go back to the home page to reach another part of the site.
  • Changed the "Insights" (blog) link to appear unless "Enable Blog" has been saved as off. An install that had never saved that switch showed it as on in Blog Settings but had no link.
  • Changed the site header on short screens (a phone held sideways) to scroll away with the page instead of covering a sixth of it.
  • Changed the floating chat bubble and the admin assistant button to slide out of the way while you scroll down on smaller screens and return when you scroll up or reach the end of the page; on tablets and small laptops they start hidden until then. The footer leaves room for them.
  • Changed announcements: they are no longer shown over the admin area, and on phones they start as a one-line bar that opens into the full notice when tapped.

Tables and record panels

  • Changed the record view panel used by every admin and user table: on phones it is a sheet at the bottom of the screen, and at every width the header X is its one close button. Delete buttons inside it are outlined rather than solid red.
  • Changed small controls — dialog and sheet close buttons, table checkboxes, row menus, pager buttons, switches, menu options — to a 40 px touch target on phones and tablets.
  • Changed the standard trade page to re-read order history at most once every two seconds while order updates are streaming, instead of once per update, which cuts backend load from accounts a bot trades on.

Fixed

A listing filter could corrupt the backend until it restarted

A crafted value in the filter parameter that every listing page accepts — public ones included — could write onto an object the whole backend process shares. The backend then misbehaved in unrelated places until it was restarted: sign-in failed, wallet statistics failed, and user deletion in the admin panel refused to run. It was seen on a live install.

  • Fixed the code that expands dotted filter keys (user.profile.email) into nested objects, in the shared query builder and in the two media listings. A key using certain reserved names reached an object shared by the whole process instead of creating a child. Such keys are now dropped, and children are only ever created as the object's own properties.

Accounts and sign-up

  • Fixed re-registering an address that had an unverified account, with email verification on. It only re-sent the verification email for the existing account, so the mailbox owner would verify an account whose password a stranger had set. A never-used pending account is now given to the new registrant: its password and name are replaced, its old code and sessions are revoked, and a new code is sent. An account that has been used in any way is not handed over.
  • Fixed the Google button on the registration page signing banned, suspended and inactive accounts in; it now refuses them, as the sign-in page already did. With email verification on, an account that never verified its address now has its password cleared, sessions ended, API keys disabled and wallet links removed before the Google owner is signed in, so whoever registered the address first keeps no way in.
  • Fixed deleting a user leaving that user's API keys working: a request made with one was still accepted as the deleted account, with the key's permissions. Keys whose owner is deleted or missing are now refused.
  • Fixed a customer whose two-factor secret the server could not read being refused at withdrawal, transfer and P2P-release confirmations even with a valid recovery code.
  • Fixed named rate limits ("5 per hour") being exceeded by several requests fired at the same instant: all of them read the counter before any was counted.
  • Fixed sign-in, registration and password reset waiting up to five minutes and then failing on a site served over plain http with the default proof-of-work captcha, because the browser does not provide the hashing function there.

Fiat deposits were credited in the wrong currency, to the wrong deposit, or after being rejected

Several payment-provider routes trusted details recorded on the deposit instead of what the provider actually settled, or matched a payment to a deposit too loosely. Each entry below says what that provider now checks.

