Bitcoin Forum
August 21, 2026, 01:35:05 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: BitBox joins the list - another HW bug surfaces.  (Read 177 times)
satscraper (OP)
Legendary
*
Offline

Activity: 1568
Merit: 2899



View Profile
August 17, 2026, 05:54:57 PM
Last edit: August 17, 2026, 07:47:25 PM by satscraper
Merited by The Sceptical Chymist (5), Lucius (1), hosemary (1)
 #1

BitBox's internal audit uncovered two severe, previously unpatched vulnerabilities.

First, the memory corruption bug in Multi edition variant of BitBox present through firmware 9.26.4 triggered when then unprovisioned device i.e.  no wallet set up yet was connected to  malicious  computer, potentially enabling arbitrary code execution and firmware compromise.Bitcoin-only edition was never affected, as it doesn't contain the vulnerable code path.

 Second, the flaw in the Silent Payments implementation present in firmware 9.21.0 - 9.26.4 allowed the infected machine to redirect  transaction to an unintended SP address, effectively locking funds rather than stealing them which means that recovery would require the attacker's cooperation.

Officials claim that no exploitation of either bug has been reported , so to be on the safe side all users should update to 9.26.5 via the official BitBoxApp.

Life with hardware wallets is getting funny. Which one next? Grin

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Lucius
Legendary
*
Offline

Activity: 4074
Merit: 7727



View Profile WWW
August 18, 2026, 03:02:51 PM
 #2

~snip~
Life with hardware wallets is getting funny. Which one next? Grin


I hope that there won't be another serious case like coldcard, and I really believe that no other manufacturer was stupid enough to do something like that. If nothing else, that case forced everyone else to take a much more serious look at their code and try to find any vulnerabilities.

dkbit98
Legendary
*
Offline

Activity: 3066
Merit: 8833



View Profile WWW
August 18, 2026, 06:08:50 PM
Merited by decodx (1)
 #3

BitBox's internal audit uncovered two severe, previously unpatched vulnerabilities.
I don't see any issue here.
This was just internally identified bug, that happens all the time for hardware wallet devices.
CLosed source wallets don't even report when they find internal bugs, unless customer finds them.

Second, the flaw in the Silent Payments implementation present in firmware 9.21.0 - 9.26.4 allowed the infected machine to redirect  transaction to an unintended SP address, effectively locking funds rather than stealing them which means that recovery would require the attacker's cooperation.
SIlent Payments are still in early phase and I think BitBox is one of the first hardware wallets to support them, so I am not shcoked to see this.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░░░░░░░░░░▀▀██
▄▄██████▄▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
██████████
▐████▌▐████▌
▀▀▀█░░░█▀▀▀
 
satscraper (OP)
Legendary
*
Offline

Activity: 1568
Merit: 2899



View Profile
August 19, 2026, 10:54:13 AM
 #4


I don't see any issue here.


The issue is that BitBox developers only began to scrutinize their code seriously and take notice of its flaws exclusively after Coinkity drama. Until then, they had been complacent. Version 9.26.1 was released in April this year, and for the past four months, the worst might happen.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Z-tight
Legendary
*
Offline

Activity: 1694
Merit: 1320



View Profile
August 20, 2026, 02:10:01 PM
 #5

Life with hardware wallets is getting funny. Which one next? Grin
Every serious hardware wallet manufacturer would have learnt a thing or two from the Coldcard hack, and conducted a serious audit of their system. It is obviously something they should do regularly and many obviously do, but i expect a more thorough check would have happened across so many systems.

The funny part of this is, some people could even fall for phishing scam after this announcement. You know the community is yet to recover from the shock of the Coldcard incident, so as soon as this Bitbox audit hits the news, a lot of their users would become apprehensive, without looking closely into the details. It then becomes a 'good' time for bad actors to swoop in and try to deceive people into exposing their seed to 'protect' their funds. Hopefully, nobody falls for that.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
SquirrelJulietGarden
Hero Member
*****
Offline

Activity: 2100
Merit: 966



View Profile
August 20, 2026, 03:00:13 PM
Merited by The Sceptical Chymist (4)
 #6

Quoting it from another thread for discussion here because that thread was created after this one.

According to BitcoinMagazine, Bitcoin wallet manufacturer BitBox has told users it was able to fix “severe vulnerabilities” with its hardware wallet’s firmware, and reassured users that no funds were taken. Yet it still urged users to upgrade carefully.
BitBox did right urgent alarm to their customers but even they make a mild announcement, people must self aware of the issue's severity and urgently move their funds.

If I was a BitBox user, I would move my bitcoins, my funds to another wallet, that can be Bitcoin Core, Electrum or other multicoin wallet. If I do any upgrade on BitBox wallet, I would like to do it with an empty wallet, and wait for more updates from BitBox, more news from community, and before dust settles, I will not carelessly move my fund back to BitBox wallet.

Lastly, at that time I would like to make a small funding to my Bitbox wallet for testing and see how thing goes.

