BitBox Patches 'Serious' Vulnerabilities in Wallets That Could Have Put Funds at Risk

cryptonews.ruPublicado a 2026-08-18Actualizado a 2026-08-18

Resumen

Hardware wallet manufacturer BitBox has released a firmware update to fix two "serious" vulnerabilities. The first flaw, present in uninitialized BitBox02 Multi and BitBox02 Nova devices, was a memory corruption issue that could allow an attacker to execute arbitrary code and install malicious firmware, potentially leading to fund loss. The second vulnerability involved the implementation of Silent Payments, which could let an attacker redirect a user's bitcoin to an unintended address, though direct theft was impossible; an attacker could then demand a ransom to assist in recovering the coins. BitBox stated it has received no reports of these vulnerabilities being exploited or of user funds being lost. This disclosure comes during a sensitive period for the self-custody sector, following a major incident involving Coldcard wallets. A previously undetected firmware vulnerability in Coldcard, related to weak random number generation for seed phrases, has reportedly led to the theft of over $112 million in bitcoin from more than 8,600 addresses. Recent data leaks from Trezor and SafePal have also exposed information for over 53,000 customers combined, though these incidents did not compromise private keys or recovery phrases. The leaks could, however, facilitate targeted phishing attacks. BitBox did not respond to requests for additional comment by the time of publication.

Hardware wallet manufacturer BitBox has released a firmware update that patches two vulnerabilities which the company described as "serious." These vulnerabilities could have allowed the installation of malicious firmware, putting users' funds at risk.

In a security notice on Monday, BitBox detailed the first vulnerability—a memory corruption issue in uninitialized BitBox02 Multi and BitBox02 Nova versions. An attacker could exploit this flaw on the host device to execute arbitrary code and install malicious firmware, potentially leading to loss of funds.

The second vulnerability affected BitBox's implementation of Silent Payments and could allow an attacker to lock bitcoin at an unintended address. While direct theft was not possible, the attacker could demand a ransom to assist in recovering the coins, BitBox stated. The company added that it had not received any reports of the vulnerabilities being exploited or of user funds being lost.

The disclosure comes at a sensitive time for the self-custody sector. Earlier, a Coldcard firmware vulnerability led to the theft of over $112 million worth of bitcoin, demonstrating how weaknesses in devices designed to protect private keys can become single points of failure.

Cointelegraph reached out to BitBox for further comment but did not receive a response prior to publication.

BitBox Patch Released Following Coldcard Bitcoin Theft and Wallet Data Leaks

The BitBox security update follows a wave of incidents affecting hardware wallets and related services.

The most damaging was the Coldcard vulnerability, linked to a firmware change made in March 2021, which remained undetected for over five years. This vulnerability affected the generation of random values for the wallet seed phrase: attackers could brute-force find the seed phrases of affected wallets and obtain their private keys without physical access.

Galaxy Research reported on Friday that losses related to Coldcard exceeded $112 million. Approximately 17,786 BTC was withdrawn from more than 8,600 addresses.

Related: Coldcard exploit pushed July losses to $247,000,000, making it the second-worst month of 2026

Recently, separate data leaks at Trezor and SafePal exposed customer and order information for over 53,000 users. Trezor linked the leak of data for 13,689 customers to its delivery service provider ShipMonk, while SafePal stated that an authorization vulnerability in an order-tracking plugin exposed information for 39,798 customers.

In none of these incidents were the devices, private keys, or recovery phrases compromised. However, both companies warned that the exposed information could facilitate targeted phishing attacks and identity impersonation attempts.

Magazine: Do Coldcard attacks mean all hardware wallets are now unsafe?

end-content

Preguntas relacionadas

QWhat were the two serious vulnerabilities identified by BitBox in their hardware wallets, and what risks did they pose?

AThe first vulnerability was a memory corruption issue affecting unconfigured BitBox02 Multi and BitBox02 Nova devices. An attacker could exploit it to execute arbitrary code and install malicious firmware, risking fund loss. The second vulnerability was in the Silent Payments implementation, which could allow an attacker to lock a user's Bitcoin to an unintended address, enabling ransom demands.

