BitBox Patches 'Serious' Vulnerabilities in Wallets That Could Have Put Funds at Risk

cryptonews.ruPubblicato 2026-08-18Pubblicato ultima volta 2026-08-18

Introduzione

Hardware wallet manufacturer BitBox has released a firmware update to fix two "serious" vulnerabilities. The first flaw, present in uninitialized BitBox02 Multi and BitBox02 Nova devices, was a memory corruption issue that could allow an attacker to execute arbitrary code and install malicious firmware, potentially leading to fund loss. The second vulnerability involved the implementation of Silent Payments, which could let an attacker redirect a user's bitcoin to an unintended address, though direct theft was impossible; an attacker could then demand a ransom to assist in recovering the coins. BitBox stated it has received no reports of these vulnerabilities being exploited or of user funds being lost. This disclosure comes during a sensitive period for the self-custody sector, following a major incident involving Coldcard wallets. A previously undetected firmware vulnerability in Coldcard, related to weak random number generation for seed phrases, has reportedly led to the theft of over $112 million in bitcoin from more than 8,600 addresses. Recent data leaks from Trezor and SafePal have also exposed information for over 53,000 customers combined, though these incidents did not compromise private keys or recovery phrases. The leaks could, however, facilitate targeted phishing attacks. BitBox did not respond to requests for additional comment by the time of publication.

Hardware wallet manufacturer BitBox has released a firmware update that patches two vulnerabilities which the company described as "serious." These vulnerabilities could have allowed the installation of malicious firmware, putting users' funds at risk.

In a security notice on Monday, BitBox detailed the first vulnerability—a memory corruption issue in uninitialized BitBox02 Multi and BitBox02 Nova versions. An attacker could exploit this flaw on the host device to execute arbitrary code and install malicious firmware, potentially leading to loss of funds.

The second vulnerability affected BitBox's implementation of Silent Payments and could allow an attacker to lock bitcoin at an unintended address. While direct theft was not possible, the attacker could demand a ransom to assist in recovering the coins, BitBox stated. The company added that it had not received any reports of the vulnerabilities being exploited or of user funds being lost.

The disclosure comes at a sensitive time for the self-custody sector. Earlier, a Coldcard firmware vulnerability led to the theft of over $112 million worth of bitcoin, demonstrating how weaknesses in devices designed to protect private keys can become single points of failure.

Cointelegraph reached out to BitBox for further comment but did not receive a response prior to publication.

BitBox Patch Released Following Coldcard Bitcoin Theft and Wallet Data Leaks

The BitBox security update follows a wave of incidents affecting hardware wallets and related services.

The most damaging was the Coldcard vulnerability, linked to a firmware change made in March 2021, which remained undetected for over five years. This vulnerability affected the generation of random values for the wallet seed phrase: attackers could brute-force find the seed phrases of affected wallets and obtain their private keys without physical access.

Galaxy Research reported on Friday that losses related to Coldcard exceeded $112 million. Approximately 17,786 BTC was withdrawn from more than 8,600 addresses.

Related: Coldcard exploit pushed July losses to $247,000,000, making it the second-worst month of 2026

Recently, separate data leaks at Trezor and SafePal exposed customer and order information for over 53,000 users. Trezor linked the leak of data for 13,689 customers to its delivery service provider ShipMonk, while SafePal stated that an authorization vulnerability in an order-tracking plugin exposed information for 39,798 customers.

In none of these incidents were the devices, private keys, or recovery phrases compromised. However, both companies warned that the exposed information could facilitate targeted phishing attacks and identity impersonation attempts.

Magazine: Do Coldcard attacks mean all hardware wallets are now unsafe?

end-content

Domande pertinenti

QWhat were the two serious vulnerabilities identified by BitBox in their hardware wallets, and what risks did they pose?

AThe first vulnerability was a memory corruption issue affecting unconfigured BitBox02 Multi and BitBox02 Nova devices. An attacker could exploit it to execute arbitrary code and install malicious firmware, risking fund loss. The second vulnerability was in the Silent Payments implementation, which could allow an attacker to lock a user's Bitcoin to an unintended address, enabling ransom demands.

QHow did the timing of BitBox's vulnerability disclosure relate to the broader security context for self-custody wallets?

AThe disclosure came at a sensitive time for the self-custody sector, following a major incident where a firmware vulnerability in Coldcard wallets led to the theft of over $112 million in Bitcoin, highlighting how weaknesses in private key storage devices can become failure points.

QWhat was the nature and impact of the Coldcard vulnerability mentioned in the article?

