Tuesday, August 18, 2026
banner

BitBox has released a firmware update fixing two severe vulnerabilities that could have exposed hardware wallet users to malicious firmware or caused Bitcoin to be locked to an unintended address.

Summary

  • BitBox has patched two severe vulnerabilities affecting its BitBox02 and BitBox02 Nova hardware wallets.
  • One flaw could have allowed malicious firmware installation, while another could have locked Bitcoin to an unintended address.
  • BitBox said neither vulnerability had been exploited and no user funds were reported lost.
  • The fixes follow a Coldcard firmware flaw linked to more than $112 million in Bitcoin thefts.

BitBox said in a security disclosure on Monday that the first vulnerability involved memory corruption affecting unconfigured Multi editions of the BitBox02 and BitBox02 Nova, while a second flaw affected the wallet maker’s Silent Payments implementation.

The company said it had found no evidence that either vulnerability had been exploited and had received no reports of users losing funds because of the flaws.

BitBox vulnerability could have allowed malicious firmware

For the first vulnerability, BitBox said a malicious host connected to an affected wallet could exploit memory corruption to execute arbitrary code before the device had been configured with a wallet.

Successful exploitation could potentially allow the host to install malicious firmware, creating a route through which funds could later be compromised, according to the company.

The exposure was limited to Multi editions of the BitBox02 and BitBox02 Nova that had not yet been set up. BitBox classified the vulnerability as severe because arbitrary code execution could undermine protections designed to prevent unauthorised software from running on the hardware wallet.

Firmware controls how a hardware wallet handles cryptographic operations, verifies transactions and communicates with a connected computer. BitBox said the vulnerability could therefore put funds at risk if an attacker managed to use the flaw to install malicious firmware on an affected device.

Similar hardware and firmware weaknesses have surfaced at other wallet makers in recent months. In June, crypto.news reported on a flaw in the TROPIC01 Secure Element used by Trezor Safe 7 devices after Ledger Donjon researchers carried out a laser fault injection attack during laboratory testing.

Trezor said its Safe 7 remained protected because the device uses three independent hardware security layers. According to the company, compromising TROPIC01 alone did not provide access to a user’s PIN, wallet or funds.

Tropic Square had provided the chip to Ledger Donjon for independent testing, with researchers notifying the company in January that they had extracted some chip secrets and bypassed firmware signature checks using the laboratory attack.

Another hardware attack disclosed in July allowed Ledger Donjon researchers to reset the password on a Tangem wallet card using a targeted laser pulse against its secure element.

Ledger Donjon said the attack required physical possession of the card, invasive preparation, specialist knowledge and laboratory equipment costing about $250,000. Tangem described the everyday risk to customers as “virtually non-existent,” while advising users to keep their wallet cards physically secure.

Silent Payments flaw could have locked Bitcoin

BitBox’s second severe vulnerability affected Silent Payments, a Bitcoin privacy feature that allows users to receive payments without publishing a new address for each transaction.

According to BitBox, a malicious host could exploit the implementation to cause Bitcoin to be locked to an unintended address.

Direct theft was not possible through the vulnerability, the company said. An attacker could instead leave the victim unable to recover the Bitcoin without cooperation and potentially demand a ransom in exchange for helping unlock the coins.

Such an attack would not automatically transfer control of the affected Bitcoin to the malicious host, but BitBox said the vulnerability could still put funds at risk by making them inaccessible to their owner.

The company addressed the problem through its latest firmware update and said it had received no reports of the Silent Payments flaw being exploited.

BitBox has dealt with other security issues through firmware updates this year. Its Oeschinen update in July included several security fixes, including one for a buffer out-of-bounds write affecting the BitBox02 firmware and bootloader.

According to the company’s disclosure at the time, a USB request accepted a length value without properly checking it against the size of the destination buffer, creating a potential route for a malicious host to trigger an out-of-bounds write.

BitBox said no working exploit had been demonstrated for that vulnerability, although an effect on control flow could not be completely ruled out.

Earlier in January, the company also patched two BitBox02 Nova vulnerabilities reported through its bug bounty programme. BitBox classified the issues as minor and moderate because exploitation required advanced physical access and applied only under specific conditions.

Coldcard firmware flaw has put wallet security under scrutiny

BitBox’s update follows the disclosure of a separate Coldcard firmware flaw linked to more than $112 million in stolen Bitcoin after the vulnerability remained undetected for more than five years.

Galaxy Research said Friday that Coldcard-related losses had exceeded $112 million, with approximately 1,778.6 BTC swept from more than 8,600 addresses.

The vulnerability was traced to a firmware change introduced in March 2021 that affected the randomness used to generate wallet seeds. Attackers could brute-force impacted seeds and derive the corresponding private keys without obtaining physical access to the hardware wallet, according to research into the incident.

A wallet seed is used to derive the private keys controlling its cryptocurrency. Weaknesses that reduce the randomness used during seed generation can therefore reduce the number of possible combinations an attacker needs to test.

For users whose wallets were created with affected Coldcard firmware, updating the device alone would not repair a seed that had already been generated with weak randomness. Moving funds to a wallet created from a newly generated secure seed would be required to remove exposure associated with the compromised seed.

The incident affected a hardware wallet line that received its first major hardware revision in several years earlier in 2026. Coinkite launched the Coldcard MK5 in March, with the device becoming the first hardware update to its flagship MK series since the MK4 arrived in 2022.

The MK5 retained the previous model’s dual secure-element architecture using chips from two different vendors and kept private keys air-gapped. Its main changes included a 1.54-inch Gorilla Glass display, redesigned physical buttons and improved NFC functions.

Coinkite said at the time that the five major MK5 upgrades focused on usability while preserving the security architecture used by the previous model.

Customer data leaks have created separate phishing risks

Hardware wallet owners have also faced security incidents outside the devices themselves, with recent breaches involving Trezor and SafePal exposing customer and order information belonging to more than 53,000 people.

Trezor attributed the exposure of information belonging to 13,689 customers to shipping provider ShipMonk. SafePal separately said an authorisation flaw in an order-tracking plug-in exposed details connected to 39,798 customers.

Neither incident compromised the companies’ hardware wallets, private keys or recovery phrases, according to the respective disclosures. Both companies warned that exposed personal and order information could instead be used for targeted phishing and impersonation attempts.

Such information can give attackers details needed to make wallet-related scams appear more credible. Earlier in February, attackers sent physical letters impersonating Trezor and Ledger and instructed recipients to complete supposed authentication or transaction checks.

The physical phishing campaign used official-looking correspondence containing QR codes that directed recipients to malicious websites. Some letters created urgency by claiming users had to complete an authentication process to avoid problems accessing their wallets.

The websites asked victims to enter 12-, 20- or 24-word recovery phrases under the pretence of verifying ownership. Once submitted, the phrases were transmitted to the attackers, allowing them to recreate the wallets and gain control over the associated funds.

Trezor and Ledger said legitimate hardware wallet providers do not ask customers to enter, scan, upload or share recovery phrases through websites or other external channels. Recovery phrases should only be entered directly on a hardware wallet when restoring a wallet, according to the companies.

News#BitBox #patches #wallet #flaws #install #malicious #firmware1787048015

banner
crypto & nft lover

Johnathan DoeCoin

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar.

Follow Me

Top Selling Multipurpose WP Theme

Newsletter

banner
crypto & nft lover

Johnathan DoeCoin

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar.

@2022 u2013 All Right Reserved. Designed and Developed by PenciDesign