QHow did the timing of BitBox's vulnerability disclosure relate to the broader security context for self-custody wallets?

AThe disclosure came at a sensitive time for the self-custody sector, following a major incident where a firmware vulnerability in Coldcard wallets led to the theft of over $112 million in Bitcoin, highlighting how weaknesses in private key storage devices can become failure points.

QWhat was the nature and impact of the Coldcard vulnerability mentioned in the article?

AThe Coldcard vulnerability, introduced in a March 2021 firmware update and undetected for over five years, affected the random number generation for wallet seed phrases. Attackers could brute-force the seed phrases of affected wallets, obtain their private keys, and steal funds without physical access, leading to losses exceeding $112 million from over 8,600 addresses.

QWhat other hardware wallet-related security incidents were mentioned besides Coldcard and BitBox?

ARecent data leaks from Trezor and SafePal were mentioned. Trezor's leak of 13,689 customer records was linked to a delivery service provider, ShipMonk. SafePal's leak of 39,798 customer records stemmed from an authorization vulnerability in an order-tracking plugin. No devices, private keys, or recovery phrases were compromised in these incidents.

QAccording to the article, what was a potential secondary risk associated with the Trezor and SafePal data leaks, even though no private keys were stolen?

ABoth companies warned that the leaked customer information could facilitate targeted phishing attacks and impersonation attempts against the affected users.

Lecturas Relacionadas

Mass Production Timelines Shift Collectively, Is Glass Substrate Facing Its First Major Test?

The article discusses the shift in the glass substrate industry from initial announcements to practical delivery and reliability testing. In mid-to-late 2026, key developments include Intel and Lens Technology advancing AI-era glass substrate packaging cooperation, Avaco launching a TGV pilot line in South Korea, and reports that Samsung Electro-Mechanics is facing delays, potentially pushing mass production beyond 2028. The core challenge has moved from material comparisons to rigorous customer reliability certifications, focusing on thermal cycling, humidity resistance, and stable electrical performance post-processing. Samsung Electro-Mechanics' reported delay, linked to client sample reliability bottlenecks, reflects a broader industry trend where timelines are being adjusted. Other players like SKC/Absolics, LG Innotek, and DNP are also targeting initial supply systems or pilot lines between 2027-2028, with mainstream adoption potentially post-2030. The delays highlight that the current hurdle is supply-side technical maturity—particularly achieving stable yields and passing client certifications—rather than a lack of demand driven by AI and HPC. The collaboration between Intel and Lens Technology focuses on establishing design and verification standards. Meanwhile, Japanese firms like Shinko Electric and DNP are progressing with multi-layer wiring and stress control. Chinese panel makers, led by BOE, are rapidly entering with automated pilot lines and customer testing. On the material side, companies like Corning are exploring glass substrates for co-packaged optics (CPO), potentially offering an earlier application path than core substrates. Ultimately, the central barrier is TGV (Through Glass Via) yield, currently around 60-70%, lower than organic substrates, with higher costs due to glass brittleness and process complexity. The industry's current phase represents its first major test in transitioning from lab R&D to volume manufacturing, with success hinging on overcoming these yield and certification challenges.

marsbitHace 7 min(s)

Mass Production Timelines Shift Collectively, Is Glass Substrate Facing Its First Major Test?

marsbitHace 7 min(s)

Crypto Bull Is Back, Which Assets Bounced the Hardest?