AThe Coldcard vulnerability, introduced in a March 2021 firmware update and undetected for over five years, affected the random number generation for wallet seed phrases. Attackers could brute-force the seed phrases of affected wallets, obtain their private keys, and steal funds without physical access, leading to losses exceeding $112 million from over 8,600 addresses.

QWhat other hardware wallet-related security incidents were mentioned besides Coldcard and BitBox?

ARecent data leaks from Trezor and SafePal were mentioned. Trezor's leak of 13,689 customer records was linked to a delivery service provider, ShipMonk. SafePal's leak of 39,798 customer records stemmed from an authorization vulnerability in an order-tracking plugin. No devices, private keys, or recovery phrases were compromised in these incidents.

QAccording to the article, what was a potential secondary risk associated with the Trezor and SafePal data leaks, even though no private keys were stolen?

ABoth companies warned that the leaked customer information could facilitate targeted phishing attacks and impersonation attempts against the affected users.

Letture associate

Domestic RF Filters, Finally Starting to Compete?

China's domestic filter industry, particularly in the challenging BAW (Bulk Acoustic Wave) segment, has reached a significant inflection point, moving from solving the "availability" problem to entering a phase of commercial competition and scale. The market is attractive, with the global mobile terminal RF filter market projected to reach $9.2 billion in 2025, and BAW filters showing strong growth. However, the sector is historically dominated by giants like Broadcom and Qorvo, protected by deep patent walls, as evidenced by lawsuits that have bankrupted competitors like Akoustis. Previously, high-frequency BAW filter production in China was nearly zero. Now, domestic players like Nous Micro, Wuhan Memsensing, Hansky, and others are forming a genuine industrial cluster, achieving mass production and shipping hundreds of millions of chips to clients. Different business models are emerging, including IDM and fab-lite approaches through partnerships with foundries like Sai Microelectronics and Runxin Sensing. A key signal of this new competitive phase is a patent lawsuit filed by Nous Micro against Wuhan Memsensing in June 2025, alleging infringement of a core BAW resonator patent. This conflict, rather than mere internal friction, underscores that the industry now has substantial products and market stakes to contest. The challenge is no longer just technical breakthrough but transforming technological leads into sustainable commercial success through superior patents, product performance, cost control, and customer acquisition. Chinese companies are finally positioned to compete for a share of this lucrative market long held by foreign leaders.

marsbit5 min fa

Domestic RF Filters, Finally Starting to Compete?

marsbit5 min fa

Zhang Lei: How He Became the Biggest Money-Maker This Year

Zhang Lei's company Pinzhun Laser (频准激光) became the biggest "meat sign" (highly profitable new share) of the year on its A-share market debut. Its stock price skyrocketed nearly 600% from its IPO price, generating potential single-lot profits of over 550,000 RMB for lucky subscribers. Founded by Zhang Lei, a 2014 Ph.D. graduate from the Shanghai Institute of Optics and Fine Mechanics, Pinzhun Laser specializes in ultra-stable, narrow-linewidth lasers critical for quantum computing. Its lasers are used by leading global research teams at Harvard, Caltech, and France's PASQAL. The company later successfully applied its core frequency conversion technology to the semiconductor sector, developing deep-ultraviolet lasers for advanced chip manufacturing and inspection. This move diversified its revenue, with semiconductor sales growing rapidly to account for over 25% of its business by 2025. The company boasts gross margins consistently above 69%. Remarkably, Pinzhun Laser required only two major external funding rounds before its IPO, a testament to its early profitability. Key strategic investors in its IPO included major downstream players like BOE,佰维存储 (BIWIN), and中微半导体 (AMEC), signaling strong industry validation. The article highlights the crucial early-stage support from Hangzhou-based capital, particularly funds associated with the Hangzhou Institute of Optics and Fine Mechanics. This "patient capital" model, part of Hangzhou's broader 300-billion-yuan industrial fund strategy, focuses on partnering with scientist-entrepreneurs through the risky valley of death from lab to market. The success of Pinzhun Laser and another Hangzhou-backed firm,宇树科技 (Unitree Robotics), showcases how this supportive ecosystem helps build leading hard-tech companies.

