NewsCryptoBitBox Patches Severe Firmware Flaws Uncovered by AI-Assisted Audits in Dixence Update

BitBox Patches Severe Firmware Flaws Uncovered by AI-Assisted Audits in Dixence Update

Author: Decrypt·

Key Takeaways

  • BitBox said its engineers discovered two severe firmware vulnerabilities and an additional bootloader issue during an internal review.
  • The company stated that no user funds were stolen and there is no evidence the flaws were exploited.
  • One issue could have allowed malicious firmware to be installed on a genuine BitBox02 after a phishing attack and device unlocking.
  • A second severe bug affected the Multi edition before wallet setup and could have enabled arbitrary code execution on a hostile computer.
  • All three vulnerabilities are fixed in firmware version v9.26.5, and BitBox says older devices remain exposed until users install the update.
BitBox Patches Severe Firmware Flaws Uncovered by AI-Assisted Audits in Dixence Update

BitBox, the Zurich-based maker of the BitBox02 hardware wallet, has released its Dixence security update after the company's own engineers uncovered two severe flaws in the wallet's firmware, with the internal review also surfacing a bootloader issue.

The company disclosed the issues itself, and there is no evidence the vulnerabilities were ever exploited. According to BitBox, exploiting them required a successful phishing attack combined with the user unlocking a tampered device. The company says no user funds were stolen and the wallet seed was never at risk.

The disclosure nonetheless lands at a sensitive moment for Bitcoin holders, coming after the recent exploit of hardware wallet maker Coldcard that has resulted in over $130 million in stolen BTC.

The first problem lies in the bootloader, the code that decides which firmware a device will accept. A fix shipped in July's Oeschinen release (v9.26.2) closed most of the issue, but BitBox now says the original flaw was worse than first reported. An attacker running a phishing scam—tricking a user into installing a fake BitBoxApp and unlocking the device—could have loaded malicious firmware onto a genuine BitBox02 and made off with the coins. The BitBox02 Nova, the newer model, was never exposed because of its bootloader version.

The second severe bug is a memory-corruption flaw affecting the Multi edition of the BitBox before it has been set up with a wallet. Paired with a hostile computer, it could have allowed arbitrary code execution and, again, the installation of malicious firmware. The Bitcoin-only edition does not carry the affected code and is not impacted.

A third, less dangerous issue touched the wallet's silent payments feature. It could not steal coins directly, but it could have locked funds to a wrong address in a ransom-style move. All three vulnerabilities are fixed in firmware version v9.26.5, and BitBox says devices on older firmware remain exposed until users install the update.

BitBox leaned on frontier AI models during its internal review, part of a wider push the company described in a separate post about auditing firmware with AI help. That detail adds some context for the broader hardware-wallet sector, where vendors are under pressure to find subtle firmware bugs before attackers do, especially as users increasingly rely on these devices to protect larger balances.

The episode is another reminder that hardware wallets, long considered the ideal choice for security-conscious crypto users, are not bulletproof. The Coldcard exploit showed how a five-year-old firmware bug let thieves drain roughly 1,596 BTC, the largest hardware-wallet hack of 2026. Days earlier, the data breach of hardware wallet maker SafePal stoked fresh fears of so-called wrench attacks on wallet owners whose personal details, including physical addresses, were exposed.

In this case, BitBox says there is nothing to worry about besides updating. Per the company's disclosure: "There are no reports of stolen user funds and there is no reason for users to panic."

The fix is live at bitbox.swiss/download.