BitBox2026-09-15 20:16:55BitBox adds Lightning hot wallet creation to its mobile BitBoxAppSwiss bitcoin hardware wallet maker BitBox said users of any BitBox hardware wallet can now create a Lightning Network hot wallet inside the mobile BitBoxApp. The setup lets users fund the wallet directly from on-chain balances and pay Lightning invoices without moving between different apps, wallets, or third-party services. According to the announcement, the Lightning wallet is derived from an existing BitBox backup, so users do not need to write down a new seed phrase, while the hardware wallet and the Lightning wallet remain separate. BitBox said the Lightning side operates as a hot wallet for small, everyday payments such as coffee purchases, invoices, and quick transfers, while long-term savings remain stored on the hardware device. Inside BitBoxApp, users can scan and pay Lightning invoices, send and receive bitcoin, claim a dedicated Lightning address, top up from an on-chain wallet, and move funds back again. The feature is built with Breez SDK and makes BitBox one of more than 100 integration partners in the Breez network. Spark provides the underlying infrastructure, and users do not need to run a node, open channels, or manage liquidity, with custody of funds remaining in users’ hands. Breez also launched the developer app Glow in August.600
European Unio2026-09-14 11:38:44EU cyber rules give crypto wallet makers 24 hours to report exploited flawsCryptocurrency wallet providers in the European Union now face a tight disclosure schedule under the bloc’s Cyber Resilience Act. The new rules require hardware and software wallet makers to file an early warning within 24 hours after becoming aware of an actively exploited bug or severe vulnerability affecting their products, then submit a full notification within 72 hours. A final report must follow 14 days after corrective or mitigating measures become available, while severe incidents must be fully reported within one month. The reporting regime applies to products with digital elements made available in the EU, not only crypto wallets, and sits within the European Commission’s broader cybersecurity strategy. Penalties are steep: companies that fail to comply with Articles 13 and 14 can face fines of up to 15 million euros, or 2.5% of worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete or misleading information can trigger fines of up to 5 million euros. The move comes after recent security incidents involving wallet providers and related service vendors, including Trezor’s disclosure that 67,000 additional US customers were exposed in a breach tied to shipping provider ShipMonk, phishing warnings issued by Trezor and BitBox, and a June warning from Zilliqa about a flaw in the Zilliqa Ledger app that could expose private keys.350
EU2026-09-14 11:51:35EU Cyber Resilience Act Takes Effect With Tight Breach Reporting Rules for Crypto Wallet ProvidersThe European Union’s Cyber Resilience Act, or CRA, officially took effect on Sept. 11, setting stricter incident-reporting obligations for providers of crypto hardware and software wallets sold in the EU market. Under the new rules, firms must file an early warning report within 24 hours after discovering an actively exploited vulnerability or a severe security flaw, then submit a full notification within 72 hours. After corrective or mitigation measures are taken, manufacturers must provide a final report within 14 days, while severe incidents must be fully reported within one month. The European Commission said the reporting framework is meant to better protect consumers and businesses from cyber threats. The rules apply to all products with digital elements offered on the EU market and form part of the bloc’s broader cybersecurity strategy. Penalties in the final draft are substantial: companies that fail to comply with Articles 13 and 14 may face administrative fines of up to €15 million, roughly $17.3 million, or 2.5% of global annual turnover, whichever is higher. Firms that submit incorrect, incomplete, or misleading information may be fined up to €5 million. The measure comes after several security incidents involving wallet providers. Trezor said on Sept. 4 that a data breach at logistics vendor ShipMonk affected about 67,000 U.S. customers, above the initial estimate of 14,000. This week, Trezor and BitBox also warned users about phishing emails disguised as urgent security notices. In June, Layer-1 blockchain network Zilliqa said a flaw in its Ledger app could allow attackers to recover private keys using public on-chain data.840
