NewsCryptoBitBox Warns Users After Discovering 'Severe' Firmware Vulnerabilities

BitBox Warns Users After Discovering 'Severe' Firmware Vulnerabilities

Author: Bitcoin Magazine·

Key Takeaways

  • BitBox said internal audits uncovered and fixed multiple security issues in its firmware through the Dixence security update.
  • One flaw could have led a user to install firmware that enabled an attacker to steal funds.
  • A second vulnerability involved memory corruption in the Multi edition and could allow arbitrary code execution and malicious firmware installation.
  • BitBox said there are no reports of stolen user funds and that users only need to update their firmware, not move assets.
  • The Bitcoin-only edition is not affected by the memory-corruption issue because it does not include the multi-currency code.
BitBox Warns Users After Discovering 'Severe' Firmware Vulnerabilities

Swiss hardware wallet manufacturer BitBox says it has fixed "severe vulnerabilities" in its device firmware and assured customers that no funds were taken — but the company is still urging users to upgrade carefully.

Hardware wallets like BitBox's are built to keep users' private keys offline, which makes the device's firmware central to the security model: the firmware governs how the device stores keys and approves transactions, so flaws at that level can undermine the isolation the product is meant to provide.

In a blog post published Tuesday, the Swiss company said one of the vulnerabilities would have allowed an attacker to manipulate a user into installing firmware that could lead a criminal to steal funds. BitBox advised customers to update through the official BitBoxApp, ideally by clicking the in-app update prompt rather than searching for the update manually. That guidance echoes long-standing crypto-security practice of obtaining wallet software and updates only from official sources, since fake apps and phishing pages have persistently targeted crypto users.

The company announced the fixes, dubbed the Dixence security update, in a post on X on August 17, 2026:

We just released the Dixence security update. During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware. We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings.…

— BitBox (@BitBoxSwiss), August 17, 2026 (post on X)

"There are no reports of stolen user funds and there is no reason for users to panic," BitBox said in its security advisory. "We recommend all users to update their BitBox devices to the latest firmware version, which fixes all security issues described in this article."

A second "severe vulnerability" identified by the company involved memory corruption. BitBox said the finding relates to the Multi edition of its hardware wallet and could enable arbitrary code execution, the subsequent installation of malicious firmware, and potential loss of funds. The Multi edition supports multiple cryptocurrencies, while the Bitcoin-only edition ships with a reduced firmware without the multi-currency code. The Bitcoin-only edition of the device is not affected, the company noted, because its firmware does not contain the affected code.

The disclosure comes as Bitcoiners continue to reckon with the breach of the popular Coldcard wallet, designed by Canadian company Coinkite, in which users had their funds drained by a firmware bug that led to weak seed generation (RNG). Unlike the Coldcard hack, neither BitBox nor its users need to migrate funds — updating the firmware is sufficient.

Hackers have since stolen a confirmed $115 million in bitcoin in the Coldcard attack, according to Galaxy Research's latest figures — though the actual figure could be much higher.

Coinkite first warned users on July 31 that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software pseudorandom number generator instead of the hardware true random number generator, allowing hackers to essentially guess investors' seed phrases.

The total has slowly risen as criminals have targeted more recent devices, while Coinkite and other Bitcoiners have urged Coldcard users to immediately move their funds.

This article by Mathew Di Salvo first appeared on Bitcoin Magazine.