- BitBox released firmware 9.26.5 to fix two severe vulnerabilities.
- The flaws could have enabled malicious firmware or misdirected Bitcoin.
- BitBox said it has no reports of exploitation or fund losses.
The BitBox update is the focus of a new security disclosure from the hardware wallet maker, which urged all users to install firmware version 9.26.5 after identifying two severe vulnerabilities. According to the company, one flaw could have allowed a malicious host to execute arbitrary code and potentially install harmful firmware on certain unconfigured devices, while another could have caused Bitcoin sent through Silent Payments to be locked to an unintended address. BitBox said it has not received any reports that either issue was exploited or caused fund losses. The BitBox update arrives as hardware wallet security faces closer scrutiny across the broader self-custody market.
BitBox update fixes two severe flaws
BitBox said the new firmware corrects two separate issues that it classified as severe. The company recommended that all users update to version 9.26.5. Its disclosure said the vulnerabilities could have created serious security risks, including unauthorized code execution and scenarios in which user funds could be placed in danger.
One flaw involved memory corruption affecting Multi editions of BitBox02 and BitBox02 Nova that had not been configured with a wallet. BitBox said a malicious host could have exploited that weakness to run arbitrary code and possibly install malicious firmware. In the company’s assessment, that chain of events could have led to lost funds.
Silent Payments issue in the BitBox update
The second issue covered by the BitBox update involved the company’s Silent Payments implementation. BitBox said a malicious host could have exploited the flaw to lock Bitcoin to an unintended address. While the company said direct theft was not possible in that scenario, it warned that an attacker could potentially demand a ransom in exchange for helping recover the coins.
BitBox also said it had no reports that either vulnerability had been used in the wild. It added that it had not seen any cases of user fund losses linked to the two issues. Cointelegraph said it contacted BitBox for more detail, but the company did not respond before publication.
BitBox update lands amid wallet security pressure
The BitBox update was disclosed at a sensitive time for self-custody products. The source noted that a Coldcard firmware flaw was recently linked to more than $112 million in Bitcoin thefts, underscoring how weaknesses in tools built to protect private keys can become major failure points.
Galaxy Research said on Friday that Coldcard-related losses had exceeded $112 million, with about 1,778.6 BTC swept from more than 8,600 addresses. According to the source, that flaw stemmed from a March 2021 firmware change that went undetected for more than five years and affected wallet-seed randomness, allowing attackers to brute-force impacted seeds and derive private keys without physical access.
Broader hardware wallet risks
The source also pointed to separate breaches involving Trezor and SafePal, showing that hardware wallet risks are not limited to device firmware. Together, those incidents exposed customer and order information tied to more than 53,000 customers. Trezor said the data exposure of 13,689 customers was linked to shipping provider ShipMonk.
SafePal said an authorization flaw in an order-tracking plug-in exposed details belonging to 39,798 customers. Neither case affected devices, private keys or recovery phrases, but both companies warned that the stolen information could support targeted phishing and impersonation attempts. That context adds to the significance of the BitBox update, even though BitBox said it has seen no exploitation or losses.
Conclusion
The BitBox update to firmware version 9.26.5 addresses two severe vulnerabilities that the company said could have enabled malicious firmware installation or caused Bitcoin to be locked to an unintended address. One issue affected unconfigured Multi editions of BitBox02 and BitBox02 Nova, while the other involved Silent Payments. BitBox said it has not received any reports of exploitation or fund losses tied to either flaw. Even so, the BitBox update comes during a period of elevated concern around hardware wallet security, following major Coldcard-linked thefts and customer data exposures at Trezor and SafePal that highlight the wider risks facing self-custody users.
Disclaimer
The information provided in this article is for informational purposes only and should not be considered financial advice. The article does not offer sufficient information to make investment decisions, nor does it constitute an offer, recommendation, or solicitation to buy or sell any financial instrument. The content is opinion of the author and does not reflect any view or suggestion or any kind of advise from CryptoNewsBytes.com. The author declares he does not hold any of the above mentioned tokens or received any incentive from any company.
Featured image created by AI

