BitBox2026-08-18 18:06:42BitBox discloses severe BitBox02 firmware flaws and rolls out fixes after AI-assisted reviewBitBox, the Zurich-based company behind the BitBox02 hardware wallet, has disclosed two severe firmware flaws and a third lower-risk issue, saying all three are now fixed in version 9.26.5. The company said there is no evidence the bugs were ever exploited and no reports of stolen user funds, but warned that devices running older firmware remain exposed until users update. One of the severe flaws involved the bootloader and could have let an attacker install malicious firmware on a genuine BitBox02 through a phishing campaign that tricked a user into installing a fake BitBoxApp and unlocking the device. BitBox said the newer BitBox02 Nova was not affected by that issue because it uses a different bootloader version. The second severe flaw affected the Multi edition before wallet setup and, when paired with a hostile computer, could have enabled arbitrary code execution. A separate issue in the wallet’s silent-payment feature could not directly steal funds, but could have locked coins to the wrong address. BitBox said its internal review used frontier AI models as part of a broader firmware-auditing effort.1180
256 Foundatio2026-08-14 14:03:54256 Foundation launches ASIC firmware review and files 41 issue reportsBitcoin News said in a post on X that 256 Foundation has launched the 256 Red Team, a security effort focused on auditing ASIC miner firmware. The project uses reverse engineering, live traffic capture, and share-level reconciliation to inspect firmware behavior. According to the team, it has filed 41 issue reports covering Bitmain’s stock firmware as well as third-party options including LuxOS, VNISH, and Braiins OS. Reported findings include unauthenticated factory APIs, paths that can lead to root access, default credentials, embedded vendor SSH keys, and update mechanisms that cannot verify what is being installed. After decompiling Bitmain’s miner daemon and reviewing live connections, researchers said they found no evidence in Bitmain’s original firmware of hashrate skimming, a remote kill switch, or covert beacons. They said the main risks were concentrated in third-party “optimization” firmware. The team has also sent three responsible disclosures to VNISH, Luxor, and Braiins, giving each party 30 days to respond before public disclosure. MicroBT, Canaan, Auradine, Bitdeer, and ePIC are set for later audits.1320