Security Alert: BitBox Uncovers 'Severe' Bitcoin Wallet Vulnerability

Bitcoin wallet manufacturer BitBox has resolved severe firmware vulnerabilities, assuring users no funds were stolen but urging careful updates. This stands in contrast to the Coldcard incident, where a firmware bug led to significant fund losses due to weak seed generation.
David Isong
David IsongCrypto1 hour ago3 minute read
Security Alert: BitBox Uncovers 'Severe' Bitcoin Wallet Vulnerability

Bitcoin hardware wallet manufacturer BitBox has announced that it successfully addressed "severe vulnerabilities" within its hardware wallet's firmware, reassuring its user base that no funds were reported stolen. Despite the positive outcome, the company strongly advised users to proceed with caution when upgrading their devices.

In a blog post published on Tuesday, the Swiss company detailed that one of the critical vulnerabilities had the potential to allow an attacker to trick users into installing malicious firmware, which could subsequently lead to the theft of funds. BitBox emphasized that users should update their firmware exclusively through the official BitBoxApp, ideally by utilizing the in-app update prompt rather than manually searching for the update.

BitBox confirmed the release of the "Dixence security update" following internal audits that led to the discovery and rectification of multiple security issues. The company stated, "There are no reports of stolen user funds and there is no reason for users to panic." They further recommended that "all users to update their BitBox devices to the latest firmware version, which fixes all security issues described in this article."

Another significant vulnerability uncovered was linked to memory corruption. BitBox explained that this particular flaw affected the Multi edition of the BitBox, potentially enabling arbitrary code execution and the subsequent installation of malicious firmware, leading to a possible loss of funds. Crucially, the Bitcoin-only edition of the BitBox was not impacted by this vulnerability, as its firmware does not contain the affected code.

This announcement comes as Bitcoiners are still recovering from a different incident involving the popular Coldcard product, manufactured by Canadian company Coinkite. Users of Coldcard experienced fund drains due to a firmware bug that resulted in weak seed generation (Pseudorandom Number Generator - RNG). Unlike the Coldcard incident, BitBox users are not required to migrate their funds; they only need to update their device firmware.

The Coldcard hack has led to a confirmed $115 million in stolen bitcoin, according to recent figures from Galaxy Research, although the actual amount could be higher. Coinkite initially issued a warning on July 31, explaining that a firmware bug in Coldcard Mk3 devices, specifically versions starting from 4.0.1 in March 2021, caused seed generation to revert to a weak software Pseudorandom Number Generator instead of the more secure hardware true random number generator. This flaw allowed attackers to potentially guess investor seedphrases. The number of affected users and stolen funds has steadily increased as criminals targeted more recent devices, prompting Coinkite and others in the Bitcoin community to urge Coldcard users to immediately move their funds.

Loading...