BitBox patches two ‘severe’ wallet vulnerabilities

BitBox released a firmware update Monday fixing two severe vulnerabilities that could let a malicious host install firmware or lock Bitcoin to unintended addresses. No exploits reported.

Hardware wallet maker BitBox released a firmware update on Monday to fix two vulnerabilities it described as “severe”. The company published a security disclosure with the update and reported no cases of exploitation or customer fund loss.

The first flaw involved memory corruption in Multi editions of the BitBox02 and the BitBox02 Nova when devices had not been set up with a wallet. A malicious host connected to an uninitialized device could exploit the bug to run arbitrary code and potentially install malicious firmware. If attackers altered device behavior, users’ funds could be at risk.

The second issue affected BitBox’s Silent Payments feature, which is intended to keep payment details hidden from the host. A malicious host could have caused a payment to be locked to an unintended address. BitBox noted direct theft was not possible through that bug, but an attacker might have been able to demand a ransom to return access to the coins.

BitBox urged users to apply the firmware update and included version numbers and rollout timing in its advisory. The company advised users to verify firmware signatures and use trusted hosts for initial device setup.

The update follows recent incidents that have affected hardware-wallet security. A firmware flaw in another wallet was linked to more than $112 million in Bitcoin losses, affecting roughly 1,778.6 BTC taken from over 8,600 addresses. Separate breaches exposed order or customer data for more than 53,000 customers across two vendors; one incident involved about 13,689 customer records exposed by a shipping provider and another exposed about 39,798 records through an order-tracking plug-in. Those breaches did not compromise devices, private keys or recovery phrases but could help attackers mount targeted phishing or impersonation attempts.

BitBox’s disclosure did not provide evidence of active exploitation or connect the flaws to other recent incidents. The advisory reiterates that affected users should install the patch and follow standard device safety practices.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author