
BitBox has released firmware version 9.26.5 as part of the August 2026 "Dixence" security patch, addressing two critical vulnerabilities discovered through internal audits. The company confirmed that neither vulnerability had been exploited in real-world attacks or resulted in user asset losses to date. BitBox is advising all users to update both the BitBoxApp and device firmware to the latest versions, emphasizing that firmware version 9.26.5 is not affected by any of the vulnerabilities disclosed on August 17. The update includes several important security improvements for the BitBox firmware, among other smaller bug fixes and improvements, strengthening sensitive data handling, cryptographic operations, input validation, and protection against unexpected device states.
The first vulnerability is a memory corruption flaw that could enable arbitrary code execution, classified as a critical-severity issue. It affects BitBox02 and BitBox02 Nova Multi edition devices running firmware version 9.26.4 or earlier, specifically when the wallet has not yet completed setup and is connected to a malicious host. A successful attack could trigger memory corruption and arbitrary code execution, potentially allowing malicious firmware to be installed on the hardware wallet. BitBox's Bitcoin-only editions are not affected, as the vulnerable code is not included in their firmware. The exposure was limited to Multi editions that had not yet been set up, with BitBox classifying the vulnerability as severe due to arbitrary code execution potentially undermining protections against unauthorized software running on the hardware wallet. The vulnerability has already been fixed with the Oeschinen release with firmware version 9.26.2, though BitBox engineers discovered it internally and later reported it by external researchers.
The second vulnerability affects Silent Payments, a Bitcoin privacy feature that allows users to receive payments without publishing a new address for each transaction. A malicious host could manipulate transactions so that funds intended for a Silent Payment address become locked at an unintended address, though direct theft was not possible through this vulnerability. Devices running firmware versions 9.21.0 through 9.26.4 are affected when generating Silent Payment transactions while connected to a malicious host. While this flaw does not provide a direct means of stealing bitcoin, recovering the funds may require cooperation between the attacker and the intended recipient, potentially leading to ransom scenarios. BitBox addressed this problem through its latest firmware update and confirmed it had received no reports of the Silent Payments flaw being exploited. There is no direct theft of funds possible, but an attacker would have been able to lock the funds to an unintended payment address for a potential ransom attack, as cooperation between attacker and recipient would be necessary to recover such coins.
BitBox's update follows the disclosure of a separate Coldcard firmware flaw linked to ₹9,000 crore ($112 million) in stolen Bitcoin after the vulnerability remained undetected for more than five years. In July, a seed generation vulnerability in older Coldcard firmware resulted in an estimated $210 million (approximately ₹300 billion won) in cryptocurrency hack losses during July alone. Similar hardware and firmware weaknesses have surfaced at other wallet makers, including a TROPIC01 Secure Element vulnerability affecting Trezor Safe 7 devices and a bootloader vulnerability that was already patched in firmware 9.26.2. Hardware wallet owners have faced additional security incidents outside devices, with recent breaches involving Trezor and SafePal exposing customer information belonging to more than 53,000 people.
BitBox is urging users to install updates only through the existing BitBoxApp or the official BitBox website, and to never enter recovery words into computers, websites, or update prompts. The company emphasizes that hardware wallets are not entirely immune to security threats, as they can still become vulnerable when connected to malicious hosts or exposed to phishing attacks. Particularly with relatively new features like Silent Payments, unexpected flaws can emerge during implementation, making it critical for users to promptly apply security updates provided by manufacturers. Once added, users should ensure their devices are fully updated to protect against both known and potential future vulnerabilities. The recent weeks have seen the most in-depth review effort of BitBox's entire codebase, with the team spending countless hours going over the BitBox software stack. BitBox has received a record amount of security reports from external auditors, mostly using modern AI models to search for issues, with none of these external auditors finding a critical or severe issue.