  • Fixed rejected, refunded and frozen fiat deposits being credited — and marked completed — when the provider later reported them paid. If you had refunded such a payment outside the platform, the customer could be paid twice. Across 2Checkout, Authorize.Net, dLocal, eWAY, iPay88, Klarna, Mollie, PayPal, Paysafe, Paystack, Paytm, PayU and TransFi, a closed deposit is no longer credited or re-opened by a webhook, a return-page confirmation or a status check. See Upgrade Notes for what you will see when a provider reports one.
  • Fixed Paytm deposits that could be credited in a different currency from the one paid, at the same figure. Paytm now credits only in the deposit's own currency, and rejects the deposit when that does not match the wallet or the currency Paytm settled.
  • Fixed Paytm refunds that, for some deposits, took nothing back from the customer's balance or were treated as partial. New deposits are not affected; on an older deposit that could be, the refund is held for you instead of applied.
  • Fixed the TransFi return-page confirmation settling an order against a deposit it did not belong to, in that deposit's recorded currency instead of the settled one; and the TransFi webhook's fallback lookup, which could settle a payment against another customer's pending deposit.
  • Fixed the eWAY return-page confirmation settling a payment against a pending transaction it did not belong to, at that transaction's amount and currency. A payment can now only confirm the deposit it was created for.
  • Fixed the Klarna webhook matching a payment to another deposit of the same customer and crediting it in that deposit's recorded currency.
  • Fixed the 2Checkout notification handler matching a payment to another customer's deposit through a loose text search.
  • Fixed the Mollie webhook choosing the wrong deposit for a payment, which left the payment acknowledged to Mollie but never credited.
  • Fixed the Mollie and Adyen return-page confirmations crediting a deposit in its recorded currency without comparing it with the wallet or the currency the provider charged.
  • Fixed the PayU webhook answering success while one of APP_PAYU_MERCHANT_KEY, APP_PAYU_MERCHANT_SALT or APP_PAYU_MERCHANT_ID was missing, so PayU treated the notification as delivered, never resent it, and the payment was not credited by it. It now answers 503 until all three are set. An install that does not use PayU but still has a notification URL configured at PayU will now see PayU retrying; remove the URL at PayU to stop it.
  • Fixed extra fields on a Paystack deposit request overwriting the customer id, deposit id and fee figures the platform attaches to the payment at Paystack. Balances were never affected.

Binary options: a cancellation penalty vanished

  • Fixed the penalty on a cancelled binary order being deducted from the stake and booked nowhere when the order belonged to the Super Admin account or the install had no Super Admin. In those two cases the penalty is now waived and the full stake returned.

Withdrawals, transfers and two-factor codes

  • Fixed a wrong two-factor or recovery code at a confirmation step being answered as if the session had expired, which signed users of older mobile app versions out. Withdrawals, transfers, the P2P release and the pool-backing waiver now answer "That code is incorrect. You have N attempts left.", and the last attempt and the lockout say how many minutes to wait. The limit is unchanged: five checks per ten minutes, counted separately for each.
  • Fixed a two-factor attempt counter that lost its expiry locking a customer out of a confirmation step for good.

Wallets

  • Fixed database failures (a deadlock or a lost connection) while opening an Ecosystem wallet or recording a wallet operation's audit entry being logged and ignored, which could leave the operation partly saved while reporting success — a wallet could, for instance, keep a deposit address whose key was never saved. The whole operation now fails, rolls back and is retried on the next attempt.
  • Fixed Ecosystem tokens with no USDT market being valued at their price in another quote currency (BTC, TRX) as if it were US dollars, distorting wallet totals and profit-and-loss figures. They are now left unpriced; past days are not recalculated.
  • Fixed the Ecosystem deposit screen showing a current balance of 0 whatever the wallet held.
  • Fixed misleading "Failed to set up for wallet … Data cannot be empty" errors logged for every new wallet of a NO_PERMIT token.

Ecosystem deposit addresses and screens that ship with Core

  • Fixed Solana deposit addresses being labelled "mainnet" on installs running SOL_NETWORK="devnet" or "testnet", which made the wallet page say deposits were not available. New addresses take their label from SOL_NETWORK; see Upgrade Notes for repairing existing ones.
  • Fixed the wallet service overwriting a wallet's stored key for a network, and zeroing that network's tracked balance, when the network's deposit address was missing; coins on the old address could no longer be moved. The existing key is now kept and its own address restored. Ecosystem v6.5.6 carries the other half of this fix.
  • Fixed the Ecosystem deposit screen crashing to the error page on a network the platform cannot credit; it now shows "Deposits are not available on this network", as the wallet page does.

Spot order tickets

  • Fixed the standard trade page's spot tickets misreading the live price in a browser whose language writes decimals with a comma: the ticket showed "0,2636" and read it as 2636. A limit order went out at that price (the reported ones were refused by the market's price limit or the exchange), the total and fee preview were wrong by the same factor, and the percentage buttons sized a market buy at a tiny fraction of what was intended — and that order executed. The browser's language decided this, not the site's.
  • Fixed typing a decimal comma on the spot tickets (limit, market, stop and OCO): amount fields ignored the keystroke, the limit price read "0,5" as 5, and a trailing distance typed with a comma was dropped, so a trailing stop was placed as an ordinary fixed one.
  • Fixed the standard trade page's spot ticket keeping the price from the moment the page loaded; the market price, default limit price, estimated total and percentage buttons now follow the live price.
  • Fixed the limit ticket's Total not updating when the price was picked from the order book.
  • Fixed the trade page header cutting every market's price to two decimals (0.2633 shown as "0.26", a sub-cent coin as "0.00").
  • Fixed a chart occasionally drawing a live candle that belonged to another market at the same interval. Candle updates now carry their market, and a removed chart closes its live feed.

