Newsroom

BitBox Issues Urgent Firmware Update for Two Severe Wallet Flaws

18 August, 2026   /   News   /  AI   /   Tags:  bitbox, firmware, silent, hardware, malicious

BitBox Issues Urgent Firmware Update for Two Severe Wallet Flaws

Swiss hardware wallet maker BitBox has released a security patch addressing critical vulnerabilities in its BitBox02 and BitBox02 Nova devices that could have enabled malicious firmware installation or locked Bitcoin to unintended addresses

BitBox, the Swiss manufacturer of self-custody hardware wallets, has deployed a firmware update known as the Dixence release to correct two vulnerabilities it classified as severe. The company stated that the issues affected Multi editions of the BitBox02 and BitBox02 Nova models and its Silent Payments feature. BitBox reported no evidence of exploitation in the wild and no confirmed cases of user fund losses linked to the flaws.

Memory Corruption Risk in Unconfigured Devices

One vulnerability involved memory corruption on Multi editions of the BitBox02 and BitBox02 Nova that had not yet been configured with a wallet. According to the company, a malicious host connected to an affected device could exploit the issue to execute arbitrary code. Successful exploitation could have allowed the installation of malicious firmware, potentially undermining the device’s protections and exposing funds through altered transaction handling or cryptographic operations.

BitBox noted that the exposure was limited to devices still in an unconfigured state. The company classified the flaw as severe because arbitrary code execution could bypass safeguards designed to prevent unauthorized software from running on the hardware. Users were instructed to install the update through the BitBoxApp by navigating to the settings menu and applying the new firmware promptly.

A severe exploit could have enabled attackers to manipulate users into installing malicious firmware, unlock their device, and steal their funds.
BitBox security disclosure

Silent Payments Flaw and Potential Fund Lockup

The second vulnerability concerned BitBox’s implementation of Silent Payments, a Bitcoin privacy feature that enables receiving funds without generating a new address for every transaction. A malicious host could have used the flaw to cause Bitcoin to be locked to an unintended address. Direct theft of the coins was not possible through this issue. However, an attacker could have rendered the funds inaccessible to the rightful owner and potentially sought a ransom in exchange for assistance in recovery.

BitBox confirmed that the firmware update resolves the Silent Payments weakness. The company again stated that it had received no reports of the vulnerability being used against users or resulting in lost assets.

Update Guidance and User Precautions

BitBox recommended that all users of the affected devices upgrade to the latest firmware without delay. Community figures advising Bitcoin holders echoed the call for immediate action. One prominent voice in related crypto circles urged users to perform the update on a clean or newly set-up computer to minimize the chance of malware interfering with the process.

If you have access to a fresh or new computer, this is even better.
Mishaboar

The company has previously issued security-related firmware updates, including the Oeschinen release in July that addressed a buffer issue and earlier patches for the BitBox02 Nova reported through its bug bounty program.

Wider Context of Hardware Wallet Security Concerns

The BitBox disclosure arrives amid heightened attention on hardware wallet security. A separate Coldcard firmware vulnerability, traced to a change introduced in March 2021 and undetected for more than five years, was linked to losses exceeding $112 million. Research indicated that approximately 1,778.6 BTC was swept from more than 8,600 addresses after attackers exploited weakened seed randomness to derive private keys without physical access to the devices.

In addition, recent data exposures involving other wallet providers affected customer and order information belonging to more than 53,000 individuals. Those incidents did not compromise private keys or recovery phrases but raised concerns about targeted phishing and social engineering risks stemming from leaked personal details.

Hardware wallets are intended to keep private keys offline and reduce reliance on internet-connected systems. The latest BitBox findings illustrate that device state during initial setup and interactions with connected hosts remain critical points of attention for both manufacturers and users. BitBox stated that its audits identified the issues and that the Dixence firmware closes the identified paths for abuse.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.