Close Menu
    Facebook X (Twitter) Instagram
    Tuesday, August 18
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » BitBox patches wallet flaws that could install malicious firmware
    Crypto

    BitBox patches wallet flaws that could install malicious firmware

    James WilsonBy James WilsonAugust 18, 2026No Comments7 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    BitBox has released a firmware update fixing two severe vulnerabilities that could have exposed hardware wallet users to malicious firmware or caused Bitcoin to be locked to an unintended address.

    Summary

    • BitBox has patched two severe vulnerabilities affecting its BitBox02 and BitBox02 Nova hardware wallets.
    • One flaw could have allowed malicious firmware installation, while another could have locked Bitcoin to an unintended address.
    • BitBox said neither vulnerability had been exploited and no user funds were reported lost.
    • The fixes follow a Coldcard firmware flaw linked to more than $112 million in Bitcoin thefts.

    BitBox said in a security disclosure on Monday that the first vulnerability involved memory corruption affecting unconfigured Multi editions of the BitBox02 and BitBox02 Nova, while a second flaw affected the wallet maker’s Silent Payments implementation.

    The company said it had found no evidence that either vulnerability had been exploited and had received no reports of users losing funds because of the flaws.

    BitBox vulnerability could have allowed malicious firmware

    For the first vulnerability, BitBox said a malicious host connected to an affected wallet could exploit memory corruption to execute arbitrary code before the device had been configured with a wallet.

    Successful exploitation could potentially allow the host to install malicious firmware, creating a route through which funds could later be compromised, according to the company.

    The exposure was limited to Multi editions of the BitBox02 and BitBox02 Nova that had not yet been set up. BitBox classified the vulnerability as severe because arbitrary code execution could undermine protections designed to prevent unauthorised software from running on the hardware wallet.

    Firmware controls how a hardware wallet handles cryptographic operations, verifies transactions and communicates with a connected computer. BitBox said the vulnerability could therefore put funds at risk if an attacker managed to use the flaw to install malicious firmware on an affected device.

    Similar hardware and firmware weaknesses have surfaced at other wallet makers in recent months. In June, crypto.news reported on a flaw in the TROPIC01 Secure Element used by Trezor Safe 7 devices after Ledger Donjon researchers carried out a laser fault injection attack during laboratory testing.

    Trezor said its Safe 7 remained protected because the device uses three independent hardware security layers. According to the company, compromising TROPIC01 alone did not provide access to a user’s PIN, wallet or funds.

    Tropic Square had provided the chip to Ledger Donjon for independent testing, with researchers notifying the company in January that they had extracted some chip secrets and bypassed firmware signature checks using the laboratory attack.

    Another hardware attack disclosed in July allowed Ledger Donjon researchers to reset the password on a Tangem wallet card using a targeted laser pulse against its secure element.

    Ledger Donjon said the attack required physical possession of the card, invasive preparation, specialist knowledge and laboratory equipment costing about $250,000. Tangem described the everyday risk to customers as “virtually non-existent,” while advising users to keep their wallet cards physically secure.

    Silent Payments flaw could have locked Bitcoin

    BitBox’s second severe vulnerability affected Silent Payments, a Bitcoin privacy feature that allows users to receive payments without publishing a new address for each transaction.

    According to BitBox, a malicious host could exploit the implementation to cause Bitcoin to be locked to an unintended address.

    Direct theft was not possible through the vulnerability, the company said. An attacker could instead leave the victim unable to recover the Bitcoin without cooperation and potentially demand a ransom in exchange for helping unlock the coins.

    Such an attack would not automatically transfer control of the affected Bitcoin to the malicious host, but BitBox said the vulnerability could still put funds at risk by making them inaccessible to their owner.

    The company addressed the problem through its latest firmware update and said it had received no reports of the Silent Payments flaw being exploited.

    BitBox has dealt with other security issues through firmware updates this year. Its Oeschinen update in July included several security fixes, including one for a buffer out-of-bounds write affecting the BitBox02 firmware and bootloader.

    According to the company’s disclosure at the time, a USB request accepted a length value without properly checking it against the size of the destination buffer, creating a potential route for a malicious host to trigger an out-of-bounds write.

    BitBox said no working exploit had been demonstrated for that vulnerability, although an effect on control flow could not be completely ruled out.

