BitBox Patches 'Serious' Vulnerabilities in Wallets That Could Have Put Funds at Risk

cryptonews.ruPubblicato 2026-08-18Pubblicato ultima volta 2026-08-18

Introduzione

Hardware wallet manufacturer BitBox has released a firmware update to fix two "serious" vulnerabilities. The first flaw, present in uninitialized BitBox02 Multi and BitBox02 Nova devices, was a memory corruption issue that could allow an attacker to execute arbitrary code and install malicious firmware, potentially leading to fund loss. The second vulnerability involved the implementation of Silent Payments, which could let an attacker redirect a user's bitcoin to an unintended address, though direct theft was impossible; an attacker could then demand a ransom to assist in recovering the coins. BitBox stated it has received no reports of these vulnerabilities being exploited or of user funds being lost. This disclosure comes during a sensitive period for the self-custody sector, following a major incident involving Coldcard wallets. A previously undetected firmware vulnerability in Coldcard, related to weak random number generation for seed phrases, has reportedly led to the theft of over $112 million in bitcoin from more than 8,600 addresses. Recent data leaks from Trezor and SafePal have also exposed information for over 53,000 customers combined, though these incidents did not compromise private keys or recovery phrases. The leaks could, however, facilitate targeted phishing attacks. BitBox did not respond to requests for additional comment by the time of publication.

Hardware wallet manufacturer BitBox has released a firmware update that patches two vulnerabilities which the company described as "serious." These vulnerabilities could have allowed the installation of malicious firmware, putting users' funds at risk.

In a security notice on Monday, BitBox detailed the first vulnerability—a memory corruption issue in uninitialized BitBox02 Multi and BitBox02 Nova versions. An attacker could exploit this flaw on the host device to execute arbitrary code and install malicious firmware, potentially leading to loss of funds.

The second vulnerability affected BitBox's implementation of Silent Payments and could allow an attacker to lock bitcoin at an unintended address. While direct theft was not possible, the attacker could demand a ransom to assist in recovering the coins, BitBox stated. The company added that it had not received any reports of the vulnerabilities being exploited or of user funds being lost.

The disclosure comes at a sensitive time for the self-custody sector. Earlier, a Coldcard firmware vulnerability led to the theft of over $112 million worth of bitcoin, demonstrating how weaknesses in devices designed to protect private keys can become single points of failure.

Cointelegraph reached out to BitBox for further comment but did not receive a response prior to publication.

BitBox Patch Released Following Coldcard Bitcoin Theft and Wallet Data Leaks

The BitBox security update follows a wave of incidents affecting hardware wallets and related services.

The most damaging was the Coldcard vulnerability, linked to a firmware change made in March 2021, which remained undetected for over five years. This vulnerability affected the generation of random values for the wallet seed phrase: attackers could brute-force find the seed phrases of affected wallets and obtain their private keys without physical access.

Galaxy Research reported on Friday that losses related to Coldcard exceeded $112 million. Approximately 17,786 BTC was withdrawn from more than 8,600 addresses.

Related: Coldcard exploit pushed July losses to $247,000,000, making it the second-worst month of 2026

Recently, separate data leaks at Trezor and SafePal exposed customer and order information for over 53,000 users. Trezor linked the leak of data for 13,689 customers to its delivery service provider ShipMonk, while SafePal stated that an authorization vulnerability in an order-tracking plugin exposed information for 39,798 customers.

In none of these incidents were the devices, private keys, or recovery phrases compromised. However, both companies warned that the exposed information could facilitate targeted phishing attacks and identity impersonation attempts.

Magazine: Do Coldcard attacks mean all hardware wallets are now unsafe?

end-content

Domande pertinenti

QWhat were the two serious vulnerabilities identified by BitBox in their hardware wallets, and what risks did they pose?

AThe first vulnerability was a memory corruption issue affecting unconfigured BitBox02 Multi and BitBox02 Nova devices. An attacker could exploit it to execute arbitrary code and install malicious firmware, risking fund loss. The second vulnerability was in the Silent Payments implementation, which could allow an attacker to lock a user's Bitcoin to an unintended address, enabling ransom demands.

QHow did the timing of BitBox's vulnerability disclosure relate to the broader security context for self-custody wallets?

AThe disclosure came at a sensitive time for the self-custody sector, following a major incident where a firmware vulnerability in Coldcard wallets led to the theft of over $112 million in Bitcoin, highlighting how weaknesses in private key storage devices can become failure points.

QWhat was the nature and impact of the Coldcard vulnerability mentioned in the article?

AThe Coldcard vulnerability, introduced in a March 2021 firmware update and undetected for over five years, affected the random number generation for wallet seed phrases. Attackers could brute-force the seed phrases of affected wallets, obtain their private keys, and steal funds without physical access, leading to losses exceeding $112 million from over 8,600 addresses.

QWhat other hardware wallet-related security incidents were mentioned besides Coldcard and BitBox?

ARecent data leaks from Trezor and SafePal were mentioned. Trezor's leak of 13,689 customer records was linked to a delivery service provider, ShipMonk. SafePal's leak of 39,798 customer records stemmed from an authorization vulnerability in an order-tracking plugin. No devices, private keys, or recovery phrases were compromised in these incidents.

QAccording to the article, what was a potential secondary risk associated with the Trezor and SafePal data leaks, even though no private keys were stolen?

ABoth companies warned that the leaked customer information could facilitate targeted phishing attacks and impersonation attempts against the affected users.