The Pro trade layout

  • Fixed orders jumping around in the Orders panel: a new order no longer appears at the bottom and leaps to the top, and while your pointer or focus is in the panel (or an order is being edited) rows stay put, update in place, and new ones wait behind a "new" counter.
  • Fixed Tab doing nothing (it was reserved for a shortcut that did not exist) and Escape being swallowed when no dialog was open.

Exchange markets

  • Fixed saving a spot market's precision or fees in the admin erasing the provider's stored limits for that market, which made the pair disappear from older mobile app versions. Limits erased before the update are not restored.

Requests and files

  • Fixed a failed Stripe call during a card deposit returning Stripe's own response headers to the customer, including a content length that did not match the response and Stripe's internal request id. Error responses now carry only the platform's own headers plus any rate-limit headers.
  • Fixed files under /uploads/ ending in .webp, .avif, .webm, .docx or .xlsx — including every image uploaded through the platform, which is stored as WebP — being served by the backend as "text/html", which a browser may refuse to display or download properly.
  • Fixed coin logos being served only by the website, so a mobile app configured with an API-only host showed letter tiles. The backend now serves them at /img/crypto/ and /api/img/crypto/.
  • Fixed requests abandoned while the API documentation was being generated logging an "Unhandled Rejection … uWS.HttpResponse must not be accessed…" error each time.

Admin

  • Fixed "Delete Permanently" on a user with wallets or transactions answering a raw foreign-key error. It now counts the wallets and transactions on record and points to the normal Delete, which keeps the ledger; a bulk permanent delete that includes such an account deletes nothing and says so. Other admin deletes blocked by linked records now say which table still references the row.
  • Fixed settings search looking only in the open category, so a setting in another one showed "No settings found".

Admin and user screens

  • Fixed drop-down lists opening behind a dialog opened from a record's view panel. "Block User" could not be completed from a user's card on a phone, because no reason could be picked.
  • Fixed the admin assistant's floating button covering the bottom-right controls of dialogs and record panels on phones.
  • Fixed create and edit forms whose first row of fields was hidden behind a long form header; on the licence attestation form this hid three required fields, so Create failed without saying why.
  • Fixed form placeholders lower-casing abbreviations ("Enter min (usd)" under a label reading "Min (USD)"); abbreviations keep their capitals.
  • Fixed a new slider (Admin → Content → Slider) starting with Status off, because create forms ignored the starting value a field declares.
  • Fixed tables showing "Page 1 of 0" and a count of 0 when a list failed to load or was empty.
  • Fixed keyboard use of tables: rows and cards can be reached with Tab and opened with Enter or Space, the record panel keeps focus and returns it on close, and icon-only buttons have names for screen readers.
  • Fixed right-to-left layouts: table cells line up under their titles, close buttons move to the top-left, and icons inside fields keep their gap.
  • Fixed pages squeezed into a 480 px column on screens 480–639 px wide.
  • Fixed the mobile menu's search field on user and add-on pages, which closed the menu and did nothing.
  • Fixed smaller glitches: the "Access denied" overlay making a phone page scroll sideways; Filter and Sort buttons on tables with nothing to filter or sort; a clipped text-filter operator; long selected values overflowing a drop-down; Hummingbot and Trading Bot navigation labels always in English.
  • Fixed every browser request being refused on a site whose NEXT_PUBLIC_SITE_URL is an http:// address but which is served over HTTPS — the symptom was "Security verification failed" at login with nothing in the backend log.

The update-all summary contradicted itself

  • Fixed the summary shown when nothing was applied. It said "every add-on checked was already current" even when every add-on had failed, directly under the rows saying so, and ran its sentences together ("already current.6 failed").