Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto
No Result
View All Result
Cryip
No Result
View All Result
Home Crypto News Today Security & Hacks

BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

A month after patching a bootloader bug, BitBox reclassified it as "Severe" the same day it disclosed three new flaws in the BitBox02.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
August 18, 2026
in Security & Hacks
0 0
BitBox’s Dixence Update Fixes Three Flaws, and Upgrades an Older One to “Severe”

Photo by Sora Shimazaki from Pexels/Edited by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Swiss hardware wallet maker BitBox shipped a firmware update on August 17, 2026, patching three security flaws in its BitBox02 device, and on the same day raised the risk rating of an unrelated flaw it had already fixed a month earlier to “Severe.” The fixes close gaps that could have let an attacker manipulate an unconfigured device or redirect a Bitcoin payment under specific conditions. The reassessment of the older flaw, first reported by an outside researcher, adds an unusual twist to what would otherwise read as a routine wallet update.

We just released the Dixence security update.

During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware.

We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings.…

— BitBox (@BitBoxSwiss) August 17, 2026

  • BitBox’s “Dixence” update (firmware 9.26.5) fixes three flaws: a memory corruption issue, a Silent Payments bug, and confirms an earlier bootloader fix.
  • On the same release day, BitBox reclassified a separate flaw from its July “Oeschinen” update, first reported by CertiK researcher Guanxing Wen, as “Severe.”
  • BitBox said it has no reports of exploitation or stolen funds tied to any of the issues.

Three Flaws in the BitBox02

The memory corruption flaw affected BitBox02 Multi and BitBox02 Nova Multi devices that had not yet been set up. A malicious computer connected to one of these unconfigured devices could have executed arbitrary code on it, according to BitBox. The Bitcoin-only edition was not affected, since its firmware does not contain the vulnerable code.

The second flaw involved Silent Payments, a Bitcoin privacy feature. An attacker able to control the connected computer during a Silent Payments transaction could redirect funds to an address the sender never intended, creating what BitBox described as a potential ransom scenario. This affected firmware versions going back to 9.21.0.

The third issue, a bootloader weakness that could have let an attacker use phishing to trick a user into installing fake firmware, was already fixed in July’s Oeschinen update. Dixence’s release notes reconfirm the fix rather than patch it again.

BitBox said none of the three flaws have been exploited and no user funds have been lost. So far, that account comes only from BitBox. The kind of local compromise these flaws require, a malicious host computer or a successful phishing attempt, leaves no on-chain or third-party trail an outside party could check.

A Quiet Upgrade to “Severe”

The more notable move came on the same day, buried in an update to the Oeschinen post rather than in the new announcement. BitBox raised the severity of a buffer out-of-bounds write bug, first flagged by CertiK researcher Guanxing Wen, from its original rating to “Severe,” writing that if exploited it could have enabled theft of user funds. Companies rarely revisit a bug’s severity once they’ve already disclosed and patched it. Doing so a month after the fact suggests BitBox treats its own risk grading as something to keep revising, not a one-time call made at disclosure and left alone.

How BitBox’s Bugs Differ From Coldcard’s

That practice stands out against a rough month for the wallet industry. Coldcard, a competing hardware wallet maker, disclosed a flaw tied to roughly $38 million in losses, found only in its older Mk3 devices, a problem BitBox says its own devices are structurally not exposed to. Unlike a firmware bug, a flawed key-generation process is permanent: a software update fixes future keys but does nothing for ones already created under it. Separately, Trezor disclosed a shipping-partner breach affecting 13,689 customers, and SafePal disclosed a similar breach of its own, a supply-chain and privacy problem rather than a flaw in the wallets themselves.

BitBox’s own flaws sit in a different category from either. They are fixable by firmware update, and none of the three could be triggered without some form of user-side compromise first. The severity label BitBox now applies to its July bug matches the seriousness of the issue on paper, but the practical risk looks narrower than Coldcard’s permanent exposure.

