Bitcoin Holders Urged to Update BitBox Wallets After Two Firmware Vulnerabilities
Key Takeaways
- •BitBox identified two severe firmware vulnerabilities through internal security audits and addressed them with its Dixence security update.
- •The flaws could potentially allow malicious firmware installation and weaken the protection of cryptocurrency stored on affected devices.
- •Dogecoin community contributor Mishaboar urged Bitcoin holders using BitBox wallets to install the fixes without delay.
- •BitBox instructed users to update both the BitBoxApp and device firmware through the official application settings.
- •Users were advised to perform the update on a secure computer and to avoid using systems they suspect may be compromised.

Bitcoin holders using BitBox hardware wallets are being urged to install the latest security update after two severe firmware vulnerabilities were identified in the devices.
Dogecoin community contributor Mishaboar issued the warning to cryptocurrency users, stressing the importance of updating affected BitBox devices as soon as possible. According to information shared by Mishaboar, the vulnerabilities could potentially expose cryptocurrency holdings if attackers successfully exploit weaknesses in the wallet’s firmware.
Although BitBox does not support Dogecoin, the warning is particularly relevant to Bitcoin holders who use the hardware wallet for self-custody.
BitBox releases security fixes
BitBox identified several security weaknesses during internal security audits and addressed the most serious issues through its Dixence security update. The devices are made by Shift Crypto, a Zurich-based Swiss manufacturer that also publishes the source code for its BitBox02 firmware and companion app, allowing independent researchers to review the code alongside the company’s own audits.
One of the vulnerabilities could potentially allow an attacker to manipulate a user into installing malicious firmware on a BitBox device. If successfully exploited, the compromised firmware could weaken the device’s security and potentially provide an attacker with an opportunity to access cryptocurrency protected by the wallet. Hardware wallet manufacturers typically sign their firmware cryptographically so that devices accept only officially released code, which is one reason a weakness that enables malicious firmware installation is treated as severe.
Source: Official X
The disclosure highlights an important consideration for hardware wallet users. While these devices are designed to keep private keys isolated from internet-connected systems, weaknesses in firmware can create another potential attack path.
BitBox has released fixes for the identified vulnerabilities and instructed customers to update both their BitBoxApp and device firmware through the application’s official settings.
For affected users, installing the verified update is the most direct way to address the disclosed security issues.
Mishaboar calls for immediate action
Mishaboar urged Bitcoin holders using BitBox hardware wallets to apply the available security fixes without unnecessary delay.
However, his warning goes beyond simply installing the firmware update. He also recommended that users pay close attention to the computer they use during the installation process.
According to Mishaboar, users should ensure that the computer used for the firmware update is clean and does not contain potentially malicious software. Where possible, he suggested using a new or freshly prepared computer for the sensitive update process.
The recommendation reflects a broader cybersecurity concern. Even when a hardware wallet manufacturer has released a legitimate firmware fix, a compromised computer could introduce additional risks during the update procedure.
For that reason, users should avoid performing sensitive wallet maintenance on computers they suspect may be infected or compromised.
Why firmware security matters for Bitcoin wallets
Hardware wallets are widely used by cryptocurrency holders because they are designed to keep private keys separate from ordinary internet-connected environments.
That architecture can provide important protection against malware, phishing, and other online threats. However, hardware wallets are not immune to security vulnerabilities. Industry history illustrates the point: in December 2023, a compromised Ledger software library was used to drain funds from wallets that interacted with malicious transactions, and in 2025 a fake Trezor Suite app tricked users into entering their recovery phrases. Those episodes involved the software layer around self-custody, while the BitBox disclosure concerns the firmware running on the device itself, underscoring that both layers form part of a wallet’s security chain.
Firmware controls critical functions within the device. If an attacker discovers a serious weakness in that software, the security assumptions behind the hardware wallet can potentially be undermined.
This is why security updates are an important part of cryptocurrency self-custody. When manufacturers disclose and patch vulnerabilities, users must update their devices to benefit from the fixes.
Users should also obtain firmware updates exclusively through official wallet applications or verified channels. Downloading firmware from unknown websites, links sent through private messages, or unverified cryptocurrency communities can introduce additional risks.
Warning is focused on Bitcoin, not Dogecoin
Mishaboar’s warning comes from a well-known contributor within the Dogecoin community, but the issue itself concerns Bitcoin users.
BitBox does not support Dogecoin, so the disclosed vulnerabilities do not represent a direct security issue for DOGE stored on a BitBox device.
Instead, Mishaboar highlighted the BitBox advisory because the hardware wallet is used by Bitcoin holders who rely on self-custody to protect their assets.
The situation shows how security issues affecting wallet infrastructure can become relevant across cryptocurrency communities. A contributor associated with one digital asset can still warn users holding another asset when a commonly used security product is affected.
For Bitcoin holders, the key issue is whether they are using an affected BitBox device and whether its firmware has been updated with the latest security fixes.
Self-custody comes with added responsibility
Cryptocurrency self-custody gives users direct control over their private keys, but that control also creates additional security responsibilities.
Unlike funds held on a centralized exchange, self-custodied cryptocurrency generally depends on the user maintaining the security of their wallet, recovery information, and associated devices.
A hardware wallet can significantly reduce certain risks, but users still need to keep both the device and its supporting software up to date.
Security advisories should therefore be treated seriously, particularly when manufacturers identify vulnerabilities that could potentially affect the protection of private keys or cryptocurrency holdings.
Users should verify the authenticity of any update before installing it and avoid responding to unsolicited messages claiming to provide emergency firmware fixes.
What BitBox users should do
Bitcoin holders using BitBox devices should first open the official BitBoxApp and check whether an update is available.
Before starting the process, users should make sure the computer is secure and free from suspicious software. A freshly prepared computer can provide an additional layer of caution for users who have access to one.
The firmware should then be installed through the official application rather than through a third-party download. BitBox communicates security advisories through its official channels, and users should monitor those channels for any follow-up guidance related to the Dixence update.
Users should never disclose their recovery phrase, private keys, or other sensitive wallet information during a firmware update. Legitimate security updates should not require users to provide those credentials to another person or an unknown website.
The broader lesson for crypto investors
The BitBox vulnerability disclosure underscores a fundamental reality of cryptocurrency security: hardware wallets can reduce risk, but they cannot eliminate it entirely.
Firmware, companion applications, computers, and user behavior all form part of the security chain surrounding a self-custodied wallet.
Regularly checking official security announcements and installing verified patches can help users respond to newly discovered vulnerabilities before they become larger problems.
For Bitcoin holders using BitBox, the current priority is straightforward: check the official BitBoxApp, install the available security fixes, and take reasonable precautions when performing the firmware update.
Conclusion
Dogecoin community contributor Mishaboar has warned Bitcoin holders using BitBox hardware wallets about two severe firmware vulnerabilities and urged users to install the available security fixes.
BitBox identified the weaknesses through internal audits and addressed them through its Dixence security update. The company has provided fixes through its official software and firmware update process.
Although BitBox does not support Dogecoin, the warning remains relevant to Bitcoin users who rely on the device for self-custody.
Users should update their BitBoxApp and firmware through official channels, ensure the computer used for the installation is secure, and never disclose private keys or recovery phrases.
For cryptocurrency holders, responding promptly to verified security updates remains one of the most important steps in protecting self-custodied assets.