On August 17, hardware wallet manufacturer BitBox released the Dixence firmware update, which closed two serious vulnerabilities. Both bugs were discovered during internal audits using AI models—an approach that is becoming the new standard in the security industry.

It is important to emphasize: the company has not recorded any cases of these vulnerabilities being exploited or funds being stolen. Users' seed phrases remained safe. Nevertheless, this event is another signal that even the most protected devices require regular updates.

What exactly was found

The first vulnerability affected the BitBox02 bootloader—a critical component responsible for installing firmware. Although the bug itself was fixed back in the July version 9.26.2, further analysis showed that a potential attack would have been significantly more dangerous than initially assumed. To carry it out, an attacker would need to conduct a successful phishing attack: convince the user to install a fake version of BitBoxApp along with malicious firmware, and then unlock the device. After that, the attacker could install modified software and steal funds. The new BitBox02 Nova model is not susceptible to this attack due to a different bootloader version.

The second serious issue was memory corruption in the Multi version. It manifested on a device without a configured wallet when connected to a malicious computer. The bug allowed arbitrary code execution and the potential installation of modified firmware. The fix was released in Dixence 9.26.5.

During the same checks, engineers found a third issue—in the Silent Payments function. It did not allow direct theft of coins, but an attacker could lock them at an incorrect address and demand a ransom for restoring access. This bug was also fixed in version 9.26.5.

Who should update and how

Version 9.26.5 closes all three described issues. The company strongly recommends that all users install it. Affected scenarios:

  • BitBox02 with firmware up to 9.26.1—risk when installing a malicious app and firmware;
  • BitBox02 and BitBox02 Nova Multi up to 9.26.4—if the wallet is not configured and the device is connected to a malicious computer;
  • BitBox02 and BitBox02 Nova with versions 9.21.0–9.26.4—when using Silent Payments with a malicious device.

The update should be installed via the already installed BitBoxApp or the official website. Amid the publication of information about the vulnerabilities, the company warns of possible phishing campaigns and reminds: recovery words can only be entered on the device itself.

Context: the era of AI audits

This incident is a direct continuation of a series of events that began with the hack of Coldcard hardware wallets. In July, hackers exploited a bug in seed phrase generation that had been in the firmware for several years. By mid-August, Galaxy Research confirmed the theft of at least 1,778.84 BTC (~$112.7 million), and including unconfirmed episodes, the damage could have reached $153 million.

Notably, after the Coldcard incident, Dragonfly managing partner Haseeb Qureshi stated that an AI check costing about $2 could have detected the problem. In one experiment, the GLM 5.2 model found the bug in about 20 minutes. This changes the game: now manufacturers that do not use AI audits risk falling behind.

However, Kraken rightly pointed out the flip side: having an audit does not guarantee security. The exchange's chief security officer, Nick Percoco, emphasized that one should check not individual components, but the entire path from the randomness source to the firmware that creates the seed phrase. Bitcoin Red Team, which launched mass AI scanning of hundreds of Bitcoin projects, also noted that manual review of results and delivery of confirmed reports to developers has become the new bottleneck.

In parallel, the industry faces other threats: on August 13, Trezor reported a data leak of nearly 14,000 clients, and on August 16, SafePal disclosed the theft of information from about 39,800 users, including delivery addresses and phone numbers—an ideal base for targeted phishing.

My comment. The situation with BitBox is a vivid example of how quickly the threat landscape is changing. AI auditing is becoming not a luxury, but a necessity, yet it does not negate basic hygiene rules: update firmware, do not connect devices to suspicious computers, and never enter seed phrases outside the wallet. Hackers are increasingly attacking not code, but the human—and phishing remains their main tool.