BitBox Patches 'Serious' Vulnerabilities in Wallets That Could Have Put Funds at Risk

cryptonews.ruОпубліковано о 2026-08-18Востаннє оновлено о 2026-08-18

Анотація

Hardware wallet manufacturer BitBox has released a firmware update to fix two "serious" vulnerabilities. The first flaw, present in uninitialized BitBox02 Multi and BitBox02 Nova devices, was a memory corruption issue that could allow an attacker to execute arbitrary code and install malicious firmware, potentially leading to fund loss. The second vulnerability involved the implementation of Silent Payments, which could let an attacker redirect a user's bitcoin to an unintended address, though direct theft was impossible; an attacker could then demand a ransom to assist in recovering the coins. BitBox stated it has received no reports of these vulnerabilities being exploited or of user funds being lost. This disclosure comes during a sensitive period for the self-custody sector, following a major incident involving Coldcard wallets. A previously undetected firmware vulnerability in Coldcard, related to weak random number generation for seed phrases, has reportedly led to the theft of over $112 million in bitcoin from more than 8,600 addresses. Recent data leaks from Trezor and SafePal have also exposed information for over 53,000 customers combined, though these incidents did not compromise private keys or recovery phrases. The leaks could, however, facilitate targeted phishing attacks. BitBox did not respond to requests for additional comment by the time of publication.

Hardware wallet manufacturer BitBox has released a firmware update that patches two vulnerabilities which the company described as "serious." These vulnerabilities could have allowed the installation of malicious firmware, putting users' funds at risk.

In a security notice on Monday, BitBox detailed the first vulnerability—a memory corruption issue in uninitialized BitBox02 Multi and BitBox02 Nova versions. An attacker could exploit this flaw on the host device to execute arbitrary code and install malicious firmware, potentially leading to loss of funds.

The second vulnerability affected BitBox's implementation of Silent Payments and could allow an attacker to lock bitcoin at an unintended address. While direct theft was not possible, the attacker could demand a ransom to assist in recovering the coins, BitBox stated. The company added that it had not received any reports of the vulnerabilities being exploited or of user funds being lost.

The disclosure comes at a sensitive time for the self-custody sector. Earlier, a Coldcard firmware vulnerability led to the theft of over $112 million worth of bitcoin, demonstrating how weaknesses in devices designed to protect private keys can become single points of failure.

Cointelegraph reached out to BitBox for further comment but did not receive a response prior to publication.

BitBox Patch Released Following Coldcard Bitcoin Theft and Wallet Data Leaks

The BitBox security update follows a wave of incidents affecting hardware wallets and related services.

The most damaging was the Coldcard vulnerability, linked to a firmware change made in March 2021, which remained undetected for over five years. This vulnerability affected the generation of random values for the wallet seed phrase: attackers could brute-force find the seed phrases of affected wallets and obtain their private keys without physical access.

Galaxy Research reported on Friday that losses related to Coldcard exceeded $112 million. Approximately 17,786 BTC was withdrawn from more than 8,600 addresses.

Related: Coldcard exploit pushed July losses to $247,000,000, making it the second-worst month of 2026

Recently, separate data leaks at Trezor and SafePal exposed customer and order information for over 53,000 users. Trezor linked the leak of data for 13,689 customers to its delivery service provider ShipMonk, while SafePal stated that an authorization vulnerability in an order-tracking plugin exposed information for 39,798 customers.

In none of these incidents were the devices, private keys, or recovery phrases compromised. However, both companies warned that the exposed information could facilitate targeted phishing attacks and identity impersonation attempts.

Magazine: Do Coldcard attacks mean all hardware wallets are now unsafe?

end-content

Пов'язані питання

QWhat were the two serious vulnerabilities identified by BitBox in their hardware wallets, and what risks did they pose?

AThe first vulnerability was a memory corruption issue affecting unconfigured BitBox02 Multi and BitBox02 Nova devices. An attacker could exploit it to execute arbitrary code and install malicious firmware, risking fund loss. The second vulnerability was in the Silent Payments implementation, which could allow an attacker to lock a user's Bitcoin to an unintended address, enabling ransom demands.

QHow did the timing of BitBox's vulnerability disclosure relate to the broader security context for self-custody wallets?

AThe disclosure came at a sensitive time for the self-custody sector, following a major incident where a firmware vulnerability in Coldcard wallets led to the theft of over $112 million in Bitcoin, highlighting how weaknesses in private key storage devices can become failure points.

