BitBox discloses severe firmware vulnerabilities and urges users to update
The hardware-wallet maker says its Aug. 17 Dixence release fixes three serious issues, including a bootloader exploit path and flaws affecting some uninitialized devices and silent payments.
By The Third AnglePublished 3 min read
Illustrative software-security imagery for BitBox's firmware disclosure; the image does not depict BitBox hardware or the vulnerabilities. Photo: Unsplash · Unsplash License
BitBox has disclosed three serious firmware vulnerabilities and urged users to install its latest update. The hardware-wallet maker's Aug. 17 Dixence release says the issues were found during internal audits and fixed in firmware version 9.26.5 or earlier releases, depending on the vulnerability.
BitBox said it has no reports that the issues were exploited or that user funds were stolen. Decrypt reported the disclosure as an AI-assisted security review, but the company's own notice is the source for the affected device versions and update instructions.
Three different failure paths
The first issue concerns older bootloader versions. BitBox says an attacker could have manipulated a user into installing malicious firmware on an authentic BitBox02 after a successful phishing attack and device unlock. The company says that path was fixed in firmware 9.26.2 and does not affect the BitBox02 Nova.
A separate memory-corruption issue affects some Multi devices that have not yet been set up with a wallet and are used with a malicious host device. If exploited, BitBox says it could enable arbitrary code execution and potentially malicious firmware installation. A third issue in the Silent Payments implementation could have locked funds to an unintended payment address, although it did not allow direct theft, according to the company.
The practical fix
BitBox says devices on firmware version 9.26.5 are not affected by the issues described in the Dixence release. It recommends updating through the BitBoxApp and downloading only from the official BitBox site or the update banner inside the app. Users should not enter recovery words in response to an email, search result or support request.
The disclosure does not establish a theft event. Its significance is operational: a hardware wallet can remain in a user's possession while firmware, host-device or transaction-handling weaknesses create a path to loss. The update closes those paths for the affected versions, but users still need to identify their device edition and current firmware before assuming they are protected.