On August 17, hardware crypto wallet manufacturer BitBox introduced a firmware update codenamed Dixence. This release closes two serious security vulnerabilities discovered during internal audits using AI models. It is important to emphasize: at this time, there is no evidence that the vulnerabilities were exploited by attackers in real-world attacks, and user funds and seed phrases remain safe.
Technical Details of the Discovered Issues
The first vulnerability affected the BitBox02 bootloader—a critical component responsible for installing firmware. Although the error itself was partially fixed back in the July version 9.26.2, subsequent analysis showed that a potential attack could have been far more dangerous than initially assumed. Exploiting it required a complex multi-step phishing attack: the victim needed to be convinced to install a fake version of the BitBoxApp application along with malicious firmware, and then be persuaded to unlock the device. Only then could the attacker reflash the real BitBox02 and steal funds. The new BitBox02 Nova model, thanks to a different bootloader version, is immune to this attack.
The second, equally serious issue was related to memory corruption in the Multi version. It manifested on a device without a configured wallet when connected to an infected computer. The error opened the door to arbitrary code execution and the potential installation of modified firmware. This vector was fully neutralized in Dixence version 9.26.5.
Additional Findings and Industry Context
During the same checks, engineers also identified a third, less critical bug—in the Silent Payments function. It did not allow direct theft of coins but gave an attacker the chance to lock funds at an incorrect address, after which they could blackmail the owner, demanding a ransom to restore access. This issue has also been fixed in version 9.26.5.
BitBox emphasizes that it conducted an in-depth review of the entire codebase over recent weeks and received a record number of reports from third-party auditors actively using modern AI models. So far, external checks have not revealed any new critical or serious vulnerabilities.
Who Needs to Update
I recommend that all BitBox device owners immediately install version 9.26.5 via the official BitBoxApp application or the manufacturer's website. Risk scenarios vary depending on the model and software version:
- BitBox02 with firmware up to 9.26.1—risk when installing malicious software;
- BitBox02 and BitBox02 Nova Multi up to 9.26.4—risk when connecting to an infected computer without a configured wallet;
- BitBox02 and BitBox02 Nova (versions 9.21.0–9.26.4)—risk when using Silent Payments with a malicious device.
I also remind you of basic hygiene: never enter your seed phrase anywhere except on the hardware wallet itself, and beware of phishing campaigns that may intensify following the publication of information about vulnerabilities.
My Comment as an Analyst
This incident is yet another confirmation that even hardware wallets are not absolutely invulnerable. However, BitBox's response is telling: the rapid detection and closure of vulnerabilities using AI tools demonstrates that proactive audits are becoming the new industry standard. It is especially important that these findings come against the backdrop of the recent Coldcard hack, where damage from the seed phrase exploit exceeded $112 million. In such conditions, trust in manufacturers is built precisely on the ability to respond quickly to threats, and BitBox is setting an example in this regard.