Swiss hardware wallet maker BitBox has released the Dixence firmware update, version 9.26.5, patching two vulnerabilities the company called "severe." Its own engineers found the flaws during an internal code review assisted by artificial intelligence. The company says there are no confirmed reports of stolen funds or exploitation attempts.
What happened
BitBox02 and BitBox02 Nova are hardware wallets made by Zurich-based Shift Crypto, sold in two editions: Bitcoin-only for BTC holders and Multi for those who also store Ethereum, ERC-20 tokens and other coins. The company disclosed the vulnerabilities itself on Monday, in a post about auditing its firmware with frontier AI models.
The Dixence update fixes a bug in the bootloader, the code that decides which firmware a device will accept. A partial fix shipped back in July, in version 9.26.2, but BitBox now says the original issue was worse than first reported. The company said the AI-assisted code review is what caught the additional impact that the first patch missed.
Exploiting the flaw required a phishing attack: tricking a user into installing a fake BitBoxApp and unlocking the device. Only then could an attacker load malicious firmware onto a genuine BitBox02 and seize control of it. The newer BitBox02 Nova was never exposed, thanks to a newer bootloader version already installed at the factory.
Details of the flaws
The second severe bug is memory corruption in the Multi edition of the wallet, before a specific user wallet has been set up on it. A hostile computer connected to the device in that state could exploit it to execute arbitrary code and install malicious firmware without the owner noticing. The Bitcoin-only edition doesn't carry the affected code, so it was never at risk. The attack only worked during that in-between, not-yet-configured state, meaning the risk mostly applied to new, just-unboxed devices.
A third, less dangerous issue also made the fix list. It touched the Silent Payments feature, a Bitcoin privacy tool that lets a sender generate a one-time address without querying the recipient's wallet directly. It couldn't steal coins directly, but it could lock funds to the wrong address, opening the door to a ransom-style demand for their return, even without physical access to the victim's device.
A wave of hardware wallet incidents
BitBox's disclosure follows a string of high-profile hardware wallet incidents that have piled up over the past several months. The most damaging remains Coldcard. A five-year-old firmware bug, dating back to March 2021, went unnoticed for years while allowing attackers to brute-force weak seed randomness and derive private keys.
Galaxy Research estimates Coldcard-related losses topped $112 million. Attackers swept roughly 1,596 BTC from more than 8,600 addresses, making it the largest hardware wallet hack of 2026. Across July alone, crypto holders lost an estimated $247 million to similar attacks, the second-worst month of the year by researchers' count. Separately, data breaches at Trezor and SafePal exposed more than 53,000 customers and stoked fears of so-called wrench attacks, where attackers track down victims through their physical address.
- Trezor traced its breach to shipping partner ShipMonk, affecting 13,689 customers
- SafePal blamed an authorization flaw in a third-party order system
- Coldcard remains the year's largest hardware wallet hack, with losses above $112 million
After this string of incidents, hardware wallet makers have started publicly detailing their own internal audits, trying to show the market that problems aren't being swept under the rug. BitBox tied its own case directly to that broader industry context, saying disclosure transparency matters more than short-term reputational risk.
What the company recommends
BitBox insists there's no reason to panic, but urges all users to update to version 9.26.5 through the official BitBoxApp. Older firmware stays exposed until the update is installed manually, so the company advises against delaying the step for anyone, even owners of the newer BitBox02 Nova.
"There are no reports of stolen user funds and there is no reason for users to panic."
- from BitBox's official vulnerability disclosure, August 17, 2026
The practical steps are simple. Check the current firmware version inside the BitBoxApp, download updates only from the official bitbox.swiss site, and never plug the device into an unfamiliar or suspicious computer during first setup. The same rules apply to owners of other hardware wallet models too, since that first setup remains the most vulnerable stage regardless of the maker.
The past few months carry a simple reminder. Even hardware wallets, long considered the gold standard for protecting the private keys of Bitcoin holders, aren't immune to coding mistakes. The real difference lies in how fast a maker finds and patches a flaw before attackers get to it first. For anyone storing assets on their own, checking firmware versions is becoming as routine as backing up a seed phrase.




Comments
Your email address will not be published. Required fields are marked *