BitBox Patches Two Severe Firmware Vulnerabilities Before Any Funds Were Stolen, the Third Hardware Wallet Scare This Month

SECURITY

Two Severe Flaws Caught Internally

Swiss hardware wallet maker BitBox released firmware version 9.26.5, the Dixence update, on August 17, 2026, patching two vulnerabilities the company described as severe. The first affected Multi editions of the BitBox02 and BitBox02 Nova when a device had not yet been configured with a wallet. A malicious host connected to an uninitialised device could trigger memory corruption and execute arbitrary code, potentially installing malicious firmware without the user’s knowledge and putting stored funds at risk.

The second vulnerability affected the implementation of Silent Payments, a privacy feature designed to allow Bitcoin recipients to publish a static address without revealing transaction history. The flaw could have allowed an attacker to lock Bitcoin to an unintended address, opening the door to a ransom scenario where a victim would need to pay the attacker to recover access to their coins. BitBox confirmed no reports of either vulnerability being exploited in the wild and no user funds have been lost, noting that the flaws were identified using frontier AI models during an internal audit.

The Third Scare in One Month

The disclosure does not exist in isolation. It arrives in the same month as the Coldcard exploit that saw approximately 1,800 BTC drained from roughly 500 users through a five-year-old firmware flaw, making it the largest hardware wallet theft of 2026. SafePal disclosed a data breach on August 16 exposing the personal information of nearly 40,000 customers, including names, home addresses, phone numbers, and purchase details. Three hardware wallet security incidents in a single month is unprecedented in the space.

The critical difference with BitBox is timing: the vulnerabilities were caught and patched before any exploitation occurred. Coldcard’s flaw was discovered only after funds had already been stolen. SafePal’s breach exposed customer data that has already been used in targeted phishing attacks. BitBox’s internal audit caught the problem before the damage was done, but the pattern across all three incidents raises the same question.

What Bitcoin Holders Should Do

BitBox is urging all users to update their firmware to version 9.26.5 through the official BitBoxApp, ideally by clicking the in-app update prompt rather than searching online for the update file. Downloading firmware from any source other than the official app increases the risk of installing a compromised version, which is precisely the attack vector the first vulnerability would have enabled.

The broader lesson from August 2026 is not that hardware wallets are broken. It is that the security supply chain behind self-custody tools is under more pressure than it has ever been, with AI-assisted attack methods accelerating the pace at which vulnerabilities are discovered and exploited. The teams behind these devices need to find and fix flaws faster than attackers can weaponise them. BitBox managed it this time. The question is whether the industry as a whole can sustain that pace.

ENJOYED THIS ARTICLE?Support the authorSend a zap over Lightning or on-chain