Strive2026-09-09 20:37:49Joe Burnett says Trezor and BitBox email infrastructure may have been compromisedJoe Burnett, vice president at Strive, said in a post on X that the email infrastructure used by Trezor and BitBox appears to have been compromised. He also said Bitcoin remains in what he described as a strengthening phase. The update was published by ChainCatcher. The source text did not provide additional details on the suspected breach, its scope, or any response from the companies. No further technical information, timeline, or impact assessment was included in the original item. As presented, the report is limited to Burnett’s statement on X and his accompanying comment on Bitcoin’s current phase.730
hardware wall2026-08-26 18:16:05BitBox says card-payment sales rose roughly 10x after Coldcard incident; Trezor and OneKey also report gainsHardware wallet maker BitBox said its credit-card payment sales in August rose by about 10 times versus a baseline from the previous several weeks, with most of the increase coming from North America. Trezor and OneKey also confirmed higher sales over the same period, though neither company disclosed exact figures. After the Coldcard incident, Trezor, BitBox, and OneKey said they re-examined processes tied to mnemonic generation, random number generators, entropy, and firmware verification. Trezor plans penetration testing for core firmware functions and said it will publish the related security audit report. OneKey said it will step up reviews of security-critical code paths and transaction-signing procedures. Ledger CTO Charles Guillemet said AI-assisted attacks mean patch releases, vulnerability disclosure, and user education need to move faster. Blockstream Jade has already released a firmware update with multiple fixes and advised users to update their apps, operating systems, devices, routers, and home appliances as well.940
BitBox2026-08-18 21:06:52BitBox tells users to update after finding severe firmware vulnerabilitiesBitBox, the Swiss hardware wallet maker, said it has fixed multiple severe security issues in its firmware and told users to update through the official BitBoxApp. The company said there have been no reports of stolen funds and that users should not panic, but it still urged all customers to install the latest firmware carefully. According to BitBox, one flaw could have allowed an attacker to manipulate users into installing firmware that could lead to theft. Another severe issue involved memory corruption in the BitBox Multi edition, which could have enabled arbitrary code execution, malicious firmware installation, and potential fund loss. BitBox said its Bitcoin-only edition was not affected because the relevant code is not present in that firmware. The disclosure comes as the Bitcoin wallet sector is still dealing with fallout from a separate Coldcard firmware bug disclosed by Coinkite. In that case, users were told to move funds after weak seed generation exposed wallets to theft. BitBox said its situation is different: users do not need to migrate funds, only update their device firmware.1150
BitBox2026-08-18 18:06:42BitBox discloses severe BitBox02 firmware flaws and rolls out fixes after AI-assisted reviewBitBox, the Zurich-based company behind the BitBox02 hardware wallet, has disclosed two severe firmware flaws and a third lower-risk issue, saying all three are now fixed in version 9.26.5. The company said there is no evidence the bugs were ever exploited and no reports of stolen user funds, but warned that devices running older firmware remain exposed until users update. One of the severe flaws involved the bootloader and could have let an attacker install malicious firmware on a genuine BitBox02 through a phishing campaign that tricked a user into installing a fake BitBoxApp and unlocking the device. BitBox said the newer BitBox02 Nova was not affected by that issue because it uses a different bootloader version. The second severe flaw affected the Multi edition before wallet setup and, when paired with a hostile computer, could have enabled arbitrary code execution. A separate issue in the wallet’s silent-payment feature could not directly steal funds, but could have locked coins to the wrong address. BitBox said its internal review used frontier AI models as part of a broader firmware-auditing effort.1190
BitBox2026-07-03 00:45:14BitBox Launches BitBox02 Nova: A Redesigned Hardware Wallet for Bitcoin Self-Custody with Native iOS Support and Whisper BluetoothBitBox has announced the BitBox02 Nova, a newly redesigned hardware wallet specifically built for Bitcoin self-custody. The device introduces native compatibility with iOS devices, eliminating previous workarounds. It features Whisper, a trust-minimized Bluetooth architecture that physically isolates wireless communication from the core wallet firmware, ensuring cryptographic integrity and privacy. The BitBox02 Nova uses an EAL6+ certified secure chip and offers increased memory for future updates. Two versions are available: a Bitcoin-only edition with minimal firmware, and a multi-coin version supporting altcoins and universal two-factor authentication.600