BitBox Fixes Two Severe Hardware Wallet Vulnerabilities In Dixence Update
BitBox has released its August 2026 Dixence security update after internal audits uncovered two severe vulnerabilities in its hardware wallet firmware, including a memory corruption flaw capable of enabling arbitrary code execution.
The Dixence update fixes both vulnerabilities with firmware version 9.26.5. BitBox has not identified any exploitation or stolen user funds tied to either flaw and is recommending that all users update their BitBoxApp and device firmware.
Memory Flaw Could Allow Malicious Firmware
The first vulnerability affects Multi editions of the BitBox02 and BitBox02 Nova through firmware version 9.26.4 when a device has not yet been set up with a wallet and is connected to a malicious host.
Successful exploitation could trigger memory corruption and arbitrary code execution, potentially allowing malicious firmware to be installed on the hardware wallet. BitBox’s Bitcoin-only edition is not affected because its firmware does not contain the vulnerable code.
The disclosure arrives weeks after vulnerable seed generation in older Coldcard firmware became the largest crypto security loss recorded in July. The Coldcard-linked drain led an estimated $210.3 million in crypto hack losses during the month, with affected firmware producing Bitcoin seeds with substantially less randomness than intended.
Silent Payment Flaw Could Lock Bitcoin Funds
A second BitBox vulnerability affects its Silent Payments implementation. A malicious host could manipulate a transaction so that funds intended for a Silent Payment address were instead locked to an unintended address.
The flaw did not provide a direct mechanism for stealing the bitcoin. Recovery could require cooperation from the attacker and intended recipient, creating a potential ransom scenario. BitBox02 and BitBox02 Nova devices running firmware versions 9.21.0 through 9.26.4 may be affected when creating a Silent Payment transaction while connected to a malicious host.
Hardware wallet manufacturers have faced several unrelated security disclosures this year. Trezor disclosed a separate TROPIC01 secure-element vulnerability affecting one physical security layer in the Safe 7 in June, although that attack required physical possession, specialized equipment and did not expose wallet backups or funds.
Earlier Bootloader Weakness Was Already Patched
BitBox also provided new details on a separate bootloader weakness already fixed in firmware version 9.26.2. That attack could have manipulated a user into installing malicious firmware on an authentic BitBox02 after first compromising them through a fake BitBoxApp or similar phishing route. BitBox02 Nova devices are not affected by that older bootloader path.
Users should install updates through the existing BitBoxApp or the official BitBox website and never enter recovery words into a computer, website or update prompt. BitBox firmware version 9.26.5 is not affected by any of the vulnerabilities covered in the August 17 disclosure.




Post Comment
You must be logged in to post a comment.