Summary
- BitBox has released the Dixence update after AI assessments revealed two significant vulnerabilities and an issue with the bootloader.
- Exploitation would necessitate a phishing attack and the user unlocking a compromised device.
- The company assures that no user funds were compromised and the wallet seed remained secure.
BitBox, headquartered in Zurich and the creator of the BitBox02 wallet, has launched the Dixence security update following the discovery of two major vulnerabilities in its firmware through internal AI audits.
The company proactively reported these vulnerabilities, noting that there is no evidence indicating they had been exploited. However, this revelation may raise concerns among Bitcoin users, especially following a recent incident involving hardware wallet manufacturer Coldcard, which resulted in the theft of over $130 million in Bitcoin.
Myriad: What’s next for Bitcoin? Make your prediction here.The first identified issue pertains to the bootloader, which controls the firmware a device can utilize. A fix was introduced in the Oeschinen release (v9.26.2) in July, but BitBox has since determined that the original concern was more serious than initially thought. An attacker could potentially execute a phishing scheme, tricking a user into installing a fraudulent BitBoxApp and unlocking the device, thereby allowing them to install malicious firmware on a legitimate BitBox02 and steal funds.
The newer BitBox02 Nova model was not affected due to its different bootloader version.
The second critical flaw involves memory corruption in the Multi edition of the BitBox before it is configured with a wallet. If paired with a hostile computer, this could facilitate arbitrary code execution and potentially malicious firmware installation. Fortunately, the Bitcoin-only edition does not contain the compromised code and is unaffected.
A third, less severe issue involved the wallet's silent-payment feature, which, while not capable of directly stealing funds, could have redirected them to an incorrect address in a ransom-like scenario. All three vulnerabilities have been addressed in the updated version v9.26.5.
BitBox utilized advanced AI models during its internal review as part of a broader initiative discussed in a separate blog post regarding the importance of AI in auditing firmware.
This situation serves as a reminder that while hardware wallets are generally viewed as the safest option for security-minded crypto enthusiasts, they are not infallible.
Myriad: When will GPT-6 be unveiled? Share your prediction.The Coldcard exploit highlighted how a five-year-old firmware vulnerability allowed hackers to steal approximately 1,596 BTC, marking the largest hardware wallet hack of 2026. Recently, the data breach at hardware wallet manufacturer SafePal has raised new concerns about potential wrench attacks, exposing wallet owners’ personal information, including their physical addresses.
In light of these events, BitBox reassures users that there is no cause for alarm beyond installing the update. According to BitBox, "There are no reports of stolen user funds and there is no reason for users to panic."
The update can be accessed at bitbox.swiss/download, while older firmware remains vulnerable until users complete the update.