Swiss hardware crypto wallet manufacturer BitBox has released the Dixence firmware update, which closes several critical security vulnerabilities in its devices. During internal audits conducted with the involvement of AI models, the company's engineers discovered and fixed serious bugs that could have led to the compromise of user funds.

It is important to emphasize: at this time, there is no evidence that these vulnerabilities were exploited by attackers in real-world attacks. Client funds and their seed phrases were not affected, which indicates the timeliness of the problem detection.

Details of the discovered issues

The first and most dangerous vulnerability affected the BitBox02 bootloader — a critical component responsible for firmware installation. Although the initial fix was introduced back in the July version 9.26.2, further analysis showed that a potential attack would have had far more serious consequences than originally assumed.

The attack scenario required the attacker to conduct a successful phishing campaign: convincing the victim to install a fake version of the BitBoxApp application along with malicious firmware, and then unlock the device. This would have allowed the attacker to inject modified software into a real BitBox02 and gain full control over funds. The new BitBox02 Nova model, which uses a different bootloader, is not susceptible to this attack.

A second critical bug, related to memory corruption, was discovered in the Multi version. It manifested on devices without a configured wallet when connected to an infected computer, allowing arbitrary code execution and the installation of modified firmware. The fix was included in version Dixence 9.26.5.

Additionally, during the checks, an issue was found in the Silent Payments function. It did not allow direct theft of coins, but it gave the attacker the ability to lock funds at an incorrect address, followed by a demand for ransom to restore access. This bug was also fixed in version 9.26.5.

Extensive audits and industry context

BitBox developers emphasize that over the past weeks they have conducted an in-depth audit of the entire codebase. The company received a record number of reports from third-party researchers, most of whom actively used modern AI tools to search for vulnerabilities. External checks have not yet revealed any critical or serious issues.

The recommendation for all BitBox device owners is to immediately update the firmware to version 9.26.5 through the official BitBoxApp application or the manufacturer's website. Depending on the model and software version, users fall into different risk groups: from vulnerability to phishing attacks to issues with memory and Silent Payments.

The company also warns of possible phishing campaigns following the publication of information about the vulnerabilities and reminds users: recovery words should never be entered outside the wallet itself.

This event is just part of a broader trend in the industry. After the recent hack of Coldcard hardware wallets, in which hackers stole over 1,778 BTC (~$112.7 million), manufacturers worldwide have strengthened security measures. Notably, an AI audit costing only about $2 could have prevented the Coldcard incident, as experiments with the GLM 5.2 model, which found the bug in 20 minutes, showed.

However, as experts at Kraken rightly note, the presence of an audit in itself does not guarantee security. What needs to be checked is not individual components, but the entire seed phrase generation path — from the randomness source to the final firmware. Against the backdrop of data leaks at Trezor (nearly 14,000 clients) and SafePal (about 39,800 users), the BitBox incident serves as a reminder: security in cryptocurrencies is a continuous process, not a one-time solution.

My comment: BitBox's proactive approach using AI tools is the right step that should become an industry standard. However, the fact that the vulnerabilities were only found after the high-profile Coldcard hack indicates the market's reactivity. Manufacturers should implement continuous automated audits rather than wait for incidents to begin checks.