BitBox Fixes Severe Firmware Flaws Threatening Wallet Funds
BitBox, the hardware-wallet brand of Zurich-based Shift Crypto, builds BitBox02 devices to keep private keys offline and require transaction details to be verified on the device. That design reduces exposure to a compromised computer, but firmware flaws can reopen the attack surface by allowing malicious code or misdirecting payments. The disclosure is significant because self-custody users bear the loss directly if their signing device is compromised.
On Aug. 17, 2026, BitBox released its Dixence update, raising firmware to version 9.26.5. It fixed a memory-corruption flaw affecting uninitialized Multi-edition devices connected to a malicious host, which could permit arbitrary code execution and malicious firmware installation, and a Silent Payments bug that could lock bitcoin to an unintended address. BitBox said the issues emerged from internal audits that included frontier AI models, with no reports of exploitation or stolen funds. Devices running version 9.26.5 or later are not affected, and the company urged all users to upgrade through the official BitBoxApp.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →