In short
- BitBox shipped the Dixence replace after inside AI audits discovered two extreme vulnerabilities plus a bootloader concern.
- Exploiting them required a profitable phishing assault plus the consumer unlocking a tampered gadget.
- BitBox says no consumer funds have been stolen and the pockets seed was by no means in danger.
BitBox, the Zurich-based maker behind the BitBox02, launched the Dixence safety replace this week after its personal engineers uncovered two extreme flaws within the cryptocurrency pockets’s firmware.
The corporate disclosed the problems itself, with no proof they have been ever exploited. However the information itself is probably going sufficient to set off the alarms of most Bitcoin holders, given the latest exploit of {hardware} pockets maker Coldcard that’s resulted in over $130 million in stolen BTC.

For BitBox, the primary downside lives within the bootloader, the code that decides which firmware a tool will settle for. A repair shipped in July’s Oeschinen launch (v9.26.2) closed most of it, however BitBox now says the unique concern was worse than first reported. An attacker who ran a phishing rip-off—tricking a consumer into putting in a faux BitBoxApp and unlocking the gadget—might have loaded malicious firmware onto a real BitBox02 and walked off with the cash.
The BitBox02 Nova, the newer mannequin, was by no means uncovered due to its bootloader model.
The second extreme bug is a memory-corruption flaw within the Multi version of the BitBox earlier than it has been arrange with a pockets. Paired with a hostile pc, it might permit arbitrary code execution and, once more, malicious firmware. The Bitcoin-only version does not carry the affected code, so it is clear.
A 3rd concern, much less harmful, touched the pockets’s silent-payment characteristic. It could not steal cash immediately, however might have locked funds to a incorrect tackle in a ransom-style transfer. All three are fastened in v9.26.5.
BitBox leaned on frontier AI fashions throughout its inside evaluation, a part of a wider push the corporate described in a separate put up about auditing firmware with AI assist.
It’s one other reminder that {hardware} wallets, lengthy thought-about the best alternative for security-conscious crypto customers, aren’t bulletproof.

The Coldcard Bitcoin exploit confirmed how a five-year-old firmware bug let thieves drain roughly 1,596 BTC, the biggest hardware-wallet hack of 2026. Days in the past, the information breach of {hardware} pockets maker SafePal stoked contemporary fears of so-called wrench assaults on pockets homeowners whose private particulars, together with bodily addresses, have been uncovered.
On this case, BitMox says there’s nothing to fret about moreover updating. Per BitBox’s disclosure, “There are not any stories of stolen consumer funds and there’s no purpose for customers to panic.”
The repair is reside at bitbox.swiss/obtain, and older firmware stays uncovered till customers set up it.
Each day Debrief Publication
Begin each day with the highest information tales proper now, plus unique options, a podcast, movies and extra.