▄████████████████████████▄
██████████████████████████
██████▀████████████▀██████
████████▀████████▀████████
███▀█████▀████▀█████▀███
████▄▀█▄███▀████▄█▀▄████
██████▄██████▄███▄██████
██████████▄███████████████
██████████████████████████
█████████████████████████
████████████▄█████████████
██████████████████████████
▀████████████████████████▀

.GOATED....
░░░░░░░▄▄▄██████
░░░░▄▄▀██████▀▀▀
░░░███████████
▄████████▄█████
▀▀▄▄██████▄██
██████████████▄
█████▀█████████
█████▄█████████
█▄▄▀██████▀▄██
░░███████████▀▄
░░░▀████████████
░░░░░▀████▄▄▄███
░░░░░░░░░▀▀▀████
▄████████████████▄
█████████████░▄░██
█████████████░▄░██
██████████████████
███▀░░░▀█▀░░░▀████
███░░░░░░░░░░░████
███▄░░░░░░░░░▄████
█████▄░░░░░▄██████
███████▄█████████████
█████████████████████
██░▀░████████████████
██░▀░████████████████
▀████████████████████

....THE #1 CRYPTO CASINO....
|
|
|
.PLAY NOW.
Z-tight
Legendary
*
Offline

Activity: 1694
Merit: 1320



View Profile
August 20, 2026, 04:05:59 PM
 #7

If I was a BitBox user, I would move my bitcoins, my funds to another wallet, that can be Bitcoin Core, Electrum or other multicoin wallet. 
I am not sure that would be necessary, and it is a bad option to move your BTC from a hardware wallet into an online wallet, let alone when you add a multi-coin wallet to the list. I don't think there is any need to panic, it is not new for wallet developers to discover and patch vulnerabilities in their system, and these flaws were not as critical as Coldcard's that had to do with random number generation.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
████████████████████████
████████▄▄██████▄▄██████

████████████████████████
██▄▄█████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
██████▀▀██████▀▀████████
████████████████████████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
█████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀
▄██▀▄██
█████▀▀
███████
████████
▀██▄████
▄████▄▄
▄█████▀███
▄█████▀████
█████▀███████
▀██▀█████████
|  BTC     XMR  
  DAI     LTC  
   Fees  0.8%    
decodx
Hero Member
*****
Offline

Activity: 1512
Merit: 979


#kycfree 🗽


View Profile
August 20, 2026, 04:10:30 PM
 #8


I don't see any issue here.


The issue is that BitBox developers only began to scrutinize their code seriously and take notice of its flaws exclusively after Coinkity drama. Until then, they had been complacent.

This isn't true at all. You’re just pulling narratives out of thin air to push a completely baseless conspiracy.

https://github.com/BitBoxSwiss/bitbox02-firmware/blob/master/CHANGELOG.md

Claiming they only cared about code quality because of the "CoinKite drama" just proves you have zero clue how open-source development or security research actually works.

Quote
Version 9.26.1 was released in April this year, and for the past four months, the worst might happen.

What's the big deal with version 9.26.1? Older firmwares are also affected in different scenarios. But for the "worst to happen", it takes some very specific conditions to align.

Apart from high technical finesse required by the attacker, this would first require a successful phishing attack on the user to get them to install the manipulated firmware, e.g. through a fake version of the BitBoxApp, and unlock their device.

Not exactly "another ColdCard case," right?

▄███████████████████████▄
███████████████████████
████████████▀▀██████████
████████████████████████
██████████▄▄██████████
█████████████████████
███████████████████████
█████████████████████
██████████▀▀██████████
████████████████████████
██████████▄▄████████████
███████████████████████
▀███████████████████████▀
 
 MoBit 
████
██
██
██
██
██
██
██
██
██
██
██
████
 NO   LOGS
 
 LOW  FEES
 
 PGP  GUARANTEE
████
██
██
██
██
██
██
██
██
██
██
██
████
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Forsyth Jones
Legendary
*
Offline

Activity: 2002
Merit: 2205


I love Bitcoin!


View Profile WWW
August 20, 2026, 11:57:12 PM
Merited by The Sceptical Chymist (5)
 #9

It seems the vulnerability involved an attacker tricking the victim into installing malicious firmware on a genuine Bitbox device. In other words, only if the user was deceived in a phishing attempt could their funds be stolen, like downloading malicious firmware from a Bitbox.swiss phishing site.

The other vulnerability, a memory corruption issue affecting the multi-version, really caught my attention. From what I get it, exploitation doesn't depend on remote access or phishing, it simply requires connecting the affected version of Bitbox to a malicious PC with code that alters the installation of malicious firmware. However, the article doesn't specify whether this flaw is exploited "under the rug" (without any user action or without them noticing).

In theory, people use USB hardware wallets expecting them to protect their funds, even if a PC is infested with malware and infostealers. This is the premise that practically all manufacturers preach: "your seed phrase doesn't leave the device, even if it's connected to a host via USB full of malware". Does this prove that this isn't quite how we should think from now on?

