{Hardware} pockets maker BitBox has launched a firmware replace that fixes two vulnerabilities it described as “extreme” that might have enabled the set up of malicious firmware or put person funds in danger.
In a safety disclosure on Monday, BitBox stated one concerned reminiscence corruption affecting Multi editions of BitBox02 and BitBox02 Nova that had not been configured with a pockets. A malicious host may exploit it to execute arbitrary code and probably set up malicious firmware, which may result in misplaced funds.
The second affected BitBox’s Silent Funds implementation and will have allowed a malicious host to lock Bitcoin to an unintended deal with. Direct theft was not potential, however an attacker may probably demand a ransom to cooperate in recovering the cash, in keeping with BitBox. The corporate stated it had obtained no experiences of both vulnerability being exploited or inflicting customers to lose funds.
The disclosure comes at a delicate second for self-custody, after a Coldcard firmware flaw was linked to greater than $112 million in Bitcoin thefts, underscoring how weaknesses in gadgets designed to guard non-public keys can grow to be factors of failure.
Cointelegraph reached out to BitBox for extra data however didn’t obtain a response earlier than publication.
BitBox patch follows Coldcard thefts, pockets information leaks
The BitBox safety replace follows a wave of hardware-wallet incidents involving gadgets and the companies surrounding them.
Probably the most damaging was the Coldcard flaw, which traced to a March 2021 firmware change that went undetected for greater than 5 years. The vulnerability affected wallet-seed randomness, permitting attackers to brute-force impacted pockets seeds and derive their non-public keys with out bodily entry.
Galaxy Analysis stated Friday that Coldcard-related losses had exceeded $112 million, with about 1,778.6 BTC swept from greater than 8,600 addresses.
Associated: Coldcard exploit pushes July losses to $247M as second-worst month of 2026
Extra not too long ago, separate information breaches involving Trezor and SafePal uncovered buyer and order data belonging to greater than 53,000 prospects. Trezor attributed the publicity of 13,689 prospects’ information to transport supplier ShipMonk, whereas SafePal stated an authorization flaw in an order-tracking plug-in uncovered particulars belonging to 39,798 prospects.
Neither incident compromised gadgets, non-public keys or restoration phrases, however each firms warned that the knowledge may allow focused phishing and impersonation assaults.
Journal: Do the Coldcard assaults imply all {hardware} wallets are actually insecure?
