BitBox Releases Dixence Update to Fix Critical Vulnerabilities in Hardware Wallet
BitBox, the Zurich-based Swiss company behind the BitBox02 hardware wallet, has published this week the Dixence security update after its engineers discovered two critical vulnerabilities in the device's firmware. The update is available on the official blog.bitbox.swiss.
Quick Response
BitBox has identified and fixed three vulnerabilities in its BitBox02 hardware wallet:
- A flaw in the bootloader that could allow the installation of malicious firmware
- A memory corruption bug in the Multi version of the wallet
- An issue in the silent payment feature that could lock funds
No user has suffered financial losses, and the Dixence v9.26.5 update resolves all issues.
The company revealed the issues independently, with no evidence they were actually exploited. However, the news comes at a delicate time for the sector, following the recent Coldcard attack that caused the theft of over 1,596 BTC worth $130 million, the largest hardware wallet hack of 2026.
The Bootloader Vulnerability and the Phishing Risk
The first problem identified by BitBox concerns the bootloader, the component that determines which firmware a device accepts. A partial solution was implemented in the Oeschinen (v9.26.2) update of July, but the company has now revealed that the original vulnerability was more severe than initially thought.
An attacker could have conducted a phishing campaign, tricking users into installing a fake version of BitBoxApp and unlocking the device. This would have allowed loading malicious firmware onto an authentic BitBox02 and stealing the funds. The latest version of the device, BitBox02 Nova, was not exposed to this risk thanks to a different version of the bootloader.
The Memory Corruption Bug and Arbitrary Code Execution
The second critical vulnerability is a memory corruption bug present in the Multi version of BitBox before the wallet's initial setup. In combination with a hostile computer, this defect could have allowed arbitrary code execution and, consequently, the installation of malicious firmware. The Bitcoin-only version of the wallet was not affected by this issue.
The Silent Payment Issue and the Risk of Fund Locking
A third, less severe but still significant problem concerned the wallet's silent payment feature. Although it could not directly steal funds, it could have locked cryptocurrencies to a wrong address in a ransomware-type attack. All three issues have been resolved in the Dixence v9.26.5 update.
The Use of Advanced AI Models for Security Audits
BitBox used cutting-edge AI models during the internal review, as part of a broader strategy described in a separate post on its blog. The company emphasizes the importance of keeping security device firmware up to date, especially in an era where cyber threats are becoming increasingly sophisticated.
The Security Context of Hardware Wallets in 2026
This episode represents another warning that even hardware wallets, traditionally considered the safest choice for security-conscious crypto users, are not invulnerable. The Coldcard attack demonstrated how a five-year-old firmware bug could be exploited to steal cryptocurrencies, while the recent SafePal data breach has shed light on physical attacks against hardware wallet users, known as "wrench attacks".
BitBox's Response and Recommendations for Users
BitBox has stated that there are no reports of user funds stolen and that there is no reason to panic. The company simply advises installing the Dixence v9.26.5 update available at the official link. Until users apply the new firmware, devices will remain exposed to the fixed vulnerabilities.
At this point, it is crucial that all BitBox02 owners immediately verify the installed firmware version and proceed with the update. The procedure is simple and can be performed via the official BitBoxApp application. BitBox has also provided detailed instructions on its blog to ensure the update is performed correctly and safely.
The Impact on the Crypto Ecosystem and Lessons Learned
The BitBox Dixence update comes at a time when the cryptocurrency ecosystem is facing unprecedented security challenges. The Coldcard episode demonstrated that even years-old vulnerabilities can be exploited with devastating consequences, while the SafePal data breach highlighted how user personal information can become an attack vector.
These events underscore the importance of layered security. While hardware wallets remain one of the safest tools for cryptocurrency custody, they cannot be considered invulnerable. Users must adopt a proactive approach, combining high-quality hardware with good security practices such as using offline seed phrases and verifying transactions on multiple devices.
The Evolution of Threats and the Need for a Coordinated Response
As the cryptocurrency industry continues to evolve, so will the threats to hardware wallet security. Companies like BitBox are already using advanced technologies such as artificial intelligence to improve their audit and development processes.
In the future, we can expect to see further innovations in this field, such as the adoption of private blockchains for device security verification or the use of advanced biometrics for user authentication. However, regardless of technological advances, user education will remain a critical factor in ensuring cryptocurrency security.
A Call to Action for the Crypto Community
The BitBox Dixence update represents a call to action for the entire crypto community. Users, both individual and institutional, must take the security of their digital assets seriously and adopt proactive measures to protect them. Hardware wallet development companies must continue to invest in research and development to improve the security of their products.
Finally, the crypto community as a whole should work to create a safer and more resilient ecosystem, sharing threat information and collaborating to develop innovative solutions. Only through a coordinated and proactive approach can we ensure that cryptocurrencies remain a safe and reliable means of storing value.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product under Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decisions.