LIVE
BTC$64,452 0.40%ETH$1,922 1.20%SOL$77.45 2.20%XRP$1.00 0.90%BNB$602.34 0.20%ADA$0.1748 0.70%DOGE$0.0702 0.40%AVAX$6.31 0.10%LINK$9.76 3.10%MATIC$0.1262 18.60%BTC$64,452 0.40%ETH$1,922 1.20%SOL$77.45 2.20%XRP$1.00 0.90%BNB$602.34 0.20%ADA$0.1748 0.70%DOGE$0.0702 0.40%AVAX$6.31 0.10%LINK$9.76 3.10%MATIC$0.1262 18.60%
LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored
Bitcoin World News
LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored
Bitcoin

BitBox Patches Severe Wallet Flaws That Could Put Bitcoin Funds at Risk

BitBox has patched two severe vulnerabilities affecting BitBox02 devices and its Silent Payments implementation. The company said it has received no reports of exploitation or user fund losses.

4 min read
BitBox Patches Severe Wallet Flaws That Could Put Bitcoin Funds at Risk

Hardware wallet manufacturer BitBox has released a firmware update addressing two vulnerabilities it classified as “severe,” including a flaw that could potentially allow malicious firmware to be installed on certain devices.

The company urged users to update affected devices to firmware version 9.26.5 as part of its security response.

In a security disclosure published Monday, BitBox said one vulnerability involved memory corruption affecting certain BitBox02 Multi and BitBox02 Nova devices that had not yet been configured with a wallet.

LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored

A malicious host could potentially exploit the vulnerability to execute arbitrary code. In the worst-case scenario, that could allow malicious firmware to be installed and potentially put users’ funds at risk.

BitBox said it has not received any reports that the vulnerability was exploited or that users lost funds.

BitBox patches Silent Payments vulnerability

The second vulnerability involved BitBox’s implementation of Bitcoin Silent Payments.

According to BitBox, a malicious host could exploit the issue to cause Bitcoin to be sent to an unintended address.

The vulnerability did not allow an attacker to directly steal the affected Bitcoin. However, BitBox said an attacker could potentially demand a ransom in exchange for helping recover the funds.

The company has also patched this issue as part of firmware version 9.26.5.

BitBox’s full technical disclosure provides additional information about the vulnerabilities and the affected products.

BitBox security disclosure and firmware update

Users urged to update BitBox devices

The disclosure highlights an important risk associated with hardware wallets: while private keys are designed to remain isolated from potentially compromised computers, vulnerabilities in wallet firmware or device software can still create security risks.

The BitBox flaws required interaction with a potentially malicious host, meaning the threat model involves the computer or environment connected to the hardware wallet.

BitBox said the affected users should install the latest firmware to protect against the vulnerabilities.

For Bitcoin holders using hardware wallets, keeping device firmware and companion applications updated is an important part of maintaining self-custody security.

BitBox update follows major hardware-wallet incidents

The BitBox disclosure comes as the hardware-wallet sector faces renewed scrutiny following several security incidents.

One of the most significant recent cases involved Coldcard, where a firmware vulnerability was linked to the theft of a substantial amount of Bitcoin.

Galaxy Research estimated that losses associated with the Coldcard incident had reached at least 1,778.6 BTC, worth more than $112 million based on the report's valuation.

Galaxy Research's analysis of the Coldcard incident

The vulnerability was reportedly connected to a change introduced years earlier and involved weaknesses affecting wallet-seed generation. Attackers were able to derive private keys from affected wallets without requiring physical access to the devices.

The incident demonstrated how a software or firmware weakness can undermine the security assumptions behind hardware-based self-custody.

Trezor and SafePal users also faced data exposure

Hardware-wallet security concerns have extended beyond vulnerabilities capable of affecting private keys.

Separate data breaches involving Trezor and SafePal exposed customer and order information belonging to tens of thousands of users.

The incidents did not compromise private keys or recovery phrases, but exposed customer information can create a different type of security threat.

Attackers can use names, contact information and purchasing records to conduct targeted phishing campaigns or impersonate wallet providers.

That makes operational security important even when a hardware wallet itself remains technically uncompromised.

Hardware wallets remain a key part of Bitcoin self-custody

Hardware wallets are designed to keep private keys isolated from internet-connected devices, reducing the attack surface compared with keeping Bitcoin keys on ordinary computers or phones.

However, they are not completely immune to vulnerabilities.

Firmware bugs, malicious host interactions, supply-chain attacks and compromised third-party services can all introduce additional risks.

The recent incidents involving multiple wallet manufacturers reinforce the importance of maintaining updated firmware, verifying official software and being cautious about unexpected wallet-related communications.

Users should also avoid entering their recovery phrases into websites, applications or devices that request them unexpectedly.

What Bitcoin users should do

BitBox users should check whether their devices are affected and update to firmware 9.26.5 through BitBox's official software and update process.

Bitcoin holders using other hardware wallets should likewise monitor official security advisories from their wallet manufacturers and install security updates when recommended.

At the same time, users should remain alert to phishing attempts following security disclosures. Attackers sometimes exploit public vulnerability announcements by pretending to offer emergency recovery tools or security patches.

The BitBox disclosure does not indicate that Bitcoin itself has been compromised.

Instead, it demonstrates that the security of self-custodied Bitcoin depends not only on the Bitcoin network, but also on the hardware, firmware and software used to control private keys.

For now, BitBox says it has found no evidence that either newly disclosed vulnerability resulted in stolen funds. The release of firmware 9.26.5 is intended to close the identified attack paths before they can be exploited.

Disclaimer

This article is for informational purposes only and does not constitute financial, investment, or trading advice. Cryptocurrency markets are highly volatile and carry significant risk. Always conduct your own research (DYOR) and consult a qualified financial advisor before making investment decisions. Past performance does not guarantee future results.

The crypto brief, in your inbox

BTC, markets, and the stories that moved crypto — daily, no noise.

No spam, ever. Unsubscribe in one click.

Related Bitcoin News

Comments (0)

Comments are reviewed before publishing.

No comments yet. Be the first.

LF Wallet promotional banner offering up to 1,000,000 LF rewards with Google Play and App Store download options.Sponsored