BitBox is recommending that all BitBox02 users update to firmware 9.26.5. The Coldcard loss estimate has itself kept moving, rising to $70.2 million as more affected addresses came to light, a reminder that this month’s wallet-security count is still being tallied. Whether other wallet makers start revisiting their own past severity ratings the way BitBox just did, and whether “no exploitation reported” claims like this one ever become independently checkable, are the two open questions this episode leaves behind.

Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.

To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.

Tags: crypto security
Saravana Kumar Mahendran

Saravana Kumar Mahendran

Saravana Kumar Mahendran is a crypto security analyst and blockchain researcher at Cryip, focusing on DeFi protocol exploits, Web3 security systems, and on-chain investigation. His research applies OSINT and fact-checking methodology to security incidents, drawing on certifications in cybersecurity and data analytics (LinkedIn Learning), and DeFi deep-dive training (Binance Academy). His work has been cited by Sherlock, Rekt.news, and Halborn Security.

Related Posts

Security & Hacks

Revolut Suspected of Leaking Customer Data After Fake Government Request

by Akil Prasath LV
September 12, 2026

Key Facts Revolut is suspected of responding to a spoofed government data request with real customer records. Exposed data reportedly...

Read moreDetails
Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

Cronos Halts Its Own Blockchain After a $75M Tectonic Exploit

August 31, 2026
Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

Ledger Denies Hack Claim After OneKey Reproduces Already-Patched Ethereum Bug

August 28, 2026
Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

Audited Crypto Platforms Lost $3.2 Billion Anyway, New Report Shows

August 27, 2026
Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

Core Lightning Tells Node Operators to Go Offline, Not Shut Down Amid Bug Patch

August 27, 2026
Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

Operation ASTERIX Shows AI Refusals Are a Speed Bump, Not a Stop Sign

August 20, 2026
Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

Binance Says It Stopped a $1.2M DAO Attack, but Won’t Name the Target

August 19, 2026
Next Post

CoinMarketCap Inaccessible for Multiple Users Across India

Arthur Hayes' 'Fair Launch' AI Token Skips the Whitepaper, Not the Hype

Recommended

  • All
  • Crypto News Today
Hyperion DeFi Retires All Legacy Debt and Begins Share Buybacks Funded by HYPE Sales

Hyperion DeFi Retires All Legacy Debt and Begins Share Buybacks Funded by HYPE Sales

October 3, 2026
SBI Holdings Completes Full Acquisition of Bitbank, Japan's Crypto Exchange

SBI Holdings Completes Full Acquisition of Bitbank, Japan’s Crypto Exchange

October 3, 2026
SEC Proposes Custody Framework Letting Advisers and Funds Hold Crypto Assets Directly

SEC Proposes Custody Framework Letting Advisers and Funds Hold Crypto Assets Directly

October 3, 2026

JPMorgan Launches Auto Callable Notes Linked to Spot Bitcoin and Ether ETFs

October 3, 2026
Evernorth Shareholders Approve Armada Merger, Clearing Path to a Nasdaq XRP Listing

Evernorth Shareholders Approve Armada Merger, Clearing Path to a Nasdaq XRP Listing

October 3, 2026
Treasury Sanctions Russia-Linked A7 Network Over $179 Billion in Stablecoin Flows

Treasury Sanctions Russia-Linked A7 Network Over $179 Billion in Stablecoin Flows

October 3, 2026
Greywick Digital Signs MOU With Litecoin Foundation to Deploy cLTC on Canton Network

Greywick Digital Signs MOU With Litecoin Foundation to Deploy cLTC on Canton Network

October 3, 2026
Walapay Raises $4.6 Million Seed Round to Expand Global Payments Infrastructure

Walapay Raises $4.6 Million Seed Round to Expand Global Payments Infrastructure

October 3, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • BNB Plus Corp Pivots From BNB Treasury to Blockchain and AI Infrastructure
  • Hyperion DeFi Retires All Legacy Debt and Begins Share Buybacks Funded by HYPE Sales
  • SBI Holdings Completes Full Acquisition of Bitbank, Japan’s Crypto Exchange

Categories

  • AI News
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Research & Analysis
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • Uncategorized
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Crypto News Today
  • Research & Analysis
  • Learn Crypto

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.