BitBox Patches Two 'Severe' Bitcoin Wallet Firmware Vulnerabilities

BTC

BTC/USDT

$64,335.29
+0.27%
24h Volume

$10,033,774,611.04

24h H/L

$65,058.81 / $64,027.85

Change: $1,030.96 (1.61%)

Long/Short
61.1%
Long: 61.1%Short: 38.9%
Funding Rate

+0.0006%

Longs pay

Data provided by COINOTAG DATALive data
Bitcoin
Bitcoin
Daily

$64,351.62

-0.58%

Volume (24h): -

Resistance Levels
Resistance 3$65,823.31
Resistance 2$64,980.20
Resistance 1$64,371.02
Price$64,351.62
Support 1$63,562.51
Support 2$62,617.14
Support 3$61,056.47
Pivot (PP):$64,604.03
Trend:Uptrend
RSI (14):52.6
(03:33 AM UTC)
4 min read
AI SummaryAI
  • BitBox patched two severe vulnerabilities in its Bitcoin hardware wallet firmware with no funds stolen.
  • Galaxy Research confirmed Coldcard exploit losses exceeded $115 million with more than 200 victims.
  • TRM Labs on-chain analysis showed approximately 1,816 BTC drained from over 5,200 addresses in four waves since July 30.
  • A firmware bug in Coinkite Mk2 and Mk3 devices reduced seed entropy from 128 bits to roughly 40 bits.

Bitcoin News

Bitcoin hardware wallet maker BitBox said Tuesday it had discovered and patched two severe vulnerabilities in its device firmware, telling users in a company blog post that no funds were stolen but urging them to upgrade carefully. The Swiss firm's Dixence security update addresses a flaw that could have let an attacker trick users into installing malicious firmware capable of stealing funds, and a second memory-corruption issue on the BitBox Multi edition that could enable arbitrary code execution, according to the official post. The Bitcoin-only edition is unaffected because its firmware does not contain the vulnerable code. BitBox recommends updating through the official BitBoxApp, ideally via the in-app update prompt rather than searching the web, to avoid downloading counterfeit versions. The company said there are no reports of stolen user funds and no reason for panic, while urging all users to install the latest firmware. The vulnerabilities were uncovered during internal audits, the post notes, underscoring how even dedicated cold-storage devices depend on trustworthy firmware. The announcement arrives as the hardware wallet ecosystem continues to process the Coldcard incident, where a firmware bug in devices from Canadian maker Coinkite caused weak seed generation; Galaxy Research's latest confirmed figures place that theft at $115 million in Bitcoin, with the total potentially rising. Unlike Coldcard users, who were told to migrate funds, BitBox users need only update their firmware rather than move their holdings. BitBox also cautioned that firmware updates obtained outside the official application could themselves become an attack vector.

The damage from the Coldcard exploit has expanded. Galaxy Research's latest figures confirm losses have exceeded $115 million (roughly 18.3 billion yen), with more than 200 victims affected. On-chain analysis from TRM Labs shows the attack unfolded in at least four waves starting July 30, draining approximately 1,816 Bitcoin across more than 5,200 addresses — making it the third-largest cryptocurrency hack of 2026. The root cause is a firmware bug in Coinkite's Mk2 and Mk3 devices, introduced with version 4.0.1 in March 2021, that caused seed generation to fall back to a weak software pseudorandom number generator instead of the hardware true random number generator. This collapsed seed entropy from the designed 128 bits to roughly 40 bits on older models, allowing attackers to guess private keys offline; Mk4, Mk5 and Q models retained only about 72 bits of entropy on pre-fix firmware. Coinkite has released patched firmware — Mk3 version 4.2.0+, Mk4/Mk5 version 5.6.0+, and Q version 1.5.0Q — but cautions that affected seeds remain compromised even after updating. Users must generate entirely new seeds and migrate funds, testing with a small transaction before moving the full balance. Seeds created with 50 or more independent dice rolls retain at least 128 bits of entropy and are not affected by the flaw. Galaxy Research notes the transactions differ in structure across waves, suggesting multiple attacker groups may be involved, though no actors have been identified. TRM Labs' analysis shows the stolen funds remain largely concentrated in a small number of attacker-controlled addresses, with only 64.9 BTC sent to the Wasabi mixer and 200 ETH to Tornado Cash — a laundering pattern distinct from the rapid, organized movement typical of North Korean actors. Coinkite first warned users on July 31, and the confirmed total has climbed as criminals targeted additional devices.

Both incidents converge on a single conclusion: self-custody security depends not on offline storage alone but on the integrity of the wallet's entropy generation and firmware. Coinkite's official advisory requires full seed rotation because a firmware update cannot restore compromised seed security, while BitBox's Dixence update stresses using the in-app upgrade path to avoid malicious downloads. On-chain data from TRM Labs shows the stolen assets remain largely unmoved in a few addresses, with only 64.9 BTC sent to Wasabi and 200 ETH to Tornado Cash — a laundering pattern analysts contrast with North Korea's rapid, organized operations. For Bitcoin holders, the practical takeaway is to verify both the device and the entropy source.

Add COINOTAG as a Preferred Source

Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.

Add on Google
Michael Roberts

Michael Roberts

COINOTAG author

View all posts
AI-AssistedCrypto Research Analyst·Michael Roberts is a crypto research analyst focused on blockchain technology, decentralized finance (DeFi), and Web3 ecosystem developments.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Comments

Comments