TechNewsReel
Live

BitBox Patches Critical Firmware Flaws to Prevent Code Execution and Fund Locking

The 'Dixence update' fixes severe vulnerabilities in Multi edition devices and silent payment systems.

TechNewsReel Newsroom · August 18, 2026

BitBox has released a critical security update to address two severe vulnerabilities that could have compromised user funds and device integrity. Firmware version 9.26.5, dubbed the "Dixence update," was deployed after internal audits identified flaws capable of allowing arbitrary code execution and the locking of assets.

The update specifically targets a memory corruption issue affecting BitBox Multi edition devices. This flaw could allow arbitrary code execution, potentially leading to a loss of funds if a device was connected to a malicious host before a wallet was initially set up. Additionally, BitBox patched a vulnerability in its silent payments implementation. While the company noted that direct theft was not possible through this flaw, an attacker could have locked funds to an unintended address to demand a ransom.

Internal Audits and AI Testing

This security push follows a period of rigorous internal codebase reviews. BitBox indicated that the rise of AI-based code testing has played a role in driving these deeper inspections. The Dixence update follows another recent security milestone, the "Oeschinen update" (v9.26.2), which resolved a bootloader issue. That previous flaw could have allowed attackers to trick users into installing malicious firmware via phishing attacks. BitBox clarified that the BitBox02 Nova model was not affected by that specific bootloader exploit.

Implications for Self-Custody

Hardware wallets are widely regarded as the gold standard for cryptocurrency self-custody, designed specifically to isolate private keys from internet-connected environments. When vulnerabilities such as arbitrary code execution are discovered, they undermine the fundamental promise of hardware isolation. This incident underscores a growing arms race in the industry, where security researchers and AI-driven auditing tools must constantly evolve to stay ahead of potential attackers targeting the hardware layer.

Current Status and Next Steps

Despite the severity of the patched flaws, the BitBox team stated there are no reports of stolen user funds and no evidence that these specific vulnerabilities were exploited in the wild. The company emphasized that there is no reason for users to panic, provided they update their devices. Users are encouraged to verify their firmware version and ensure they are running v9.26.5 to mitigate these risks. The industry will continue to watch how AI-driven auditing changes the frequency and nature of hardware wallet patches.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.