BitBox Patches 'Serious' Vulnerabilities in Wallets That Could Have Put Funds at Risk

cryptonews.ruPublished on 2026-08-18Last updated on 2026-08-18

Abstract

Hardware wallet manufacturer BitBox has released a firmware update to fix two "serious" vulnerabilities. The first flaw, present in uninitialized BitBox02 Multi and BitBox02 Nova devices, was a memory corruption issue that could allow an attacker to execute arbitrary code and install malicious firmware, potentially leading to fund loss. The second vulnerability involved the implementation of Silent Payments, which could let an attacker redirect a user's bitcoin to an unintended address, though direct theft was impossible; an attacker could then demand a ransom to assist in recovering the coins. BitBox stated it has received no reports of these vulnerabilities being exploited or of user funds being lost. This disclosure comes during a sensitive period for the self-custody sector, following a major incident involving Coldcard wallets. A previously undetected firmware vulnerability in Coldcard, related to weak random number generation for seed phrases, has reportedly led to the theft of over $112 million in bitcoin from more than 8,600 addresses. Recent data leaks from Trezor and SafePal have also exposed information for over 53,000 customers combined, though these incidents did not compromise private keys or recovery phrases. The leaks could, however, facilitate targeted phishing attacks. BitBox did not respond to requests for additional comment by the time of publication.

Hardware wallet manufacturer BitBox has released a firmware update that patches two vulnerabilities which the company described as "serious." These vulnerabilities could have allowed the installation of malicious firmware, putting users' funds at risk.

In a security notice on Monday, BitBox detailed the first vulnerability—a memory corruption issue in uninitialized BitBox02 Multi and BitBox02 Nova versions. An attacker could exploit this flaw on the host device to execute arbitrary code and install malicious firmware, potentially leading to loss of funds.

The second vulnerability affected BitBox's implementation of Silent Payments and could allow an attacker to lock bitcoin at an unintended address. While direct theft was not possible, the attacker could demand a ransom to assist in recovering the coins, BitBox stated. The company added that it had not received any reports of the vulnerabilities being exploited or of user funds being lost.

The disclosure comes at a sensitive time for the self-custody sector. Earlier, a Coldcard firmware vulnerability led to the theft of over $112 million worth of bitcoin, demonstrating how weaknesses in devices designed to protect private keys can become single points of failure.

Cointelegraph reached out to BitBox for further comment but did not receive a response prior to publication.

BitBox Patch Released Following Coldcard Bitcoin Theft and Wallet Data Leaks

The BitBox security update follows a wave of incidents affecting hardware wallets and related services.

The most damaging was the Coldcard vulnerability, linked to a firmware change made in March 2021, which remained undetected for over five years. This vulnerability affected the generation of random values for the wallet seed phrase: attackers could brute-force find the seed phrases of affected wallets and obtain their private keys without physical access.

Galaxy Research reported on Friday that losses related to Coldcard exceeded $112 million. Approximately 17,786 BTC was withdrawn from more than 8,600 addresses.

Related: Coldcard exploit pushed July losses to $247,000,000, making it the second-worst month of 2026

Recently, separate data leaks at Trezor and SafePal exposed customer and order information for over 53,000 users. Trezor linked the leak of data for 13,689 customers to its delivery service provider ShipMonk, while SafePal stated that an authorization vulnerability in an order-tracking plugin exposed information for 39,798 customers.

In none of these incidents were the devices, private keys, or recovery phrases compromised. However, both companies warned that the exposed information could facilitate targeted phishing attacks and identity impersonation attempts.

Magazine: Do Coldcard attacks mean all hardware wallets are now unsafe?

end-content

Related Questions

QWhat were the two serious vulnerabilities identified by BitBox in their hardware wallets, and what risks did they pose?

AThe first vulnerability was a memory corruption issue affecting unconfigured BitBox02 Multi and BitBox02 Nova devices. An attacker could exploit it to execute arbitrary code and install malicious firmware, risking fund loss. The second vulnerability was in the Silent Payments implementation, which could allow an attacker to lock a user's Bitcoin to an unintended address, enabling ransom demands.

QHow did the timing of BitBox's vulnerability disclosure relate to the broader security context for self-custody wallets?

AThe disclosure came at a sensitive time for the self-custody sector, following a major incident where a firmware vulnerability in Coldcard wallets led to the theft of over $112 million in Bitcoin, highlighting how weaknesses in private key storage devices can become failure points.

QWhat was the nature and impact of the Coldcard vulnerability mentioned in the article?

AThe Coldcard vulnerability, introduced in a March 2021 firmware update and undetected for over five years, affected the random number generation for wallet seed phrases. Attackers could brute-force the seed phrases of affected wallets, obtain their private keys, and steal funds without physical access, leading to losses exceeding $112 million from over 8,600 addresses.

QWhat other hardware wallet-related security incidents were mentioned besides Coldcard and BitBox?

ARecent data leaks from Trezor and SafePal were mentioned. Trezor's leak of 13,689 customer records was linked to a delivery service provider, ShipMonk. SafePal's leak of 39,798 customer records stemmed from an authorization vulnerability in an order-tracking plugin. No devices, private keys, or recovery phrases were compromised in these incidents.

QAccording to the article, what was a potential secondary risk associated with the Trezor and SafePal data leaks, even though no private keys were stolen?

ABoth companies warned that the leaked customer information could facilitate targeted phishing attacks and impersonation attempts against the affected users.

