EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

BitBox's Dixence update fixes three vulnerabilities and upgrades an old vulnerability to "critical

2026-08-19 01:03:59
Bookmark

Swiss hardware wallet manufacturer BitBox launched a firmware update for its BitBox02 device on August 17, 2026, fixing three security vulnerabilities, and on the same day raised the risk level of another unrelated vulnerability that was fixed a month ago to "serious". This fix blocks a vulnerability that could allow attackers to manipulate unconfigured devices or redirect Bitcoin payments under certain conditions. A re-evaluation of old vulnerabilities (originally reported by external researchers) adds an unusual twist to otherwise routine wallet updates.

BitBox has released a "Dixence" security update. During an internal audit, we discovered and fixed multiple security issues in BitBox firmware. We recommend that users update application and device firmware through BitBoxApp settings.

BitBox's "Dixence" update (firmware 9.26.5) fixes three vulnerabilities: a memory corruption issue, a Silent Payments vulnerability, and confirms fixes to previous boot loaders. On the same day it was released, BitBox reclassified as "critical" a separate vulnerability in the July "Oeschinen" update that was first reported by CertiK researcher Guanxing Wen. BitBox said it has not received any reports of exploitation or theft of funds related to these issues.

Three vulnerabilities in BitBox02

Memory corruption vulnerability affects BitBox02 Multi and BitBox02 Nova Multi devices that have not yet been set up. According to BitBox, malicious computers connected to these unconfigured devices could execute arbitrary code on them. Versions that only support Bitcoin are not affected because their firmware does not contain vulnerable code.

The second vulnerability involves Silent Payments (Bitcoin privacy feature). During a Silent Payments transaction, an attacker with control over a computer connection could redirect funds to an address the sender never intended to send, which BitBox described as a potential extortion scenario. This vulnerability affects firmware starting with version 9.21.0.

The third problem is a boot loader vulnerability, where attackers could use phishing to trick users into installing fake firmware. The vulnerability was fixed in the July Oeschinen update, and Dixence's release notes only confirmed the fix again rather than re-patched it.

BitBox stated that none of the three vulnerabilities were exploited and there was no loss of user funds. Currently, these claims come only from BitBox. The local attacks required by these vulnerabilities (malicious hosts or successful phishing attempts) leave no on-chain or third-party traces that cannot be verified by outsiders.

quietly escalated to "serious"

The more high-profile move occurred the same day, but this was not through a new announcement, but hidden in updates to Oeschinen's blog. BitBox raised the severity of the buffer out-of-bounds write vulnerability first flagged by CertiK researcher Guanxing Wen from the original rating to "serious" and wrote that if exploited, it could lead to the theft of user funds. Companies rarely revisit the severity of vulnerabilities after disclosing and fixing them. Doing so a month after the incident suggests that BitBox views its risk rating as something that needs to be revised continuously, rather than a one-time decision.

What is the difference between BitBox vulnerability and Coldcard

This approach is particularly prominent during a relatively difficult month for the wallet industry. Rival hardware wallet maker Coldcard disclosed a vulnerability related to approximately $38 million in losses that existed only in its older Mk3 devices, and BitBox said its own devices were structurally unaffected by the issue. Unlike firmware vulnerabilities, a flawed key generation process is permanent: Software updates can fix future keys, but are not effective for keys that have already been generated. In addition, Trezor disclosed a data breach from a transportation partner that affected 13689 customers, and SafePal disclosed a similar data breach, which was a supply chain and privacy issue rather than a vulnerability in the wallet itself.

BitBox's own vulnerabilities belong to a different category from the above two. They can be fixed through firmware updates, and any of the three vulnerabilities must be triggered through some form of client attack. BitBox's severity label now applies to its July vulnerability on paper matches the severity of the problem, but the actual risk looks narrower than Coldcard's permanent exposure. BitBox recommends that all BitBox02 users update to firmware 9.26.5. Coldcard's loss estimate itself is still in flux, rising to $70.2 million as more affected addresses are exposed, a reminder that wallet security statistics are still in progress this month. Whether other wallet makers will revisit their past severity ratings, as BitBox did, and when such claims of "unreported exploitation" will become independently verifiable are two open questions left by this incident.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP