BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

BitBox Wallet Flaws Emerge After Coldcard Exploit Led to…

What Did BitBox Fix? Hardware wallet maker BitBox has released a firmware update addressing two vulnerabilities it classified as severe, including one that could have allowed attackers to ins

AnonymousCryptoCompass newsroom
August 18, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.

AFX Scrambles After $24M Hack Traced to One Dev

What Did BitBox Fix?

Hardware wallet maker BitBox has released a firmware update addressing two vulnerabilities it classified as severe, including one that could have allowed attackers to install malicious firmware and potentially steal user funds. The first vulnerability involved memory corruption affecting Multi editions of the BitBox02 and BitBox02 Nova before a wallet had been configured on the device. According to BitBox’s security disclosure, a malicious host connected to an affected wallet could exploit the flaw to execute arbitrary code. That access could potentially be used to install malicious firmware. If successful, an attacker could interfere with the wallet’s operation and create a path toward the loss of funds once the device was used. The second vulnerability affected BitBox’s implementation of Silent Payments, a Bitcoin privacy feature designed to allow users to receive payments without repeatedly publishing new addresses. A malicious host could potentially manipulate the process so Bitcoin was locked to an unintended address. BitBox said the flaw could not be used to steal the funds directly. However, an attacker controlling information needed to recover the coins could potentially demand a ransom in exchange for cooperation. The company said it had received no reports that either vulnerability had been exploited and was not aware of users losing funds because of the flaws.

Why Are Hardware Wallet Firmware Flaws So Serious?

Hardware wallets are designed to isolate private keys from internet-connected computers and phones, reducing exposure to malware and remote attacks. That protection depends heavily on the security of the device’s firmware and the processes used to verify transactions. A vulnerability that allows arbitrary code execution can weaken that isolation. Even if an attacker cannot immediately extract a private key, malicious firmware may be able to manipulate what users see, change transaction behavior or interfere with wallet creation. The BitBox issue affecting unconfigured devices is particularly relevant because it involves the stage before a wallet is fully initialized. Users often assume that a new hardware wallet is safe as long as the physical device has not been tampered with, but software flaws can create additional attack routes when the device interacts with a compromised computer.

Investor Takeaway

Self-custody removes exchange counterparty risk but replaces it with responsibility for device security, firmware updates and recovery procedures. Hardware wallets remain useful security tools, but their protection depends on both secure hardware and continuously tested software.

How Does The BitBox Patch Compare With The Coldcard Exploit?

The disclosure arrives after a much more damaging hardware wallet failure involving Coldcard devices. A firmware change introduced in March 2021 weakened wallet-seed randomness and remained undetected for more than five years. The flaw allowed attackers to brute-force vulnerable wallet seeds and derive private keys remotely without gaining physical possession of the devices. Galaxy Research said Friday that losses linked to the Coldcard exploit had exceeded $112 million. About 1,778.6 Bitcoin had been swept from more than 8,600 addresses. The difference between the incidents is important. BitBox said it found no evidence that its vulnerabilities had been exploited, while the Coldcard flaw was connected to large confirmed losses before the weakness became widely known. Still, both cases show that self-custody security is not limited to protecting seed phrases from theft. Wallet-generation code, firmware validation, transaction signing and communication between a hardware wallet and its host device can all become attack surfaces.

Are Hardware Wallet Users Facing Wider Security Risks?

Recent incidents involving Trezor and SafePal have added another concern: customer information stored by companies and their service providers. Separate data breaches exposed customer and order information belonging to more than 53,000 users. Trezor said data involving 13,689 customers was exposed through shipping provider ShipMonk, while SafePal said an authorization flaw in an order-tracking plug-in exposed information belonging to 39,798 customers. Neither breach compromised hardware devices, private keys or recovery phrases. The exposed customer information could still be valuable to attackers because names, contact details and purchase histories can be used to build more convincing phishing and impersonation campaigns targeting known cryptocurrency holders. The series of incidents shows that hardware-wallet security extends beyond the physical device. Users depend on firmware developers, supply chains, companion applications and third-party service providers, each of which can introduce different forms of risk. For BitBox users, the immediate priority is installing the patched firmware and ensuring devices are updated through official software. More broadly, hardware wallet owners should treat firmware updates as part of routine self-custody security rather than assuming that an offline private key alone eliminates the risk of losing cryptocurrency.