BitBox Fixes Two Severe Hardware Wallet Vulnerabilities in Dixence Update
Key Takeaways
- •BitBox fixed both vulnerabilities in firmware version 9.26.5 and says the update is not affected by the issues disclosed on August 17.
- •The memory corruption flaw affected Multi editions of the BitBox02 and BitBox02 Nova through firmware 9.26.4 when connected to a malicious host before wallet setup.
- •Exploitation of the first flaw could have enabled arbitrary code execution and potentially the installation of malicious firmware.
- •The Silent Payments issue could have redirected funds to an unintended address and left recovery dependent on cooperation between the attacker and the intended recipient.
- •BitBox said it has not identified any exploitation or stolen user funds related to either vulnerability and advised users to update via BitBoxApp or the official website.

BitBox has released its August 2026 Dixence security update after internal audits uncovered two severe vulnerabilities in its hardware wallet firmware, including a memory corruption flaw capable of enabling arbitrary code execution. For hardware wallet users, disclosures like this matter because the devices are designed to keep keys isolated from connected computers, so flaws that involve a malicious host or firmware installation can affect the trust model those products rely on.
The Dixence update fixes both issues with firmware version 9.26.5. BitBox said it has not identified any exploitation or stolen user funds tied to either flaw and is recommending that all users update their BitBoxApp and device firmware.
Memory Flaw Could Allow Malicious Firmware
The first vulnerability affects Multi editions of the BitBox02 and BitBox02 Nova through firmware version 9.26.4 when a device has not yet been set up with a wallet and is connected to a malicious host.
Successful exploitation could trigger memory corruption and arbitrary code execution, potentially allowing malicious firmware to be installed on the hardware wallet. BitBox’s Bitcoin-only edition is not affected because its firmware does not contain the vulnerable code.
The disclosure comes weeks after vulnerable seed generation in older Coldcard firmware became the largest crypto security loss recorded in July. The Coldcard-linked drain led to an estimated $210.3 million in crypto hack losses during the month, with affected firmware producing Bitcoin seeds with substantially less randomness than intended.
Silent Payment Flaw Could Lock Bitcoin Funds
A second BitBox vulnerability affects its Silent Payments implementation. A malicious host could manipulate a transaction so that funds intended for a Silent Payment address were instead locked to an unintended address.
The flaw did not provide a direct mechanism for stealing the bitcoin. Recovery could require cooperation from the attacker and the intended recipient, creating a potential ransom scenario. BitBox02 and BitBox02 Nova devices running firmware versions 9.21.0 through 9.26.4 may be affected when creating a Silent Payment transaction while connected to a malicious host.
Hardware wallet manufacturers have faced several unrelated security disclosures this year. Trezor disclosed a separate TROPIC01 secure-element vulnerability affecting one physical security layer in the Safe 7 in June, although that attack required physical possession, specialized equipment and did not expose wallet backups or funds.
Earlier Bootloader Weakness Was Already Patched
BitBox also provided new details on a separate bootloader weakness already fixed in firmware version 9.26.2. That attack could have manipulated a user into installing malicious firmware on an authentic BitBox02 after first compromising them through a fake BitBoxApp or a similar phishing route. BitBox02 Nova devices are not affected by that older bootloader path.
Users should install updates through the existing BitBoxApp or the official BitBox website and never enter recovery words into a computer, website or update prompt. BitBox firmware version 9.26.5 is not affected by any of the vulnerabilities covered in the August 17 disclosure.