BitBox said it has fixed multiple severe vulnerabilities in its hardware wallet firmware and told users to update their devices through the official BitBoxApp. The Swiss company added that there have been no reports of stolen user funds, though it still urged customers to handle the update process carefully.

In a blog post published Tuesday, BitBox said one of the vulnerabilities could have allowed an attacker to manipulate users into installing firmware that could then lead to stolen funds. The company advised users to update firmware through the official BitBoxApp, ideally by clicking the in-app update prompt instead of searching for the update themselves.
In a post on X, BitBox wrote: "We just released the Dixence security update. During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware. We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings."
BitBox also said there are no reports of stolen user funds and "there is no reason for users to panic." The company added: "We recommend all users to update their BitBox devices to the latest firmware version, which fixes all security issues described in this article."
BitBox Multi affected, Bitcoin-only version not affected
BitBox said another severe vulnerability it found was tied to memory corruption. In its post, the company said the issue affected the Multi edition of the BitBox and could have enabled arbitrary code execution, followed by the installation of malicious firmware and potential loss of funds.
It also said the Bitcoin-only edition of the BitBox was not affected because its firmware does not contain the code in question.
Disclosure lands as Coldcard fallout continues
The warning arrives while Bitcoin users are still dealing with the aftermath of a separate security failure involving Coldcard, a popular product designed by Canadian company Coinkite. In that case, users had funds drained because of a firmware bug that led to weak seed generation through a flawed random number generation process.
BitBox said its case differs from the Coldcard incident. Users do not need to migrate funds and only need to update their firmware.
According to the latest figures from Galaxy Research, hackers have since stolen a confirmed $115 million in bitcoin, though the total could be higher.
Coinkite first warned users on July 31 that a firmware bug in Coldcard Mk3 devices, beginning with version 4.0.1 in March 2021, caused seed generation to fall back to a weak software pseudorandom number generator instead of the hardware true random number generator. That flaw allowed hackers to effectively guess investors' seed phrases.
The reported losses have risen slowly as criminals targeted more recent devices. At the same time, Coinkite and other Bitcoiners have urged Coldcard users to move their funds immediately.
This story first appeared in Bitcoin Magazine and was written by Mathew Di Salvo.

