BitBox discloses severe BitBox02 firmware flaws and rolls out fixes after AI-assisted review

BitBox discloses severe BitBox02 firmware flaws and rolls out fixes after AI-assisted review

N
News Editor
2026-08-18 18:06:42
BitBox, the Zurich-based company behind the BitBox02 hardware wallet, has disclosed two severe firmware flaws and a third lower-risk issue, saying all three are now fixed in version 9.26.5. The company said there is no evidence the bugs were ever exploited and no reports of stolen user funds, but warned that devices running older firmware remain exposed until users update. One of the severe flaws involved the bootloader and could have let an attacker install malicious firmware on a genuine BitBox02 through a phishing campaign that tricked a user into installing a fake BitBoxApp and unlocking the device. BitBox said the newer BitBox02 Nova was not affected by that issue because it uses a different bootloader version. The second severe flaw affected the Multi edition before wallet setup and, when paired with a hostile computer, could have enabled arbitrary code execution. A separate issue in the wallet’s silent-payment feature could not directly steal funds, but could have locked coins to the wrong address. BitBox said its internal review used frontier AI models as part of a broader firmware-auditing effort.

BitBox, the Zurich-based maker of the BitBox02 hardware wallet, released its Dixence security update this week after its engineers found two severe flaws in the device’s firmware, along with a third issue described as less dangerous.

BitBox discloses severe BitBox02 firmware flaws and rolls out fixes after AI-assisted review 2

The company said there is no evidence the vulnerabilities were ever exploited. In its disclosure, BitBox said, 「There are no reports of stolen user funds and there is no reason for users to panic.」 Older firmware versions remain exposed until users install the update.

A bootloader flaw could have enabled malicious firmware installation

The first severe issue was found in the bootloader, the code that determines which firmware a device will accept. BitBox said the July Oeschinen release, version 9.26.2, had already fixed most of the problem, but it now believes the original issue was more serious than first disclosed.

According to the company, an attacker running a phishing scam could have tricked a user into installing a fake BitBoxApp and unlocking the device, then loaded malicious firmware onto a genuine BitBox02 and stolen the coins.

BitBox said the newer BitBox02 Nova was never exposed to this issue because of its bootloader version.

Multi edition bug affected devices before wallet setup

The second severe flaw was a memory-corruption bug in the Multi edition of BitBox before the wallet had been set up. When paired with a hostile computer, the issue could have allowed arbitrary code execution and, again, the installation of malicious firmware.

The Bitcoin-only edition does not include the affected code, so it was not impacted.

Silent-payment issue carried lower direct theft risk

A third issue involved the wallet’s silent-payment feature. BitBox said it could not directly steal coins, but it could have locked funds to the wrong address in what the report described as a ransom-style scenario.

All three issues have been fixed in version 9.26.5.

Company says frontier AI models were used in the review

BitBox said it relied on frontier AI models during its internal review. The company described that work as part of a broader effort, outlined in a separate post, to audit firmware with AI assistance.

The incident adds to a growing list of reminders that hardware wallets, while often treated as a preferred option for security-focused crypto holders, are not immune to serious vulnerabilities.

Recent hardware wallet incidents have kept security concerns in focus

Decrypt noted that the recent Coldcard Bitcoin exploit showed how a five-year-old firmware bug let thieves drain about 1,596 BTC, a theft worth more than $130 million and described as the largest hardware-wallet hack of 2026.

Days earlier, a data breach at hardware wallet maker SafePal raised fresh concerns about so-called wrench attacks after personal details, including physical addresses, were exposed.

Update is live, but users still need to install it

BitBox said the fix is available at bitbox.swiss/download. Until users install it, devices running older firmware remain vulnerable.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
30

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.