This reinforces once again the maximalist discourse that the more code and support for different blockchains and coins, the greater the chances of finding some vulnerability, since only the multicoin edition of both bitbox02 and bitbox02 nova were affected if they haven't been configured yet.

The Sceptical Chymist
Legendary
*
Offline

Activity: 4172
Merit: 7368


♻️ Automatic Exchange


View Profile
Today at 01:29:33 AM
 #10

they make a mild announcement, people must self aware of the issue's severity and urgently move their funds.

Yeah, I kind of thought the announcement was 'mild' as well, but then again I'm not subscribed to anything they put out via e-mail or anything else (assuming they have something like that).  Hopefully they caught all that needed to be caught as far as security issues that could result in who-knows-what for their customers.  I definitely don't like having to download updates on an emergency basis, but given what's happened with other HW wallets, I'm not sure how much of a choice I had.

In theory, people use USB hardware wallets expecting them to protect their funds, even if a PC is infested with malware and infostealers. This is the premise that practically all manufacturers preach: "your seed phrase doesn't leave the device, even if it's connected to a host via USB full of malware". Does this prove that this isn't quite how we should think from now on?

This reinforces once again the maximalist discourse that the more code and support for different blockchains and coins, the greater the chances of finding some vulnerability, since only the multicoin edition of both bitbox02 and bitbox02 nova were affected if they haven't been configured yet.

Being tech-retarded, I'm very interested in what the smarter folks have to say about this, because it seems like a good question Forsyth Jones is asking.

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
 
    ANN THREAD    
 
      TUTORIAL      
Abiky
Legendary
*
Offline

Activity: 4032
Merit: 1528


View Profile
Today at 02:09:05 AM
 #11

BitBox's internal audit uncovered two severe, previously unpatched vulnerabilities.

First, the memory corruption bug in Multi edition variant of BitBox present through firmware 9.26.4 triggered when then unprovisioned device i.e.  no wallet set up yet was connected to  malicious  computer, potentially enabling arbitrary code execution and firmware compromise.Bitcoin-only edition was never affected, as it doesn't contain the vulnerable code path.

 Second, the flaw in the Silent Payments implementation present in firmware 9.21.0 - 9.26.4 allowed the infected machine to redirect  transaction to an unintended SP address, effectively locking funds rather than stealing them which means that recovery would require the attacker's cooperation.

Officials claim that no exploitation of either bug has been reported , so to be on the safe side all users should update to 9.26.5 via the official BitBoxApp.

Life with hardware wallets is getting funny. Which one next? Grin

We're now seeing vulnerabilities come up all of a sudden after the AI boom. Weird, isn't it? If AI wouldn't had existed, such vulnerabilities would've gone unnoticed. It seems that hardware wallets aren't as safe as we thought they would be. That's what we get for trusting companies, instead of doing things all by ourselves. Blockchain is all about "don't trust, verify".

It might be time to move away from hardware wallets, and head back to DIY cold storage methods. In the case of Bitcoin, an airgapped PC running Electrum offline, is all we need to store BTC securely. At least, BitBox patched the vulnerabilities before they became a problem. But ColdCard? It's history. I sure hope Trezor doesn't get affected too. Would you imagine that?
X-ray
Hero Member
*****
Offline

Activity: 3710
Merit: 567


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 04:10:56 AM
 #12

At least they caught the bug and fixed it, this is exactly why internal audit should be done more frequently.

The other vulnerability, a memory corruption issue affecting the multi-version, really caught my attention. From what I get it, exploitation doesn't depend on remote access or phishing, it simply requires connecting the affected version of Bitbox to a malicious PC with code that alters the installation of malicious firmware. However, the article doesn't specify whether this flaw is exploited "under the rug" (without any user action or without them noticing).

In theory, people use USB hardware wallets expecting them to protect their funds, even if a PC is infested with malware and infostealers. This is the premise that practically all manufacturers preach: "your seed phrase doesn't leave the device, even if it's connected to a host via USB full of malware". Does this prove that this isn't quite how we should think from now on?

This reinforces once again the maximalist discourse that the more code and support for different blockchains and coins, the greater the chances of finding some vulnerability, since only the multicoin edition of both bitbox02 and bitbox02 nova were affected if they haven't been configured yet.
The memory corruption that allow arbitrary code execution that can potentially be misused to install malicious firmware only exist before the device is initialized, after the wallet is created the vulnerability doesn't exist anymore which means connecting to a host via USB won't execute arbitrary code.

Without the bug, the device theoretically should be safe even if you connected to compromised host machine. To be frank, if you think your host machine is full of malware, you should do a complete reinstall.

This problem also happened only to Bitbox firmware, the other hardware wallets don't have the same problem, therefore I don't think we can generalize this problem to other hardware wallets.

Anyway, more code will always resulted in more attack surfaces, after all you need to deal with more moving parts.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!