Hardware wallet shaper BitBox has released a firmware update that fixes 2 vulnerabilities it described arsenic “severe” that could person enabled the installation of malicious firmware oregon enactment idiosyncratic funds astatine risk.
In a information disclosure connected Monday, BitBox said 1 progressive representation corruption affecting Multi editions of BitBox02 and BitBox02 Nova that had not been configured with a wallet. A malicious big could exploit it to execute arbitrary codification and perchance instal malicious firmware, which could pb to mislaid funds.
The 2nd affected BitBox’s Silent Payments implementation and could person allowed a malicious big to fastener Bitcoin to an unintended address. Direct theft was not possible, but an attacker could perchance request a ransom to cooperate successful recovering the coins, according to BitBox. The institution said it had received nary reports of either vulnerability being exploited oregon causing users to suffer funds.
The disclosure comes astatine a delicate infinitesimal for self-custody, aft a Coldcard firmware flaw was linked to much than $112 cardinal successful Bitcoin thefts, underscoring however weaknesses successful devices designed to support backstage keys tin go points of failure.
Cointelegraph reached retired to BitBox for much accusation but did not person a effect earlier publication.
BitBox spot follows Coldcard thefts, wallet information leaks
The BitBox information update follows a question of hardware-wallet incidents involving devices and the services surrounding them.
The astir damaging was the Coldcard flaw, which traced to a March 2021 firmware change that went undetected for much than 5 years. The vulnerability affected wallet-seed randomness, allowing attackers to brute-force impacted wallet seeds and deduce their backstage keys without carnal access.
Galaxy Research said Friday that Coldcard-related losses had exceeded $112 million, with astir 1,778.6 BTC swept from much than 8,600 addresses.
Related: Coldcard exploit pushes July losses to $247M arsenic second-worst period of 2026
More recently, separate information breaches involving Trezor and SafePal exposed lawsuit and bid accusation belonging to much than 53,000 customers. Trezor attributed the vulnerability of 13,689 customers’ information to shipping supplier ShipMonk, portion SafePal said an authorization flaw successful an order-tracking plug-in exposed details belonging to 39,798 customers.
Neither incidental compromised devices, backstage keys oregon betterment phrases, but some companies warned that the accusation could alteration targeted phishing and impersonation attacks.
Magazine: Do the Coldcard attacks mean each hardware wallets are present insecure?
Cointelegraph is committed to independent, transparent journalism. This quality nonfiction is produced successful accordance with Cointelegraph’s Editorial Policy and aims to supply close and timely information. Readers are encouraged to verify accusation independently.

1 hour ago









English (US)