
On August 17, hardware wallet manufacturer BitBox released the Dixence update, addressing two major vulnerabilities in its firmware. The issues were discovered during internal audits using AI models.
We just released the Dixence security update.
During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware.
We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings.…
— BitBox (@BitBoxSwiss) August 17, 2026
The company reported no exploitation of the vulnerabilities or theft of funds. Users’ seed phrases were also unaffected.
What Was Found in the Firmware
The first issue involved the BitBox02 bootloader, a component responsible for firmware installation. Although the error was fixed in the July version 9.26.2, developers later determined that a potential attack could have been more dangerous than initially thought.
To exploit it, an attacker would first need to conduct a successful phishing attack, convincing a user to install a fake version of BitBoxApp along with malicious firmware, and then unlock the device. This would allow the attacker to install altered software on the genuine BitBox02 and potentially steal funds.
The new BitBox02 Nova model is not susceptible to this attack due to a different bootloader version.
The second major vulnerability was related to memory corruption in the Multi version. It occurred on a device where a wallet was not yet set up when connected to a malicious computer. The flaw allowed arbitrary code execution and potentially installing altered firmware. It was fixed in Dixence 9.26.5.
During the same checks, engineers found another issue in the Silent Payments function. While it did not allow direct coin theft, an attacker could lock them at an incorrect address and then demand a ransom for restoring access. This issue was also resolved in version 9.26.5.
BitBox developers noted that they conducted an in-depth review of the entire codebase in recent weeks. The company also received a record number of reports from external auditors, most of whom used modern AI models to find errors. These external checks have not yet identified any critical or serious vulnerabilities.
Who Needs to Update
Version 9.26.5 addresses all three issues described by BitBox. The company recommends all users install it. Older versions are affected in different scenarios:
- BitBox02 with firmware prior to 9.26.1 — when installing malicious applications and firmware;
- BitBox02 and BitBox02 Nova Multi prior to 9.26.4 — if the wallet is not yet set up and the device is connected to a malicious computer;
- BitBox02 and BitBox02 Nova with versions from 9.21.0 to 9.26.4 — when using Silent Payments with a malicious device.
Developers recommended installing the update through the already installed BitBoxApp or the official website. The company also warned of potential phishing campaigns following the publication of vulnerability information and reminded users not to enter recovery words outside the wallet itself.
Context
Interest in such audits has grown following the hack of Coldcard hardware wallets. In July, hackers began exploiting a flaw in seed phrase generation that had been in the firmware for several years.
By mid-August, Galaxy Research confirmed the theft of at least 1778.84 BTC worth $112.7 million. Including unconfirmed incidents, the damage was estimated at around $153 million.
Following the incident, Dragonfly Managing Partner Haseeb Qureshi stated that an AI audit costing about $2 could have detected the Coldcard issue. In one experiment, the GLM 5.2 model found the flaw in about 20 minutes without internet access.
At the time, Kraken pointed out another aspect of the problem: the mere presence of an audit does not guarantee security. The exchange’s Chief Security Officer Nick Percoco noted that it is necessary to check not just individual device components but the entire path from randomness source to the firmware that actually creates the seed phrase.
Meanwhile, the Bitcoin Red Team launched a mass AI scan of Bitcoin projects. The team reviewed hundreds of repositories and reported thousands of potential issues.
According to participants, artificial intelligence significantly accelerated the search for vulnerabilities, but manual result verification and forwarding confirmed reports to developers became a new bottleneck.
Amid these events, wallet manufacturers faced other threats. On August 13, Trezor reported a data leak affecting nearly 14,000 customers through a logistics partner, and on August 16, SafePal disclosed the theft of information from approximately 39,800 users.
In the latter case, delivery addresses, phone numbers, and emails were exposed, which could be used for phishing and targeted attacks.
In August, the Netherlands’ National Cyber Security Centre recorded a new vector of online attacks on Mac devices through a vulnerability in Screen Sharing. Attackers gained full control over the computer, stole data, and installed a Monero miner.
