BitBox fixes severe wallet firmware flaws found during AI-assisted audits

1 week ago 8

BitBox has released firmware version 9.26.5 to fix two severe vulnerabilities and a silent-payment flaw found during internal security reviews that included frontier AI models.

The company said it had no reports that any of the issues were exploited, no user funds were known to have been stolen and wallet seeds were unaffected.

One previously fixed bootloader vulnerability could have allowed an attacker to install malicious firmware on an authentic BitBox02 after first tricking a user into installing a fake BitBoxApp and unlocking the device. BitBox fixed that issue in firmware version 9.26.2.

BitBox02 Nova devices were not affected by the bootloader flaw because they use a newer bootloader version.

A separate memory-corruption vulnerability affected Multi-edition devices that had not yet been set up with a wallet and were connected to a malicious host. It could have enabled arbitrary code execution and malicious firmware installation. Bitcoin-only editions were not affected.

The silent-payment flaw could have directed funds to an unintended address and enabled a ransom attempt, though it did not permit direct theft. Firmware version 9.26.5 fixes both that issue and the memory flaw.

BitBox advised all users to install the latest BitBoxApp from its official website and update their device firmware.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article