marsbit10 min fa

Zhang Lei: How He Became the Biggest Money-Maker This Year

marsbit10 min fa

3-Month Loss of $10 Billion, DAT Companies Begin to Return to Rationality

During the recent earnings season, major Digital Asset Treasury (DAT) companies reported staggering combined losses of approximately $10 billion for Q2 and over $30 billion for the first half, primarily due to markdowns on their bitcoin holdings. However, contrary to expectations, their stock prices have rebounded from June lows, indicating the market had already priced in these losses. The key shift is a collective return to rationality. Companies like Strategy, Sharplink, and Metaplanet are now prioritizing a new core metric: increasing the amount of crypto assets per share. This marks a departure from last year's aggressive growth-at-all-costs narrative. To achieve this, they are adopting disciplined capital allocation—issuing stock to buy crypto when trading at a premium, and halting dilution or initiating buybacks when at a discount. Some, like Strategy, have even broken "never sell" pledges to uphold this discipline. A major tool enabling this strategy is the STRC model—perpetual preferred shares offering high dividends (e.g., 12-13%) to raise fixed-income capital for purchasing bitcoin. Strive, Bitmine, and Metaplanet have launched their own variants. Sharplink pursues a different path, staking its vast Ethereum holdings to generate native yield. While the premium of DAT stocks over their underlying crypto asset value has declined and may not fully return, the model is evolving rather than ending. Stripped of hype, DAT firms are becoming actively managed, leveraged thematic funds. Their survival through massive losses and continued institutional investment (with major funds adding billions to positions during downturns) suggests the industry is maturing into a more calculated, long-term business focused on compounding crypto per share.

marsbit15 min fa

3-Month Loss of $10 Billion, DAT Companies Begin to Return to Rationality

marsbit15 min fa

PI Price Forecast Remains Stable at $0.086 as Pi Network Reforms App Economy

PI price forecast remains stable around $0.086 as it continues to trade below a key descending trendline from April. The token has been consolidating in a narrow range between $0.078 and $0.086 throughout August, with major EMAs positioned above the price indicating bearish pressure. Key resistance levels are identified at the 20-day EMA ($0.08772) and the SuperTrend indicators around $0.09-$0.10. Support sits at the current price and the August range low of $0.070. Fundamentally, Pi Network announced a major change to its App Studio pricing model, set for August 24, 2026. The fixed, subsidized rate of 0.25 Pi for app creation/editing will shift to a usage-based model reflecting actual AI service costs. Subsidized rates will remain for apps demonstrating genuine user adoption. Separately, the mandatory node protocol upgrade has reached version 26.1, with only version 27.1 remaining to complete the sequence. On-chain activity shows increased transaction volume, including patterns of repeated 0.03 Pi transfers, potentially related to testing following the protocol upgrade. The bullish scenario targets a break above the $0.08772-$0.09000 resistance cluster, opening a path toward the 50-day EMA at $0.09560. The bearish risk is a breakdown below the consolidation range, potentially testing the $0.070 support level. The conclusion notes that while fundamental developments are progressing, the price chart remains technically constrained until it can decisively break above the persistent downtrend line and key moving averages.

cryptonews.ru18 min fa

PI Price Forecast Remains Stable at $0.086 as Pi Network Reforms App Economy

cryptonews.ru18 min fa

"We have long ceased to be a crypto company": Tether CEO made a statement after KPMG audit

Stablecoin giant Tether has engaged Big Four auditor KPMG to verify its reserves, including a physical count of roughly 150 tons of gold in a Swiss vault. The audit confirmed the gold is present and that Tether's total reserves exceed its liabilities by $6.8 billion. CEO Paolo Ardoino described the process as "a physically heavy exercise" in an interview with Fortune. The audit aimed to address a long-standing conspiracy theory in the crypto world that USDT is not properly backed and could face a mass default. In a significant statement, Ardoino declared, "We haven't considered ourselves a crypto company for a long time. I think we are a digital dollar and digital gold company." He noted Tether has over 650 million users globally, with a strong focus in Africa and South America, where demand for stable digital assets is high due to recurring currency devaluations. Beyond financial services, Tether has been investing in decentralized communications, agriculture, and solar-powered kiosk networks for low-cost autonomous electricity. The company's next strategic move is to provide basic AI services to its user base in developing countries. Ardoino emphasized that even in the poorest nations, most people have a mobile phone capable of running simple AI models. The goal is to offer affordable, fundamental tools in sectors like healthcare, finance, and sports for a few dollars per month, payable via Tether or other digital payments. Ardoino expressed concern about societal inequality transforming from a wealth gap into a deeper "intellectual gap."

cryptonews.ru18 min fa

"We have long ceased to be a crypto company": Tether CEO made a statement after KPMG audit

cryptonews.ru18 min fa

Trading

Spot
活动图片