BitBox has pushed an urgent firmware update to fix two severe security flaws that, if exploited, could have allowed attackers to install malicious firmware or lock users’ Bitcoin to the wrong address. What BitBox patched - Memory-corruption bug (severe): This affected unconfigured “Multi” editions of the BitBox02 and BitBox02 Nova. BitBox says a malicious host physically connected to an uninitialized device could exploit the flaw to execute arbitrary code before the wallet was even set up. In the worst case that would allow installation of malicious firmware — a direct path to later compromising funds. The exposure is limited to Multi-edition devices that haven’t yet been configured. BitBox classified the flaw as severe because arbitrary code execution can defeat protections that normally prevent unauthorized software on a hardware wallet. - Silent Payments bug (severe): A flaw in BitBox’s Silent Payments implementation (a privacy feature that receives Bitcoin without publishing a new address) could be abused by a malicious host to lock funds to an unintended address. BitBox says this would not enable direct theft, but could make the coins irrecoverable to the owner unless the attacker cooperated — creating the potential for ransom-style abuse. BitBox said these vulnerabilities were disclosed on Monday, that it has released fixes in the latest firmware, and that it has found no evidence either bug was exploited or that users lost funds. Why this matters Firmware controls key wallet functions: cryptographic operations, transaction verification and host communication. Any vulnerability that allows code execution or compromises address derivation can put funds at risk. The memory-corruption issue is particularly sensitive because it can be triggered before device setup, bypassing typical software-signature protections. Broader context — more hardware wallet risks this year BitBox’s fixes come amid a wave of disclosures and attacks targeting hardware wallet components and implementations: - TROPIC01 / Trezor: Ledger Donjon researchers demonstrated a laser fault-injection attack against the TROPIC01 secure element used in some Trezor devices, extracting secrets and bypassing signature checks in lab testing. Trezor said its Safe 7 remained protected due to multiple independent security layers. - Tangem: Researchers used a targeted laser pulse in the lab to reset a Tangem card’s password. The attack required physical possession, invasive prep and roughly $250,000 in lab equipment; Tangem called everyday risk “virtually non-existent.” - Coldcard catastrophe: Galaxy Research traced a separate Coldcard firmware change from March 2021 that weakened seed randomness and has been linked to more than $112 million in losses (about 1,778.6 BTC taken from over 8,600 addresses). Because affected seeds were generated with reduced entropy, attackers could brute-force private keys without physical access. Updating firmware does not repair seeds already created with weak randomness — victims must move funds to wallets created from secure, newly generated seeds. - BitBox’s own prior fixes: This year BitBox also shipped its Oeschinen update in July to patch a USB length-check buffer issue in the BitBox02 firmware/bootloader, and earlier in January patched two Nova issues reported via its bug bounty program (classified minor/moderate, requiring advanced physical access). Non-device breaches and phishing risk Hardware wallet companies have also suffered data exposures that increase phishing risk. Trezor reported 13,689 customers’ information was exposed via a shipping partner (ShipMonk), and SafePal said an order-tracking plugin leak affected 39,798 customers. Neither incident exposed private keys or recovery phrases, but the exposed data can fuel targeted scams. There has also been a rise in convincing physical-phishing campaigns: attackers have mailed official-looking letters with QR codes directing recipients to fake sites that ask for 12–24 word recovery phrases. Trezor and Ledger reiterate that legitimate providers never ask users to enter recovery phrases online — those phrases should only be entered directly on the hardware device when restoring a wallet. What users should do now - Update BitBox devices immediately to the latest firmware. - If you have an unconfigured BitBox02/BitBox02 Nova Multi edition, be especially cautious before connecting it to any host. - Treat any unusual requests or communications (emails, letters, QR codes) with suspicion. Never enter recovery phrases into websites or share them. - Keep hardware wallets physically secure to reduce risk of invasive, lab-grade attacks. - If you use a device that has had seed-generation issues (e.g., affected Coldcard firmware), move funds to a new wallet created with a secure seed. Bottom line: BitBox’s prompt patching prevented a potential route for malicious firmware and for funds to be rendered inaccessible, but the episode underscores the importance of timely updates, cautious device handling, and ongoing vigilance across the hardware wallet ecosystem.
BitBox Urgently Patches Two Critical Security Flaws in Hardware Wallets
ChainGPTShare
BitBox released a critical firmware update to fix two major security flaws in its BitBox02 and BitBox02 Nova hardware wallets. One flaw allows malicious code execution before setup, while the other enables funds to be locked to wrong addresses. No attacks or losses have been reported. This market update follows recent issues with Trezor and Coldcard. BitBox also patched earlier USB and Nova bugs. Users are urged to update now. Altcoins to watch may see volatility as security remains a key concern.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
