BitBox shipped the Dixence update after internal AI audits found two severe vulnerabilities plus a bootloader issue.
Exploiting them required a successful phishing attack plus the user unlocking a tampered device.
BitBox says no user funds were stolen and the wallet seed was never at risk.
BitBox, the Zurich-based maker behind the BitBox02, released the Dixence security update this week after its own engineers uncovered two severe flaws in the cryptocurrency wallet’s firmware.
The company disclosed the issues itself, with no evidence they were ever exploited. But the news itself is likely enough to set off the alarms of most Bitcoin holders, given the recent exploit of hardware wallet maker Coldcard that’s resulted in over $130 million in stolen BTC.
Myriad: Bitcoin’s next move? Click to make your prediction.
For BitBox, the first problem lives in the bootloader, the code that decides which firmware a device will accept. A fix shipped in July’s Oeschinen release (v9.26.2) closed most of it, but BitBox now says the original issue was worse than first reported. An attacker who ran a phishing scam—tricking a user into installing a fake BitBoxApp and unlocking the device—could have loaded malicious firmware onto a genuine BitBox02 and walked off with the coins.
The BitBox02 Nova, the newer model, was never exposed because of its bootloader version.
The second severe bug is a memory-corruption flaw in the Multi edition of the BitBox before it’s been set up with a wallet. Paired with a hostile computer, it could allow arbitrary code execution and, again, malicious firmware. The Bitcoin-only edition doesn’t carry the affected code, so it’s clear.
A third issue, less dangerous, touched the wallet’s silent-payment feature. It couldn’t steal coins directly, but could have locked funds to a wrong address in a ransom-style move. All three are fixed in v9.26.5.
BitBox leaned on frontier AI models during its internal review, part of a wider push the company described in a separate post about auditing firmware with AI help.
It’s another reminder that hardware wallets, long considered the ideal choice for security-conscious crypto users, aren’t bulletproof.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.
The Coldcard Bitcoin exploit showed how a five-year-old firmware bug let thieves drain roughly 1,596 BTC, the largest hardware-wallet hack of 2026. Days ago, the data breach of hardware wallet maker SafePal stoked fresh fears of so-called wrench attacks on wallet owners whose personal details, including physical addresses, were exposed.
In this case, BitMox says there’s nothing to worry about besides updating. Per BitBox’s disclosure, “There are no reports of stolen user funds and there is no reason for users to panic.”
The fix is live at bitbox.swiss/download, and older firmware stays exposed until users install it.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.