started · updated
BitBox patches critical firmware flaws in hardware wallets
Swiss hardware wallet manufacturer BitBox, operated by Shift Crypto AG, has disclosed and patched two critical firmware vulnerabilities affecting its BitBox02 and BitBox02 Nova devices. The flaws were identified through internal security audits utilizing advanced AI models.
The first vulnerability involved memory corruption on unconfigured “Multi” edition devices, which could potentially allow an attacker to execute arbitrary code or install unauthorized firmware. The second flaw affected the Silent Payments feature, creating a risk where user funds could be inadvertently locked at incorrect addresses. BitBox noted that this second issue posed an accidental-loss risk rather than a direct theft scenario.
No funds have been stolen and no existing wallet seeds have been affected by these vulnerabilities. The company has released a fix in the Dixence firmware update, version 9.26.5, and is urging all users to update immediately through official channels to avoid phishing attempts.