Hardware Wallet Provider BitBox Addresses Critical Security Vulnerabilities Threatening User Assets

Hardware Wallet Provider BitBox Addresses Critical Security Vulnerabilities Threatening User Assets

The company urged all users to upgrade to firmware version 9.26.5, confirming no incidents of exploitation or asset theft have been documented.

Cryptocurrency hardware wallet manufacturer BitBox has issued a critical firmware update addressing two security flaws the company characterized as "severe," which had the potential to facilitate the deployment of malicious firmware or compromise user assets.

According to a security advisory published on Monday, BitBox revealed that one vulnerability centered on memory corruption impacting Multi editions of both BitBox02 and BitBox02 Nova devices that had not yet been set up with a wallet. An attacker controlling a malicious host system could leverage this flaw to run arbitrary code and possibly deploy malicious firmware, creating a pathway to asset theft.

The other vulnerability impacted BitBox's Silent Payments feature and could have permitted a malicious host to direct Bitcoin to an incorrect address. While direct fund theft was not feasible, an attacker could theoretically extort victims by demanding payment to assist in fund recovery, BitBox explained. The firm confirmed it had not received any reports indicating either security flaw had been actively exploited or resulted in customer fund losses.

This revelation arrives during a particularly vulnerable period for self-custody solutions, following the discovery of a Coldcard firmware vulnerability that has been connected to over $112 million in Bitcoin losses, highlighting how security weaknesses in devices meant to safeguard private keys can transform into critical points of compromise.

Cointelegraph contacted BitBox seeking additional details but had not received a reply at the time of publication.

BitBox patch follows Coldcard thefts, wallet data leaks

The security patch from BitBox emerges in the wake of numerous hardware wallet security incidents affecting both physical devices and their associated infrastructure.

The most significant breach was the Coldcard security flaw, which originated from a firmware modification implemented in March 2021 that remained unidentified for over five years. This vulnerability compromised wallet-seed randomness, enabling threat actors to brute-force affected wallet seeds and extract their private keys without requiring physical device access.

On Friday, Galaxy Research reported that Coldcard-associated losses had surpassed $112 million, with approximately 1,778.6 BTC drained from over 8,600 addresses.

In more recent developments, distinct data security breaches affecting Trezor and SafePal resulted in the exposure of customer and purchase information for more than 53,000 clients. Trezor linked the leak of 13,689 customers' personal data to its shipping vendor ShipMonk, whereas SafePal indicated that an authorization vulnerability in an order-tracking plugin resulted in the exposure of information belonging to 39,798 customers.

While neither security incident resulted in the compromise of actual devices, private keys or seed phrases, both manufacturers cautioned that the leaked information could facilitate sophisticated phishing campaigns and social engineering attacks targeting their customers.

← Back to Blog