Mark RadarMARK RADAR
About
EN
Sign in

BitBox Fixes Severe Firmware Flaws Threatening Wallet Funds

2 reports · First detected 2026-08-18 · Last active 2026-08-19

BitBox, the hardware-wallet brand of Zurich-based Shift Crypto, builds BitBox02 devices to keep private keys offline and require transaction details to be verified on the device. That design reduces exposure to a compromised computer, but firmware flaws can reopen the attack surface by allowing malicious code or misdirecting payments. The disclosure is significant because self-custody users bear the loss directly if their signing device is compromised.

On Aug. 17, 2026, BitBox released its Dixence update, raising firmware to version 9.26.5. It fixed a memory-corruption flaw affecting uninitialized Multi-edition devices connected to a malicious host, which could permit arbitrary code execution and malicious firmware installation, and a Silent Payments bug that could lock bitcoin to an unintended address. BitBox said the issues emerged from internal audits that included frontier AI models, with no reports of exploitation or stolen funds. Devices running version 9.26.5 or later are not affected, and the company urged all users to upgrade through the official BitBoxApp.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)