Skip to main content

BitBox Wallet Updates Address ‘Severe’ Flaws That Could Risk Funds



BitBox, the Swiss hardware-wallet provider, has released a firmware update aimed at correcting two security vulnerabilities it characterized as “severe.” According to a security disclosure published on Monday, the patches address issues that could theoretically allow a malicious host to interfere with device behavior and, in one case, affect how Bitcoin is routed during Silent Payments.



Key takeaways



  • BitBox says its new firmware fixes a “severe” memory corruption issue affecting Multi editions of BitBox02 and BitBox02 Nova when the device has no wallet configured.

  • The company also patched a “severe” weakness in its Silent Payments implementation that could potentially cause Bitcoin to be locked to an unintended address.

  • BitBox reported receiving no claims that either vulnerability has been exploited in the wild or caused user losses.

  • The update arrives amid heightened scrutiny of hardware-wallet supply chains and device security after high-profile wallet-related incidents.



What BitBox says the firmware update changes


In its disclosure, BitBox describes one vulnerability as a form of memory corruption involving Multi editions of BitBox02 and BitBox02 Nova. The issue is tied to scenarios where the device has not been configured with a wallet, meaning it’s in a state where it could be more vulnerable to abnormal interactions.



BitBox warns that a malicious host could exploit the flaw to execute arbitrary code and potentially install malicious firmware. If such an attack succeeded, it could compromise the device’s ability to protect user funds. As part of its disclosure, the company states it has not received reports indicating the vulnerability has been used to harm users.



Silent Payments patch: risk of unintended locking


The second vulnerability affects BitBox’s Silent Payments feature. BitBox says that while the flaw would not directly enable theft, it could allow a malicious host to lock Bitcoin to an address chosen by the attacker rather than the intended recipient.



In practical terms, BitBox frames the threat as leverage instead of direct extraction: an attacker could potentially demand a ransom to cooperate with restoring access to the coins. BitBox also says it has not seen reports of this issue being exploited or leading to lost funds.



Why the timing matters for self-custody security


BitBox’s firmware release lands at a moment when the hardware-wallet ecosystem is being tested on multiple fronts: device firmware integrity, secure generation of wallet data, and even the protection of customer and order information around wallet products.



Earlier coverage tied a Coldcard hardware-wallet issue to a March 2021 firmware change that remained undetected for more than five years. That vulnerability reportedly affected wallet-seed randomness, enabling attackers to brute-force impacted wallet seeds and derive private keys without physical access. Galaxy Research said last Friday that Coldcard-related losses had exceeded $112 million, with about 1,778.6 BTC reportedly swept from more than 8,600 addresses. (The earlier analysis is described in Cointelegraph’s reporting: Coldcard’s 5-year flaw reveals hardware-wallet testing gap.)



Beyond device bugs, separate incidents also drew attention to the broader risk surface of hardware-wallet businesses. Cointelegraph previously reported data breaches involving Trezor and SafePal that exposed customer and order information for more than 53,000 people. Those cases did not compromise device security, private keys, or recovery phrases. Instead, they raised concerns about targeted phishing and impersonation attempts—risks that can be especially dangerous for users who can be tricked into handing over seed material or signing approvals.



What users should watch after installing updates


Hardware-wallet vulnerabilities are not always limited to “theft bugs.” As BitBox’s disclosure shows, threats can also emerge from interaction patterns—such as how a device behaves before a wallet is configured—or from optional features like Silent Payments, where errors can affect the destination of funds rather than enabling immediate draining.



For BitBox users, the key next step is straightforward: install the firmware update and confirm the device is operating under the latest version recommended by the vendor. Readers may also want to review their operational habits around Silent Payments usage and ensure they are comfortable with how their wallet constructs and verifies outputs before signing.



More broadly, the pattern across recent incidents suggests that self-custody security depends on a full chain—not only the cryptography inside the hardware, but also firmware correctness, feature-specific logic, and the surrounding processes that keep customer interactions from becoming an entry point for social engineering.



With BitBox now shipping a fix and reporting no known exploitation, the remaining question for the market is whether broader scanning and third-party auditing will surface additional edge-case weaknesses in similar workflows across other devices and features. Users should treat firmware updates as an ongoing part of operational security, not a one-time task.



https://www.cryptobreaking.com/bitbox-wallet-updates-address-severe/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=BitBox%20Wallet%20Updates%20Address%20‘Severe’%20Flaws%20That%20Could%20Risk%20Funds%20

Comments

Popular posts from this blog

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...