Written by Ezra Reguerrastaff writerReviewed by Yohan Yunstaff editor
Written by Ezra Reguerrastaff writer
Reviewed by Yohan Yunstaff editor
BitBox patches ‘severe’ wallet flaws that could put funds at risk
Latest NewsPublishedAug 18, 2026
BitBox recommended all users update to firmware version 9.26.5 and stated it had received no reports of exploitation or fund losses.

Hardware wallet maker BitBox has released a firmware update that fixes two vulnerabilities it described as “severe” that could have enabled the installation of malicious firmware or put user funds at risk.
In a security disclosure on Monday, BitBox stated one involved memory corruption affecting Multi editions of BitBox02 and BitBox02 Nova that had not been configured with a wallet. A malicious host could exploit it to execute arbitrary code and potentially install malicious firmware, which could lead to lost funds.
The second affected BitBox’s Silent Payments implementation and could have allowed a malicious host to lock Bitcoin to an unintended address. Direct theft was not possible, but an attacker could potentially demand a ransom to cooperate in recovering the coins, as reported by BitBox. The company stated it had received no reports of either vulnerability being exploited or causing users to lose funds.
The disclosure comes at a sensitive moment for self-custody, after a Coldcard firmware flaw was linked to more than $112 million in Bitcoin thefts, underscoring how weaknesses in devices designed to protect private keys can become points of failure.
Cointelegraph reached out to BitBox for more information but did not receive a response before publication.
BitBox patch follows Coldcard thefts, wallet data leaks
The BitBox security update follows a wave of hardware-wallet incidents involving devices and the services surrounding them.
The most damaging was the Coldcard flaw, which traced to a March 2021 firmware change that went undetected for more than five years. The vulnerability affected wallet-seed randomness, allowing attackers to brute-force impacted wallet seeds and derive their private keys without physical access.
Galaxy Research stated Friday that Coldcard-related losses had exceeded $112 million, with about 1,778.6 BTC swept from more than 8,600 addresses.
Related: Coldcard exploit pushes July losses to $247M as second-worst month of 2026
More recently, separate data breaches involving Trezor and SafePal exposed customer and order information belonging to more than 53,000 customers. Trezor attributed the exposure of 13,689 customers’ data to shipping provider ShipMonk, while SafePal stated an authorization flaw in an order-tracking plug-in exposed details belonging to 39,798 customers.
Neither incident compromised devices, private keys or recovery phrases, but both companies warned that the information could enable targeted phishing and impersonation attacks.
Magazine: Do the Coldcard attacks mean all hardware wallets are now insecure?


Subscribe to daily byte-sized crypto news from Cointelegraph
Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
- Bitcoin Wallet
- Wallet
- Security
- Cybersecurity
- Bitcoin
More on the subject
Strategy raises $334M through stock sales but buys no Bitcoin
20 hours ago
Yohan Yun
BTC price loses 200-week trend line as 2022 repeats: Five things to know in Bitcoin this week
21 hours ago
William Suberg
Bitcoin to $1M by 2030 is ‘mathematically impossible’ says Markus Thielen
Aug 15, 2026
Ciaran Lyons
Strategy raises $334M through stock sales but buys no Bitcoin
20 hours ago
Yohan Yun
BTC price loses 200-week trend line as 2022 repeats: Five things to know in Bitcoin this week
21 hours ago
William Suberg
Bitcoin to $1M by 2030 is ‘mathematically impossible’ says Markus Thielen
Aug 15, 2026
Ciaran Lyons