QWhat was the nature and impact of the Coldcard vulnerability mentioned in the article?

AThe Coldcard vulnerability, introduced in a March 2021 firmware update and undetected for over five years, affected the random number generation for wallet seed phrases. Attackers could brute-force the seed phrases of affected wallets, obtain their private keys, and steal funds without physical access, leading to losses exceeding $112 million from over 8,600 addresses.

QWhat other hardware wallet-related security incidents were mentioned besides Coldcard and BitBox?

ARecent data leaks from Trezor and SafePal were mentioned. Trezor's leak of 13,689 customer records was linked to a delivery service provider, ShipMonk. SafePal's leak of 39,798 customer records stemmed from an authorization vulnerability in an order-tracking plugin. No devices, private keys, or recovery phrases were compromised in these incidents.

QAccording to the article, what was a potential secondary risk associated with the Trezor and SafePal data leaks, even though no private keys were stolen?

ABoth companies warned that the leaked customer information could facilitate targeted phishing attacks and impersonation attempts against the affected users.

Пов'язані матеріали

Bitcoin Exchange Upbit Announces Inclusion of This Altcoin in Its Spot Trading Cryptocurrency List! Here Are the Details

South Korean cryptocurrency exchange Upbit has announced the addition of the Lighter token ($LIT) to its Korean Won (KRW) market. Trading for $LIT will commence on August 24, 2026, at 13:00. The supported network for the token is Ethereum, and users are advised to verify network information carefully before making deposits or withdrawals, as transfers only via the Ethereum network are supported. Initial trading will have specific restrictions: for the first five minutes, buy order quantities will be limited, and sell orders priced at 10% or less of the previous day's closing price will not be permitted. For roughly the first two hours, non-limit order types, such as market and conditional orders, will also be restricted. According to Upbit data, the previous day's closing price for $LIT on the Bitcoin ($BTC) market was 0.00004500 $BTC, approximately 4,803 Korean Won. Lighter is a protocol offering a decentralized perpetual futures market. The $LIT token is used within the protocol for staking and liquidity pool participation. Token holders can gain access to the Light Liquidity Pool (LLP) by staking $LIT and may qualify for fee waivers on transfers, withdrawals, and transaction fees based on their staking level. Upbit has cautioned users that transaction processing could be delayed due to insufficient liquidity.

cryptonews.ru5 хв тому

Bitcoin Exchange Upbit Announces Inclusion of This Altcoin in Its Spot Trading Cryptocurrency List! Here Are the Details

cryptonews.ru5 хв тому

Published in Science Robotics, Tsinghua University Team Spent 22 Years Finally Teaching a Robot to Play Soccer

A research team led by Professor Zhao Mingguo from Tsinghua University’s Department of Automation, in collaboration with ByteDance Seed and China Agricultural University, has published a paper in the *Science Robotics* August 2026 special issue on humanoid robots. Titled “Learning Vision-Driven Reactive Soccer Skills for Humanoid Robots,” the paper presents a novel vision-driven, reactive learning framework that enables a humanoid robot to autonomously find, approach, and kick a football in dynamic environments using only on-board vision. The work addresses the long-standing challenge of real-time perception and reaction in noisy, delayed, and partially occluded real-world conditions. The team’s unified perception-motion reinforcement learning framework performs end-to-end training. It incorporates a virtual perception system modelled on real sensor noise and latency, an encoder-decoder architecture for state estimation during visual interruptions, and an adversarial motion prior (AMP) for natural, human-like movement. The resulting policy allows the robot to perform continuous actions—searching, chasing, gait adjustment, and multi-directional kicking—as a fluid skill. The research culminates a 22-year effort originating from Tsinghua’s “Vulcan” robot soccer team, founded by Zhao in 2004. The policy was validated on the humanoid platform from Accelerated Evolution (a company founded by a former team captain) and successfully deployed in RoboCup competitions, where the Tsinghua team won the 2025 Humanoid League and retained the Large Size title in 2026. The study demonstrates significant performance improvements over traditional modular systems, with faster reaction times and robust performance against moving balls, marking a step toward practical, skilled humanoid platforms.

marsbit10 хв тому

Published in Science Robotics, Tsinghua University Team Spent 22 Years Finally Teaching a Robot to Play Soccer

marsbit10 хв тому

Торгівля

Спот
活动图片