{
  "id": 1672100,
  "title": "BitBox patches ‘severe’ wallet flaws that could put funds at risk",
  "url": "https://urgent.news/2026/08/18/bitbox-patches-severe-wallet-flaws-that-could-put-funds-at-risk",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-08-18T08:07:04.000Z",
  "source": {
    "name": "Cointelegraph",
    "slug": "cointelegraph",
    "url": "https://cointelegraph.com/news/bitbox-patches-severe-wallet-firmware-flaws"
  },
  "original_language": "en",
  "account": "BitBox has issued a firmware update to address two \"severe\" vulnerabilities that could potentially compromise user funds. The company recommended that all users update to firmware version 9.26.5, stating it had not received any reports of exploitation or fund losses. The first vulnerability involves memory corruption in Multi editions of BitBox02 and BitBox02 Nova when not configured with a wallet, which could allow a malicious host to execute arbitrary code and potentially install malicious firmware, leading to lost funds. The second issue affects BitBox's Silent Payments feature, potentially enabling a malicious host to lock Bitcoin to an unintended address. While direct theft was not possible, an attacker could demand a ransom to assist with recovering the coins. The disclosure comes at a sensitive time for self-custody, following a Coldcard firmware flaw linked to over $112 million in Bitcoin thefts. The recent hardware-wallet incidents have raised concerns about the security of devices designed to protect private keys, as seen in the Coldcard flaw that went undetected for over five years, impacting wallet-seed randomness and allowing attackers to brute-force wallet seeds and derive private keys without physical access.",
  "summary": "BitBox recommended all users update to firmware version 9.26.5 and said it had received no reports of exploitation or fund losses.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}