BNB $603.43 -0.29%
XRP $0.996112 -0.68%
ETH $1,896.50 -0.14%
BTC $64,228.42 +1.12%
BNB $603.43 -0.29%
XRP $0.996112 -0.68%
ETH $1,896.50 -0.14%
BTC $64,228.42 +1.12%
BREAKING
Digital Wallet

BitBox Patches Two Critical Firmware Flaws Before Any Funds Were Lost

BitBox Patches Two Critical Firmware Flaws Before Any Funds Were Lost
BitBox Patches Two Critical Firmware Flaws Before Any Funds Were Lost

Community Trust ScoreVerified

93%
Real
Verified15 votes
Updated 9 minutes ago

BitBox just pushed a firmware update. Version 9.26.5 is out, and it fixes two vulnerabilities the company called “severe” — the kind of word hardware wallet makers don’t throw around lightly.

The first flaw hit Multi editions of the BitBox02 and BitBox02 Nova, but only on devices that hadn’t been set up with a wallet yet. Memory corruption in that unconfigured state could let a malicious host run arbitrary code on the device — which basically means a bad actor could force the installation of harmful firmware without the user knowing. That’s about as bad as it gets for a device whose whole job is to keep private keys offline and safe. The second problem sat inside BitBox’s Silent Payments feature, a relatively new Bitcoin privacy tool. The bug could have allowed an attacker to lock Bitcoin to unintended addresses. Direct theft wasn’t possible, but the scenario where a user’s funds get locked and an attacker demands ransom to help recover them isn’t exactly a comfort. BitBox says no exploitation happened. No funds lost. No reports of anyone being hit. The company moved to patch both issues before anything went wrong, which is probably the best outcome you can hope for when a “severe” flaw gets found.

No comment from BitBox beyond the disclosure itself.

Advertisement

What the Two Flaws Actually Meant for Users

The memory corruption issue is worth unpacking a little more. Hardware wallets that haven’t been initialized yet are in a vulnerable state — they’re essentially blank slates, and if the software talking to them is compromised or malicious, that window matters. BitBox’s Multi edition devices in that pre-setup state could have had arbitrary code pushed through. From there, the attacker could install firmware that looks legitimate but isn’t. The user would have no obvious way to tell.

Silent Payments is trickier to explain. It’s a privacy feature that lets Bitcoin senders pay someone without reusing addresses, which helps break transaction traceability. BitBox’s implementation had a flaw that might have allowed funds to get routed to addresses the user never intended. Again — not a direct theft vector, but the ransom angle is real. If your Bitcoin is locked and the only path to recovery runs through someone who wants payment, you’re in a bad spot even if nobody technically “stole” anything. BitBox’s update closes that path entirely, at least in the current version.

Users still running older firmware should upgrade to 9.26.5. That’s the clear takeaway.

A Rough Stretch for Hardware Wallet Security

BitBox’s disclosure didn’t land in a vacuum. The hardware wallet sector has had a genuinely rough run lately, and the timing makes the industry context hard to ignore.

Coldcard, one of the most popular Bitcoin-focused hardware wallets, got hit with a vulnerability tied to a firmware change from March 2021. The flaw messed with wallet-seed randomness — the process that generates the private keys keeping funds secure. Attackers who knew about it could derive private keys through brute force without ever touching the physical device. That’s a nightmare scenario for a product built around the premise that keys stay offline. The flaw went undetected for more than five years. Losses linked to it surpassed $112 million. That number is hard to sit with.

Separately, both Trezor and SafePal dealt with data breaches that exposed customer information for more than 53,000 users combined. Neither company’s devices were compromised — the hardware itself held up — but the personal data that leaked is a different kind of problem. Phishing attacks, impersonation scams, targeted social engineering: all of it becomes easier when attackers know who owns a hardware wallet and where they live. Trezor traced its breach to a third-party shipping provider. SafePal found the source in an order-tracking authorization flaw. Different causes, same result for the customers whose data got out.

So when BitBox drops a “severe” vulnerability disclosure, it lands against that backdrop. The industry’s self-custody pitch — that keeping keys on a hardware device is safer than leaving funds on an exchange — still holds up broadly, but incidents like these chip away at the assumption that the hardware side is airtight.

BitBox’s approach here was proactive. Find the flaws, patch them, disclose publicly, urge users to update. That’s the playbook, and they ran it before anyone got hurt. Whether users actually upgrade in time is a different question — firmware update adoption in the hardware wallet space is notoriously uneven, and a lot of people set up a device, put it in a drawer, and don’t think about it again for months or years.

The Coldcard situation is probably the starkest reminder of what happens when a vulnerability sits unpatched and undetected. Five years is a long time for a flaw to exist in firmware that people trust with life-changing sums of money. The $112 million figure attached to it isn’t abstract.

BitBox’s two flaws didn’t reach that outcome. But they could have.

Frequently Asked Questions

What does BitBox firmware version 9.26.5 fix?

Version 9.26.5 patches two vulnerabilities: a memory corruption flaw in unconfigured BitBox02 and BitBox02 Nova Multi editions that could allow malicious firmware installation, and a Silent Payments bug that could have locked Bitcoin to unintended addresses.

Were any BitBox user funds stolen due to these vulnerabilities?

No. BitBox said there are no reported cases of exploitation or financial loss tied to either vulnerability before the patch was released.

Why It Matters

The prompt response by BitBox to address these critical vulnerabilities underscores the importance of security in the hardware wallet sector, particularly as the crypto market continues to attract both legitimate users and cyber threats. By proactively patching these flaws before any funds were compromised, BitBox reinforces trust among its user base and highlights the necessity for continuous vigilance in safeguarding digital assets, especially as the industry evolves and risks become more sophisticated. This incident serves as a reminder for all hardware wallet manufacturers to prioritize security updates and customer communication to maintain confidence in their products.

Community Trust IndexModerate Confidence
93%
Real
Real93%7%Fake
15 community signals

James Thorp

James Thorp is a passionate crypto journalist from South Africa specializing in Litecoin, Dash, and emerging digital assets. With years of experience covering the crypto markets, James delivers in-depth analysis and breaking news on altcoins, blockchain adoption, and decentralized payment networks for The Currency Analytics.

Advertisement

Related Stories