    Earlier in January, the company also patched two BitBox02 Nova vulnerabilities reported through its bug bounty programme. BitBox classified the issues as minor and moderate because exploitation required advanced physical access and applied only under specific conditions.

    Coldcard firmware flaw has put wallet security under scrutiny

    BitBox’s update follows the disclosure of a separate Coldcard firmware flaw linked to more than $112 million in stolen Bitcoin after the vulnerability remained undetected for more than five years.

    Galaxy Research said Friday that Coldcard-related losses had exceeded $112 million, with approximately 1,778.6 BTC swept from more than 8,600 addresses.

    The vulnerability was traced to a firmware change introduced in March 2021 that affected the randomness used to generate wallet seeds. Attackers could brute-force impacted seeds and derive the corresponding private keys without obtaining physical access to the hardware wallet, according to research into the incident.

    A wallet seed is used to derive the private keys controlling its cryptocurrency. Weaknesses that reduce the randomness used during seed generation can therefore reduce the number of possible combinations an attacker needs to test.

    For users whose wallets were created with affected Coldcard firmware, updating the device alone would not repair a seed that had already been generated with weak randomness. Moving funds to a wallet created from a newly generated secure seed would be required to remove exposure associated with the compromised seed.

    The incident affected a hardware wallet line that received its first major hardware revision in several years earlier in 2026. Coinkite launched the Coldcard MK5 in March, with the device becoming the first hardware update to its flagship MK series since the MK4 arrived in 2022.

    The MK5 retained the previous model’s dual secure-element architecture using chips from two different vendors and kept private keys air-gapped. Its main changes included a 1.54-inch Gorilla Glass display, redesigned physical buttons and improved NFC functions.

    Coinkite said at the time that the five major MK5 upgrades focused on usability while preserving the security architecture used by the previous model.

    Customer data leaks have created separate phishing risks

    Hardware wallet owners have also faced security incidents outside the devices themselves, with recent breaches involving Trezor and SafePal exposing customer and order information belonging to more than 53,000 people.

    Trezor attributed the exposure of information belonging to 13,689 customers to shipping provider ShipMonk. SafePal separately said an authorisation flaw in an order-tracking plug-in exposed details connected to 39,798 customers.

    Neither incident compromised the companies’ hardware wallets, private keys or recovery phrases, according to the respective disclosures. Both companies warned that exposed personal and order information could instead be used for targeted phishing and impersonation attempts.

    Such information can give attackers details needed to make wallet-related scams appear more credible. Earlier in February, attackers sent physical letters impersonating Trezor and Ledger and instructed recipients to complete supposed authentication or transaction checks.

    The physical phishing campaign used official-looking correspondence containing QR codes that directed recipients to malicious websites. Some letters created urgency by claiming users had to complete an authentication process to avoid problems accessing their wallets.

    The websites asked victims to enter 12-, 20- or 24-word recovery phrases under the pretence of verifying ownership. Once submitted, the phrases were transmitted to the attackers, allowing them to recreate the wallets and gain control over the associated funds.

    Trezor and Ledger said legitimate hardware wallet providers do not ask customers to enter, scan, upload or share recovery phrases through websites or other external channels. Recovery phrases should only be entered directly on a hardware wallet when restoring a wallet, according to the companies.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTether execs are spending big on El Salvador real estate, report
    James Wilson

    Related Posts

    South Korea orders Polymarket block over illegal gambling concerns

    August 18, 2026

    BitMine adds 9,926 ETH as BMNR stock gains 3.7%

    August 18, 2026

    Farcaster seeks new operator seven months after sale

    August 18, 2026
    Leave A Reply Cancel Reply

    Don't Miss

    BitBox patches wallet flaws that could install malicious firmware

    Tether execs are spending big on El Salvador real estate, report

    South Korea orders Polymarket block over illegal gambling concerns

    Is HTX redeeming 80% of TrueUSD?

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    BitBox patches wallet flaws that could install malicious firmware

    August 18, 2026

    Tether execs are spending big on El Salvador real estate, report

    August 18, 2026

    South Korea orders Polymarket block over illegal gambling concerns

    August 18, 2026
    Lithosphere News Releases
    Copyright © 2026

    Type above and press Enter to search. Press Esc to cancel.