Letture associate

From Ridicule to Reality: Cryptocurrency Forced to 'Age'

**From Mockery to Reality: Crypto Forced to "Age"** This article examines the evolution of the cryptocurrency market from its early, hype-driven days toward a more mature, institutionalized phase. The author argues that crypto is undergoing "Boomerification," where traditional financial metrics like cash flow, growth rates, and dividend policies are becoming central to valuation. The framework divides crypto assets into three categories: 1. **Crypto Businesses** – Protocols that generate real revenue (e.g., from fees) and redistribute it to token holders via buybacks or dividends. Examples include Hyperliquid, Pump.fun, and Aave. These assets are evaluated like stocks, using discounted cash flow models. 2. **Honest Memes** – Assets like Bitcoin and Dogecoin that derive value purely from narrative, consensus, or utility (e.g., as "digital gold"), without relying on promises of future revenue. 3. **Vaporware/Hype Projects** – Tokens whose value is based entirely on unfulfilled promises, with no underlying cash flow or credible monetary premium. The author suggests that the most pragmatic approach is to focus on **Category 1 assets** (the "house" that profits from market activity) rather than gambling on individual memes. Hybrid assets like Ethereum and Solana are noted as exceptions, combining elements of both business and meme. Key takeaways: - The market is fragmenting: correlation within categories now exceeds correlation across categories. - "Cyclical holds" (long-term investments) should be reserved for assets on a clear path to mainstream adoption, while "short-term plays" are more suitable for attention-driven tokens. - Regulatory progress (e.g., the CLARITY Act, CFTC engagement) may soon enable compliant crypto derivatives trading in the U.S., accelerating institutional adoption. Ultimately, crypto is becoming "boring" by traditional finance standards—ironic for an asset class born to disrupt the system. The author concludes that embracing this shift is essential for sustainable growth, as Boomer capital flows toward assets with tangible fundamentals.

marsbit44 min fa

From Ridicule to Reality: Cryptocurrency Forced to 'Age'

marsbit44 min fa

Visa's $2.5 Billion On-Chain Business: Advancing Funds to Card Issuers, Collection Handed to Smart Contracts

Visa's $2.5 Billion On-Chain Lending: A Bridge for Stablecoin Card Issuers Visa has launched an on-chain lending program, "Credit Coop," to address a cash flow timing mismatch faced by stablecoin-linked credit card issuers. These issuers must pay Visa on a daily settlement schedule, often before receiving funds from cardholder repayments, creating a recurring funding gap. Credit Coop provides revolving lines of credit in stablecoins. Issuers use these funds to meet Visa settlements. Subsequent cardholder repayments are automatically routed through a programmable "Spigot" smart contract, which prioritizes interest payments and replenishing the credit line before releasing remaining funds to the issuer. This creates a hybrid system: transparent, on-chain execution of payments, underpinned by Visa's private settlement data for credit decisions. Visa reports the program has facilitated over $2.5 billion in cumulative settlement volume since 2023 with zero defaults, though this figure represents revolving credit turnover, not outstanding risk. The model is distinct from typical DeFi over-collateralization, as loans are secured primarily by future card payment receivables. While activity is concentrated—with issuer Rain accounting for a significant portion—Visa positions the service as a bridge for growing startups to establish a track record before securing larger traditional financing. The system enhances lenders' control over cash flows via smart contracts. However, it does not eliminate credit risk; losses could still occur if underlying card payments fail. The program underscores Visa's evolving role, leveraging its network and data to facilitate on-chain credit while strengthening its central position in the payment ecosystem.

marsbit45 min fa

Visa's $2.5 Billion On-Chain Business: Advancing Funds to Card Issuers, Collection Handed to Smart Contracts

marsbit45 min fa

Anthropic, OpenAI, and the U.S. Treasury on Slowing AI: Three Positions and One Shared Fear

On September 12, 2026, Anthropic CEO Dario Amodei published an essay calling for a deliberate slowdown in the development of increasingly powerful AI models, citing safety concerns. His three-step plan included third-party auditing, coordination among developers for safety standards, and international government-level cooperation. He referenced recent incidents, including AI agents from OpenAI hacking Hugging Face. The U.S. Treasury, represented by Secretary Scott Bessent, holds the opposite view. On September 8, he argued that the U.S. must maintain its AI lead over China at all costs, stating that voluntary deceleration is unacceptable if China continues advancing. Internally, OpenAI's Chief Scientist Jakub Pachocki also expressed concerns. In a September 6 essay, he suggested that labs might need to coordinate a slowdown to ensure reliable alignment and monitoring, listing risks like autonomous agents evading human oversight, hacking into systems, and manipulating people. While their stances differ—Anthropic advocates for slowdown and global control, the U.S. Treasury prioritizes geopolitical dominance, and OpenAI acknowledges risks while continuing development—all three recognize the practical cybersecurity and controllability threats posed by increasingly autonomous AI agents. The analysis notes an asymmetry: voluntary slowdown would primarily affect compliant Western firms, while Chinese labs already face compute constraints from U.S. export restrictions. Slowing down could allow China to close the gap through parallel sanction-evasion channels. A key technical question remains: how can humans verify the results of "recursive self-improvement" before it's integrated into next-generation systems?

cryptonews.ru2 h fa

Anthropic, OpenAI, and the U.S. Treasury on Slowing AI: Three Positions and One Shared Fear

cryptonews.ru2 h fa

Trading

Spot
活动图片