BitBox has released a firmware update to fix two severe vulnerabilities that could have exposed hardware wallet users to malicious firmware or caused Bitcoin to be locked to an unintended address. The first vulnerability involved memory corruption affecting unconfigured Multi editions of the BitBox02 and BitBox02 Nova, while a second flaw affected the wallet maker’s Silent Payments implementation.
According to BitBox, a malicious host connected to an affected wallet could exploit memory corruption to execute arbitrary code before the device had been configured with a wallet. Successful exploitation could potentially allow the host to install malicious firmware, creating a route through which funds could later be compromised.
The company said it had found no evidence that either vulnerability had been exploited and had received no reports of users losing funds because of the flaws.
Vulnerability details
The exposure was limited to Multi editions of the BitBox02 and BitBox02 Nova that had not yet been set up. BitBox classified the vulnerability as severe because arbitrary code execution could undermine protections designed to prevent unauthorised software from running on the hardware wallet.
The second vulnerability affected Silent Payments, a Bitcoin privacy feature that allows users to receive payments without publishing a new address for each transaction. A malicious host could exploit the implementation to cause Bitcoin to be locked to an unintended address.
Recent security issues
Similar hardware and firmware weaknesses have surfaced at other wallet makers in recent months. In June, a flaw was discovered in the TROPIC01 Secure Element used by Trezor Safe 7 devices. Another hardware attack disclosed in July allowed researchers to reset the password on a Tangem wallet card using a targeted laser pulse against its secure element.
BitBox’s update follows the disclosure of a separate Coldcard firmware flaw linked to more than $112 million in stolen Bitcoin after the vulnerability remained undetected for more than five years.
