Swiss hardware wallet manufacturer BitBox has disclosed and patched several severe firmware vulnerabilities that could have allowed attackers to install malicious software and potentially steal user funds. The company announced the fixes in a security update on August 17, 2026, and is urging all users to update their devices immediately.
Crucially, BitBox stated there is no evidence the flaws were ever exploited by malicious actors and that no user funds have been lost. The required firmware update, known as “Dixence” (version 9.26.5), resolves the issues. Unlike other recent hardware wallet incidents, users only need to perform the update and do not need to move their bitcoin to a new wallet.
BitBox urges users: Patches Severe Firmware Flaw now
In a blog post and social media announcements, BitBox detailed the findings from an internal security audit. The company stressed the importance of updating through the official BitBoxApp, ideally by using the in-app notification prompt. This method ensures the update is sourced directly from the company and not from a potentially malicious third-party website.
The “Dixence” update addresses multiple issues, with the most critical being a memory corruption bug affecting the Multi edition of its wallets. The company reassured owners of its Bitcoin-only hardware wallets that their devices were not affected by this specific flaw, as the vulnerable code is not included in their firmware.
The proactive discovery and transparent disclosure stand in contrast to other recent industry events. Prominent community figures, such as Dogecoin developer Mishaboar, have supported the call for caution, advising users to perform the update on a clean or newly set-up computer to minimize any risk of malware on the host machine interfering with the process.
This follows a recently published urgent wallet security guide for Bitcoin holders.
Dissecting the vulnerabilities: Memory corruption and silent payments
The internal audit uncovered two new significant vulnerabilities and provided more detail on a previously addressed bootloader issue. The company classified the findings as “severe” due to their potential to compromise the device’s integrity and lead to a loss of funds, even though they were never exploited in the wild.
Memory corruption bug in multi edition wallets
The most serious flaw was a memory corruption bug affecting unconfigured BitBox02 and BitBox02 Nova Multi edition devices. An attacker with control over the host computer could have exploited this vulnerability during the initial setup process to execute arbitrary code.
This would grant them the ability to install malicious firmware, ultimately giving them control over the user’s private keys and any funds held in the wallet.
Flaw in silent payments implementation
A second vulnerability was found in the wallet’s implementation of Silent Payments, a privacy-enhancing feature that allows users to receive bitcoin without reusing addresses. The flaw could have allowed a malicious host to trick the device into locking funds to an unintended address.
While this wouldn’t allow the attacker to directly steal the coins, the legitimate owner would be unable to spend them without the attacker’s cooperation, creating a potential vector for a ransom-style attack.
Previously addressed bootloader issue
BitBox also gave more information on a bootloader vulnerability that was partially fixed in a previous update, “Oeschinen.” This flaw could have been used to deceive a user into confirming the installation of malicious firmware that appeared legitimate. The latest Dixence update fully resolves this attack vector, strengthening the security of the device’s boot process against social engineering attacks.
A stark contrast to the costly Coldcard hack
The BitBox incident provides a sharp contrast to the recent and far more damaging security failure involving Coldcard hardware wallets. While BitBox discovered its flaws internally and deployed a patch before any users lost money, the Coldcard bug went undetected for over five years, resulting in massive real-world losses for its users.
The critical flaw in Coldcard devices, which dated back to a firmware version released in March 2021, caused the wallet to use a weak random number generator when creating a user’s seed phrase. This allowed attackers to brute-force the private keys without ever needing physical access to the device.
According to Galaxy Research, the Coldcard hack losses have now climbed past $112 million, with attackers sweeping approximately 1,778.6 BTC from over 8,600 different addresses.
The fallout from the Coldcard incident required users to urgently migrate all of their funds to new, secure wallets. For BitBox users, the resolution is much simpler and less stressful: a straightforward firmware update with no need to move assets. This highlights the value of continuous internal security audits and a rapid, transparent response.
Hardware wallet security under the microscope
This latest announcement from BitBox comes at a time of heightened scrutiny for the entire hardware wallet sector. In recent months, other major manufacturers have also faced security challenges, eroding some of the trust users place in these devices as the ultimate tool for self-custody. While different in nature, these incidents collectively underscore the complex challenges of securing digital assets.
For example, both Trezor and SafePal have recently dealt with data breaches that exposed the personal and order information of over 53,000 customers. While these breaches did not compromise the wallets or private keys themselves, they exposed users to a significantly higher risk of sophisticated phishing and impersonation attacks. Knowing a person owns a hardware wallet makes them a high-value target for scammers.
These security events, from firmware flaws to data leaks, occur against a backdrop of a volatile market where analysts are already warning of major price movements. One recent Fundstrat analyst prediction warned of a potential 30% swing in Bitcoin’s price, and the added stress of questioning one’s security setup only compounds the difficulty for investors.
The BitBox case serves as a critical reminder that even the most reputable hardware wallets are not infallible and require users to remain vigilant and proactive about security updates.
