BitBox, the Zurich-based maker of the BitBox02 hardware wallet, released its Dixence security update this week after its engineers found two severe flaws in the device’s firmware, along with a third issue described as less dangerous.

The company said there is no evidence the vulnerabilities were ever exploited. In its disclosure, BitBox said, 「There are no reports of stolen user funds and there is no reason for users to panic.」 Older firmware versions remain exposed until users install the update.
A bootloader flaw could have enabled malicious firmware installation
The first severe issue was found in the bootloader, the code that determines which firmware a device will accept. BitBox said the July Oeschinen release, version 9.26.2, had already fixed most of the problem, but it now believes the original issue was more serious than first disclosed.
According to the company, an attacker running a phishing scam could have tricked a user into installing a fake BitBoxApp and unlocking the device, then loaded malicious firmware onto a genuine BitBox02 and stolen the coins.
BitBox said the newer BitBox02 Nova was never exposed to this issue because of its bootloader version.
Multi edition bug affected devices before wallet setup
The second severe flaw was a memory-corruption bug in the Multi edition of BitBox before the wallet had been set up. When paired with a hostile computer, the issue could have allowed arbitrary code execution and, again, the installation of malicious firmware.
The Bitcoin-only edition does not include the affected code, so it was not impacted.
Silent-payment issue carried lower direct theft risk
A third issue involved the wallet’s silent-payment feature. BitBox said it could not directly steal coins, but it could have locked funds to the wrong address in what the report described as a ransom-style scenario.
All three issues have been fixed in version 9.26.5.
Company says frontier AI models were used in the review
BitBox said it relied on frontier AI models during its internal review. The company described that work as part of a broader effort, outlined in a separate post, to audit firmware with AI assistance.
The incident adds to a growing list of reminders that hardware wallets, while often treated as a preferred option for security-focused crypto holders, are not immune to serious vulnerabilities.
Recent hardware wallet incidents have kept security concerns in focus
Decrypt noted that the recent Coldcard Bitcoin exploit showed how a five-year-old firmware bug let thieves drain about 1,596 BTC, a theft worth more than $130 million and described as the largest hardware-wallet hack of 2026.
Days earlier, a data breach at hardware wallet maker SafePal raised fresh concerns about so-called wrench attacks after personal details, including physical addresses, were exposed.
Update is live, but users still need to install it
BitBox said the fix is available at bitbox.swiss/download. Until users install it, devices running older firmware remain vulnerable.