Related Reads

Google and Meta Called Out for Benchmark Gaming

Recently, analysis firm SemiAnalysis accused tech giants Google and Meta of "benchmark gaming" with their AI models Gemini 3.8 Flash and Muse Spark 1.3. The accusation stems from a dramatic performance drop between two versions of the Terminal-Bench evaluation for AI agents. On the older, public Terminal-Bench 2.1, Gemini 3.8 Flash scored 89.4, ranking second and beating GPT-6 Astra, while Muse Spark 1.3 scored 88.8. However, on the newly released, more secure Terminal-Bench 4.0, their scores plummeted to 19.1 and approximately 33.3 respectively, far behind competitors. SemiAnalysis argues this indicates "benchmark contamination," where companies train models not on the public test questions themselves, but on expensive, privately purchased training data specifically designed to mimic the benchmark's style. This has evolved into a lucrative industry, with specialized firms selling tailored training tasks for thousands to hundreds of thousands of dollars. The article specifically points to Datacurve, a company that both sells expert coding data and runs its own benchmark (DeepSWE), where the accused models also performed well. Meta's Chief AI Officer, Alexandr Wang, dismissed the claims as a "silly argument," pointing out similar performance drops for other models like GPT-5.6 Sol. He stated Meta never claimed Muse Spark 1.3 was as powerful as top-tier models, only that it offered better value. The report concludes that this is the inevitable fate of all high-quality public benchmarks—they become "gamed" over time. The proposed solution of private, high-quality benchmarks comes with a significant downside: it would erode public transparency, turning open rankings into marketing tools and leaving developers without a common, fair measure to compare AI models.

marsbit2h ago

Google and Meta Called Out for Benchmark Gaming

marsbit2h ago

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

Coinbase co-founder Fred Ehrsam is venturing into the oil fields of Venezuela, a surprising shift for a prominent figure in the digital asset space. Through his company Primavera Infinita, he recently secured a production contract for the Budare-Elotes block with Venezuela's state oil firm PDVSA. This move into a politically volatile, sanction-scarred country highlights a bet on high returns from its reopening under new leadership and shifting U.S. foreign policy. Ehrsam’s investment reflects a venture capital-style appetite for risk, targeting assets deeply discounted by political uncertainty. He is not alone; smaller, politically connected U.S. firms like Aspect Holdings and Hunt Oil are also entering, while established giants like ExxonMobil remain cautious due to past expropriations. To manage the complex, capital-intensive nature of oil, Ehrsam is assembling a professional team. This trend extends beyond Ehrsam. Other crypto wealth, like BitMEX's Arthur Hayes and Tether, is diversifying into traditional hard assets—energy, metals, and agriculture—seeking physical scarcity as a long-term anchor. Tether, for instance, took a controlling stake in agricultural giant Adecoagro. These moves signify crypto capital's evolving interest: not just tokenizing real-world assets (RWA), but directly acquiring and operating them. Ultimately, Ehrsam's gamble is less on oil geology and more on the duration of Venezuela's current political window. It underscores a broader narrative where digital-era wealth seeks stability and scale in the physical world's most traditional, immovable resources.

marsbit2h ago

Crypto's Nouveau Riche Strikes Gold in the Real World: Coinbase Co-founder's Venezuelan Oil Field Adventure

marsbit2h ago

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

Title: Refuting the "Ethereum Abandoning ETH" Argument: What Does Paying Gas Without ETH Really Mean? The debate sparked by Vitalik Buterin's discussion of EIP-8141 (Frame Transactions), which suggests users could pay transaction fees without holding ETH, has led to extreme claims that ETH will lose its value. However, this perspective misunderstands the proposal. Currently, an Ethereum user initiating a transaction must also pay the network's Gas fee in ETH. EIP-8141 aims to decouple these actions. It allows a transaction to be split into separate "frames." A user could sign a transaction to, for example, send USDC, while a separate Paymaster account pays the required ETH Gas fee on their behalf. The user would then settle the cost with the Paymaster using USDC or another token. From the user's perspective, they pay in a stablecoin without interacting with ETH. Crucially, from the Ethereum protocol's perspective, the Gas is still paid in ETH; only the settlement layer between the user and Paymaster changes. This concept isn't entirely new; ERC-4337's Account Abstraction already allows similar Gas sponsorship. EIP-8141 seeks to integrate this capability more natively. The core goal is to drastically improve user experience by abstracting away the complexity of Gas, similar to how one pays with a credit card abroad without handling the local currency. It also enables atomic operations, like bundling token approval with a swap, which would revert together if the swap fails. Regarding ETH's value, the argument that "no ETH is needed" is incorrect. While users may not hold ETH, Paymasters and services must still acquire and spend ETH to pay network fees on the backend. The demand for ETH shifts from being distributed across millions of user wallets to being concentrated in the balances of these service providers. The key variable is whether this improved usability attracts significant new users and increases overall network activity. If it does, total ETH burned in fees could rise substantially. If it doesn't, the change merely reshuffles who holds the ETH needed for Gas. In summary, EIP-8141 aims to lower the entry barrier by hiding Gas complexity, betting that this will drive broader adoption and increase the fundamental utility—and thus demand—for the Ethereum network and ETH itself.

marsbit2h ago

Refuting the Ethereum 'Abandoning' ETH Narrative: What Does It Really Mean to Pay Gas Without ETH?

marsbit2h ago

Trading

Spot
活动图片