Overview
- BitBox issued firmware version 9.26.5 to patch two severe vulnerabilities and told users to download the official BitBoxApp and apply the firmware update to affected BitBox02 and BitBox02 Nova devices.
- One flaw was a memory-corruption bug in unconfigured Multi editions that a malicious host could exploit to run arbitrary code before a wallet was set up and potentially install malicious firmware.
- The second flaw was in the Silent Payments implementation where a malicious host could cause funds to be directed to an unintended address, leaving coins inaccessible and enabling a ransom scenario without permitting direct theft.
- BitBox says it has found no evidence either vulnerability was exploited and it has received no reports of user funds lost; the company previously fixed a separate bootloader issue in firmware 9.26.2.
- The fixes arrive during heightened scrutiny of hardware-wallet software after other 2026 incidents that showed weak seed randomness or firmware bugs can cause large losses, so users should update now and follow best practices for seed security and fund migration if a seed was ever suspected to be weak.