In brief – BitBox shipped the Dixence update after internal AI audits found two severe vulnerabilities plus a bootloader issue. – Exploiting them required a successful phishing attack plus the user unlocking a tampered device. – BitBox says no user funds were stolen and the…
llet seed was never at risk. BitBox, the Zurich-based maker behind the BitBox02, released the Dixence security update this week after its own engineers uncovered two severe flaws in the cryptocurrency wallet’s firmware
The company disclosed the issues itself, with no evidence they were ever exploited. But the news itself is likely enough to set off the alarms of most Bitcoin holders, given the recent exploit of hardware wallet maker Coldcard that’s resulted in over $130 million in stolen BTC. For BitBox, the first problem lives in the bootloader, the code that decides which firmware a device will accept.
A fix shipped in July’s Oeschinen release (v9.26.2) closed most of it, but BitBox now says the original issue was worse than first reported. An attacker who ran a phishing scam—tricking a user into installing a fake BitBoxApp and unlocking the device—could have loaded malicious firmware onto a genuine BitBox02 and walked off with the coins. The BitBox02 Nova, the newer model, was never exposed because of its bootloader version.