BitBox Patches Severe Hardware Wallet Vulnerabilities, Urging All Users to Update Firmware Promptly

The Coldcard vulnerability traced to a March 2021 firmware change targeted wallet-seed randomness. Attackers could brute-force affected seeds and derive private keys without physical access, with losses exceeding $112 million (about 1,778.6 BTC across more than 8,600 addresses).
The BitBox02 vulnerability also affected the Nova variant in addition to Multi editions, with a memory-corruption flaw that could be exploited when the device wallet was not configured.
Broader ecosystem risk is highlighted by data breaches affecting other hardware-wallet makers, including Trezor and SafePal, exposing customer and order information for more than 53,000 users.
Cointelegraph reported that BitBox disclosed the vulnerabilities and that reporters attempted to contact BitBox for comment but did not receive a response prior to publication.
Hardware wallet maker BitBox has patched two severe security flaws in its BitBox02 devices, urging all users to update immediately. Crypto News reported that the vulnerabilities could allow attackers to install malicious firmware or lock Bitcoin to an unintended address — though no known exploits or losses have occurred.
The company released firmware version 9.26.5 to fix both issues. Crypto.news noted that the flaws affected multiple BitBox02 variants, including Multi and Nova editions.
The first vulnerability was a memory corruption bug. It hit BitBox02 Multi and Nova editions when no wallet was configured on the device. KuCoin reported that an attacker exploiting this flaw could achieve arbitrary code execution — meaning they could run any code they wanted on the device. That opens the door to installing malicious firmware.
Memory corruption means a program writes data to the wrong place in memory. Done on purpose, it can hijack a device's behavior. In this case, the risk was highest when users had not yet set up their wallet — a window that exists for new or reset devices.
The second vulnerability involved Silent Payments, a Bitcoin privacy feature. Crypto.news explained that a malicious host — like a compromised computer — could manipulate the process. The result: Bitcoin sent to an address the user never intended. No direct theft is possible, but attackers could use this to pressure victims into paying a ransom to recover access.
BitBox stressed that no funds can be directly stolen through this flaw. Still, locking coins to an unspendable address is serious. Users could lose access to their Bitcoin without a way to reverse it, making ransom demands a real threat.
The BitBox disclosure comes as the hardware wallet industry faces growing scrutiny. A separate vulnerability in Coldcard — traced to a March 2021 firmware change — targeted the randomness used to generate wallet seeds. Attackers could brute-force affected seeds and derive private keys without ever touching the device. Losses linked to that flaw exceeded $112 million, spanning more than 1,778 BTC across over 8,600 addresses.
Head Topics reported that data breaches have also hit Trezor and SafePal, exposing customer and order information for more than 53,000 users. These incidents show that hardware wallets, once seen as near-impenetrable, face real-world threats at every layer — from firmware bugs to supply chain data leaks.
BitBox says no users were harmed by either vulnerability. The company disclosed the flaws publicly and released firmware 9.26.5 as a direct fix. BigGo Finance reported that the update addresses both the memory corruption bug and the Silent Payments flaw in one patch.
Users should update their device firmware now. To do so, connect the BitBox02 to its companion app and follow the on-screen update prompt. Keeping firmware current is the single most effective defense against this class of vulnerability. BitBox did not respond to press requests for comment before publication, according to Crypto News.
Publishers
10
Articles
10
Reach
20