The company disclosed the issues itself, with no evidence they were ever exploited. But the news itself is likely enough to set off the alarms of most Bitcoin holders, given the recent exploit of hardware wallet maker Coldcard that’s resulted in over $130 million in stolen BTC.
Myriad: Bitcoin's next move? Click to make your prediction.For BitBox, the first problem lives in the bootloader, the code that decides which firmware a device will accept. A fix shipped in July's Oeschinen release (v9.26.2) closed most of it, but BitBox now says the original issue was worse than first reported. An attacker who ran a phishing scam—tricking a user into installing a fake BitBoxApp and unlocking the device—could have loaded malicious firmware onto a genuine BitBox02 and walked off with the coins.
The BitBox02 Nova, the newer model, was never exposed because of its bootloader version.
The second severe bug is a memory-corruption flaw in the Multi edition of the BitBox before it's been set up with a wallet. Paired with a hostile computer, it could allow arbitrary code execution and, again, malicious firmware. The Bitcoin-only edition doesn't carry the affected code, so it's clear.
A third issue, less dangerous, touched the wallet's silent-payment feature. It couldn't steal coins directly, but could have locked funds to a wrong address in a ransom-style move. All three are fixed in v9.26.5.
It’s another reminder that hardware wallets, long considered the ideal choice for security-conscious crypto users, aren't bulletproof.
Myriad: When will OpenAI release GPT-6? Click to make your prediction. In this case, BitMox says there’s nothing to worry about besides updating. Per BitBox's disclosure, "There are no reports of stolen user funds and there is no reason for users to panic."


















