BitBox Discovers Two Critical Firmware Vulnerabilities and One Bootloader Issue, Releases Fix Update
2026-08-19 02:21
Odaily News: Swiss hardware wallet manufacturer BitBox has discovered two critical firmware vulnerabilities and one bootloader issue during an internal AI audit, and has released the Dixence security update. Exploiting these vulnerabilities would require combining phishing attacks with user unlocking of tampered devices, but BitBox stated that no user funds have been stolen and seed phrases were not compromised. The bootloader vulnerability affects older BitBox02 models, where attackers could load malicious firmware to steal assets; this issue was partially fixed in the Oeschinen update released in July. The second critical vulnerability affects the pre-initialization phase of Multi version devices and could potentially allow arbitrary code execution. The third issue involves the silent payments feature, which cannot directly steal assets but could potentially lead to funds being locked. The new Nova version is not affected.
