BitBox has issued a firmware update for its BitBox02 and BitBox02 Nova hardware wallets after identifying two severe vulnerabilities that could have exposed users to malicious firmware or made Bitcoin inaccessible.

The company said neither issue had been exploited and that it had received no reports of lost funds. One flaw affected unconfigured Multi editions of the devices, while the other involved the Silent Payments privacy feature.

Pre-setup flaw raised risk of malicious firmware

BitBox said the first vulnerability could be triggered by a malicious host connected to an affected wallet before the device had been configured with a wallet. In that scenario, memory corruption could be used to execute arbitrary code on the device.

According to the company, successful exploitation could have opened a path to installing malicious firmware. Because firmware governs core wallet functions such as cryptographic operations, transaction verification and communication with a connected computer, BitBox classified the issue as severe.

The exposure was limited to Multi editions of the BitBox02 and BitBox02 Nova that had not yet been set up. BitBox said the flaw was serious because arbitrary code execution could bypass protections intended to stop unauthorised software from running on the wallet.

Silent Payments bug could make coins unrecoverable

The second severe issue involved Silent Payments, a Bitcoin privacy feature designed to let users receive funds without publishing a fresh address for each transaction. BitBox said a malicious host could exploit the implementation so that Bitcoin would be locked to an unintended address.

The company said the flaw did not enable direct theft. Instead, it could leave a victim unable to recover the affected Bitcoin without outside cooperation, creating a scenario in which an attacker might demand a ransom to help unlock the coins.

Even without transferring control of the funds to the attacker, BitBox said the bug still posed a serious risk because it could make a user’s Bitcoin inaccessible.

BitBox says no exploitation was reported

Both vulnerabilities were addressed in the latest firmware release for BitBox02 and BitBox02 Nova. BitBox said it had received no reports that either the firmware-installation issue or the Silent Payments flaw had been used in attacks.

The company also said no user funds were reported lost. That leaves the update as a precautionary security fix rather than a response to confirmed theft or active exploitation.

Broader focus on wallet firmware security

The update comes amid wider scrutiny of hardware wallet firmware security. The source report noted that the BitBox fixes follow a Coldcard firmware flaw that was linked to more than $112 million in Bitcoin thefts.

For BitBox users, the immediate confirmed next step is the firmware update that closes both issues. The company’s account, based on the information provided, is that the known risk has been mitigated by the new release and that no exploitation has been reported so far.

Source: crypto.news