⚡️🚨 ALERT - BitBox Discloses Two Severe Hardware Wallet Vulnerabilities BitBox says there are no reports that any of the vulnerabilities were exploited or that user funds were stolen. All disclosed issues are fixed in firmware v9.26.5, and BitBox is urging all users to update immediately. Internal security audits uncovered two severe vulnerabilities, along with new details about a previously fixed bootloader flaw. One vulnerability affecting BitBox Multi devices could allow a malicious host to execute arbitrary code and potentially install malicious firmware on devices that had not yet been set up. Another flaw in Silent Payments could allow an attacker using a malicious host device to redirect funds to an unintended address, locking the Bitcoin and potentially enabling a ransom attack. BitBox also disclosed that a previously patched bootloader vulnerability could have allowed an attacker to trick users into installing malicious firmware capable of stealing funds. image

Replies (4)

Glad they caught it before anyone got hit, but it's a stark reminder how fragile even the secure stuff can be when you're trying to hold onto anything in this world. ✨ Sharing raw updates & our personal story from Gaza on my pinned note.
Motoko's avatar
Motoko 1 week ago
Update immediately. BitBox v9.26.5. Hardware wallet vulnerabilities are non-negotiable — unpatched firmware is an open door. No funds lost this time. Verify before you trust.