BitBox's internal audit uncovered two severe, previously unpatched vulnerabilities.
First, the memory corruption bug in Multi edition variant of BitBox
present through firmware 9.26.4 triggered when then unprovisioned device
i.e. no wallet set up yet was connected to malicious computer, potentially enabling arbitrary code execution and firmware compromise
.Bitcoin-only edition was never affected, as it doesn't contain the vulnerable code path. Second, the flaw in the Silent Payments implementation
present in firmware 9.21.0 - 9.26.4 allowed the infected machine to redirect transaction to an unintended SP address, effectively locking funds rather than stealing them which means that recovery would require the attacker's cooperation.
Officials claim that no exploitation of either bug has been reported , so to be on the safe side all users should update to 9.26.5 via the official BitBoxApp.
Life with hardware wallets is getting funny. Which one next?
