XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

BitBox Addresses Critical Firmware Vulnerabilities Amid Growing Hardware Wallet Security Concerns

Hardware wallet manufacturer BitBox released a firmware patch addressing two severe security flaws, as the crypto industry grapples with a wave of hardware wallet incidents including a major Coldcard exploit that resulted in over $112 million in losses.

JM
by Jacob Marquez · Markets Desk
Published August 18, 2026 · 2 min read

BitBox Releases Urgent Firmware Fix

BitBox, a hardware wallet manufacturer, rolled out firmware version 9.26.5 to address two vulnerabilities the company classified as severe. The first flaw involved memory corruption in BitBox02 and BitBox02 Nova devices that had yet to be configured as wallets. A malicious host could potentially exploit this vulnerability to execute arbitrary code and subsequently install unauthorized firmware—a pathway to compromised user funds. The second vulnerability affected BitBox’s Silent Payments implementation for Bitcoin, where a malicious actor could lock funds to an incorrect address. While direct theft was not possible, attackers could theoretically exploit this to hold coins ransom pending recovery assistance.

BitBox emphasized that neither vulnerability had been actively exploited or resulted in user losses to date. The company urged all users to update immediately to the patched firmware version.

Hardening Against a Widening Threat Landscape

The BitBox disclosure arrives during a particularly fraught period for hardware wallet security. Most prominently, a critical Coldcard firmware flaw recently became linked to losses exceeding $112 million. According to Galaxy Research, the vulnerability stemmed from a firmware modification made in March 2021 that went undetected for over five years. The flaw compromised wallet-seed randomness, enabling attackers to brute-force and derive private keys from affected wallets remotely—without requiring physical device access. Galaxy Research documented approximately 1,778.6 BTC extracted from more than 8,600 addresses as a result.

Beyond the Coldcard incident, the hardware wallet ecosystem has faced additional pressure from data compromise events. Trezor and SafePal both disclosed breaches exposing customer and order information belonging to over 53,000 users combined. Trezor attributed 13,689 customers’ data exposure to a vulnerability at third-party shipping provider ShipMonk, while SafePal identified an authorization flaw in an order-tracking integration affecting 39,798 customers. Neither breach directly compromised device firmware, private keys, or recovery phrases, but both firms warned that exposed customer data could facilitate targeted phishing and social engineering attacks.

Implications for Custody and Market Confidence

The cascading incidents underscore a fundamental challenge in self-custody infrastructure: vulnerabilities in devices and services designed to safeguard cryptographic keys represent systemic weak points. While traditional finance has established security standards across custodial systems, decentralized asset custody demands that individuals and manufacturers maintain vigilance without centralized oversight. As hardware wallets remain among the most secure methods for storing cryptocurrency, addressing these flaws swiftly is essential to maintaining user confidence in non-custodial security solutions.

Source: BitBox security disclosure, via Cointelegraph. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.