Swiss hardware wallet maker BitBox shipped a firmware update on August 17, 2026, patching three security flaws in its BitBox02 device, and on the same day raised the risk rating of an unrelated flaw it had already fixed a month earlier to “Severe.” The fixes close gaps that could have let an attacker manipulate an unconfigured device or redirect a Bitcoin payment under specific conditions. The reassessment of the older flaw, first reported by an outside researcher, adds an unusual twist to what would otherwise read as a routine wallet update.
We just released the Dixence security update.
During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware.
We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings.…
— BitBox (@BitBoxSwiss) August 17, 2026
- BitBox’s “Dixence” update (firmware 9.26.5) fixes three flaws: a memory corruption issue, a Silent Payments bug, and confirms an earlier bootloader fix.
- On the same release day, BitBox reclassified a separate flaw from its July “Oeschinen” update, first reported by CertiK researcher Guanxing Wen, as “Severe.”
- BitBox said it has no reports of exploitation or stolen funds tied to any of the issues.
Three Flaws in the BitBox02
The memory corruption flaw affected BitBox02 Multi and BitBox02 Nova Multi devices that had not yet been set up. A malicious computer connected to one of these unconfigured devices could have executed arbitrary code on it, according to BitBox. The Bitcoin-only edition was not affected, since its firmware does not contain the vulnerable code.
The second flaw involved Silent Payments, a Bitcoin privacy feature. An attacker able to control the connected computer during a Silent Payments transaction could redirect funds to an address the sender never intended, creating what BitBox described as a potential ransom scenario. This affected firmware versions going back to 9.21.0.
The third issue, a bootloader weakness that could have let an attacker use phishing to trick a user into installing fake firmware, was already fixed in July’s Oeschinen update. Dixence’s release notes reconfirm the fix rather than patch it again.
BitBox said none of the three flaws have been exploited and no user funds have been lost. So far, that account comes only from BitBox. The kind of local compromise these flaws require, a malicious host computer or a successful phishing attempt, leaves no on-chain or third-party trail an outside party could check.
A Quiet Upgrade to “Severe”
The more notable move came on the same day, buried in an update to the Oeschinen post rather than in the new announcement. BitBox raised the severity of a buffer out-of-bounds write bug, first flagged by CertiK researcher Guanxing Wen, from its original rating to “Severe,” writing that if exploited it could have enabled theft of user funds. Companies rarely revisit a bug’s severity once they’ve already disclosed and patched it. Doing so a month after the fact suggests BitBox treats its own risk grading as something to keep revising, not a one-time call made at disclosure and left alone.
How BitBox’s Bugs Differ From Coldcard’s
That practice stands out against a rough month for the wallet industry. Coldcard, a competing hardware wallet maker, disclosed a flaw tied to roughly $38 million in losses, found only in its older Mk3 devices, a problem BitBox says its own devices are structurally not exposed to. Unlike a firmware bug, a flawed key-generation process is permanent: a software update fixes future keys but does nothing for ones already created under it. Separately, Trezor disclosed a shipping-partner breach affecting 13,689 customers, and SafePal disclosed a similar breach of its own, a supply-chain and privacy problem rather than a flaw in the wallets themselves.
BitBox’s own flaws sit in a different category from either. They are fixable by firmware update, and none of the three could be triggered without some form of user-side compromise first. The severity label BitBox now applies to its July bug matches the seriousness of the issue on paper, but the practical risk looks narrower than Coldcard’s permanent exposure.
BitBox is recommending that all BitBox02 users update to firmware 9.26.5. The Coldcard loss estimate has itself kept moving, rising to $70.2 million as more affected addresses came to light, a reminder that this month’s wallet-security count is still being tallied. Whether other wallet makers start revisiting their own past severity ratings the way BitBox just did, and whether “no exploitation reported” claims like this one ever become independently checkable, are the two open questions this episode leaves behind.
AI Disclosure: Cryip uses AI-assisted tools to help refine language — correcting spelling and grammar and simplifying complex terms for readability.
We do this to make crypto topics easier to understand for readers at all experience levels. AI does not draft facts, sources, or conclusions. Every article is reviewed and approved by a human editor before publication. Read our full AI Use & Content Policy.
















