
Hardware wallet maker BitBox patches memory corruption and Silent Payments flaws following recent high-profile crypto security incidents.
AI-generated summary
BitBox released a firmware update fixing two severe vulnerabilities related to memory corruption and Silent Payments implementation.
Hardware wallet maker BitBox has released a firmware update that fixes two vulnerabilities it described as “severe” that could have enabled the installation of malicious firmware or put user funds at risk.
In a security disclosure on Monday, BitBox said one involved memory corruption affecting Multi editions of BitBox02 and BitBox02 Nova that had not been configured with a wallet. A malicious host could exploit it to execute arbitrary code and potentially install malicious firmware, which could lead to lost funds.
The second affected BitBox’s Silent Payments implementation and could have allowed a malicious host to lock Bitcoin to an unintended address. Direct theft was not possible, but an attacker could potentially demand a ransom to cooperate in recovering the coins, according to BitBox. The company said it had received no reports of either vulnerability being exploited or causing users to lose funds.
The disclosure comes at a sensitive moment for self-custody, after a Coldcard firmware flaw was linked to more than $112 million in Bitcoin thefts, underscoring how weaknesses in devices designed to protect private keys can become points of failure.
Cointelegraph reached out to BitBox for more information but did not receive a response before publication.
The BitBox security update follows a wave of hardware-wallet incidents involving devices and the services surrounding them.
The most damaging was the Coldcard flaw, which traced to a March 2021 firmware change that went undetected for more than five years. The vulnerability affected wallet-seed randomness, allowing attackers to brute-force impacted wallet seeds and derive their private keys without physical access.
Galaxy Research said Friday that Coldcard-related losses had exceeded $112 million, with about 1,778.6 BTC swept from more than 8,600 addresses.
More recently, separate data breaches involving Trezor and SafePal exposed customer and order information belonging to more than 53,000 customers. Trezor attributed the exposure of 13,689 customers’ data to shipping provider ShipMonk, while SafePal said an authorization flaw in an order-tracking plug-in exposed details belonging to 39,798 customers.
Neither incident compromised devices, private keys or recovery phrases, but both companies warned that the information could enable targeted phishing and impersonation attacks.

MANTRA Chain halted its mainnet on Aug. 21 after an attacker exploited an upstream dependency. Transactions, staking, and transfers are currently suspended while the team tests a security patch on the DuKong testnet before a coordinated restart.

Solana has successfully reduced its slot time to 350 milliseconds, down from 400ms, as part of a multi-stage plan to improve network latency. The update, approved via SIMD-0525, aims for further reductions toward a 200ms target.

Ethereum's better.codes contest tracks a 52.14-bit cryptographic proof gap for the koalaIRS12 parameter profile, measuring distance between certified safety and unsafe bounds via soundness and attack tracks.

Coldcard maker Coinkite released a security overhaul for Bitcoin hardware wallets following a firmware flaw that led to over $130 million in stolen Bitcoin.

Solana has upgraded its network for the first time since genesis, reducing base slot timing from 400ms to 350ms to speed up transaction confirmations. The change is part of a phased plan to reach 200ms, aiming to improve latency and censorship resistance.

A Bitcoin address tied to Maya Protocol's Aug. 18 exploit still held ~20.8 BTC worth $1.59M on Aug. 21, as technical analyses reveal broader pool damage exceeding initial estimates and recovery plans remain undefined.