The cryptocurrency market experienced a significant surge last week, with Bitcoin rallying over 26% to nearly $79,500, its strongest weekly gain since March 2023, fueling discussions of a renewed bull market. This rebound highlighted several key market dynamics. First, short-term directional shifts are increasingly tied to U.S. policy cycles. The rally was driven by two major catalysts: the U.S. Treasury's announcement to increase long-term bond buybacks, easing macro liquidity pressures, and former President Trump's push for clearer crypto legislation, boosting regulatory certainty and risk appetite. Second, Bitcoin spot ETFs solidified their role as a leading market indicator. In the week ending August 21, U.S. Bitcoin and Ethereum spot ETFs saw a combined net inflow of $2.6 billion, the highest since October 2025, signaling strong institutional re-entry. Third, the rally followed a clear capital rotation pattern: Bitcoin's breakout ignited broader gains, with Ethereum (up nearly 30%), major altcoins, and meme coins sequentially posting larger percentage increases. Analysis of the top performers among the top 50 altcoins by market cap revealed the week's biggest gainers: ENA (Ethena) led with a 100.75% surge, fueled by a Coinbase partnership. It was followed by PUMP (Pump.fun, up 88-99%), STX (Stacks, up 82-94%), TRUMP (Official Trump, up 79-91%), and ZEC (Zcash, up 75.15%), which uniquely reached a new all-time high. Meme coins like BOME on Solana also saw explosive gains, exemplifying the high-risk, high-reward sentiment. The rally illustrated a clear path: Bitcoin set the stage, major coins like Ethereum led the charge, and altcoins/meme coins delivered the most explosive returns, mapping the gradient of returning market enthusiasm.

marsbitHace 20 min(s)

Crypto Bull Is Back, Which Assets Bounced the Hardest?

marsbitHace 20 min(s)

Wuhan is About to Witness Its Largest IPO in History

Wuhan is poised for its largest-ever IPO as Yangtze Memory Technologies Co., Ltd. (YMTC) has officially applied for a listing on the Shanghai Stock Exchange's STAR Market, seeking to raise 33 billion yuan. The domestic leader in 3D NAND flash memory chips completed its IPO辅导 (tutoring) process in a record three months, with market expectations valuing the company at 300 billion yuan or higher. YMTC's roots trace back to 2006 with the founding of Wuhan Xinxin. After surviving the global financial crisis and periods of operational difficulty, the company was formally established in 2016 through a joint investment involving Tsinghua Unigroup, the National Integrated Circuit Industry Investment Fund (the "Big Fund"), and local Hubei government funds. With a distinct "national team" background, its major shareholders include provincial and municipal state-owned assets committees and the Big Fund. Based in Wuhan's Optics Valley (East Lake High-tech Development Zone), YMTC's potential listing highlights the region's rise as a tech hub. Optics Valley is already home to 72 listed companies and has ambitious plans to exceed 100 by 2030. The zone recently established four industry-focused母基金 (mother funds) totaling 18 billion yuan to further boost sectors like integrated circuits and optoelectronics. YMTC's IPO would complete the "Optics Valley Seven Stars," a group of leading local optoelectronic and communication giants.

marsbitHace 20 min(s)

Wuhan is About to Witness Its Largest IPO in History

marsbitHace 20 min(s)

Banks and Regulators Join Pilot Project to Test Quantum-Resistant Crypto Transfers

Banks and financial regulators from Europe, the Middle East, and Asia have joined a pilot project to test quantum-resistant crypto infrastructure for digital asset wallets and on-chain transactions. The initiative, announced by the Responsible Fintech Institute and infrastructure provider Safeheron, will use NEAR's quantum-resistant testnet. It will employ the ML-DSA-65 post-quantum digital signature standard, recently finalized by the U.S. National Institute of Standards and Technology (NIST). Participating regulators include the Abu Dhabi Global Market, Bhutan's Gelphu Financial Services Authority, and Malta's Financial Services Authority. Financial institutions involved are Bison Bank and DK Bank. In the pilot, banks will test wallet creation and transactions in a unified application environment, while regulators will initially observe and later contribute to governance mechanisms. The organizers plan to publish a technical paper detailing the research, protocol design, and test results, eventually open-sourcing the core technology. This effort comes as financial authorities prepare for the advent of quantum computers, which threaten current public-key cryptography. For instance, the Hong Kong Monetary Authority aims for the territory's banking sector to be fully prepared for quantum-related security risks by 2030. The Bank for International Settlements (BIS) also recommended in a 2025 document that financial institutions begin a coordinated, phased transition to post-quantum systems.

cryptonews.ruHace 22 min(s)

Banks and Regulators Join Pilot Project to Test Quantum-Resistant Crypto Transfers

cryptonews.ruHace 22 min(s)

Trading

Spot
活动图片