BitBox bulletins indicate that the company has issued solidware updates to repair two high-risk loopholes affecting BitBox02 and BitBox02 Nova. One might allow the attackers to install malicious solids under certain conditions, and the other related to the achievement of Silent Payments, which could result in bitcoin being locked into an unexpected address. The company stated that it had not found any loopholes to be exploited and had not received a report of financial losses to its users.
Risk of malicious solidware for uninitialized equipment
The first gap relates to memory damage and affects the initialized configuration versions of BitBox02 and BitBox02 Nova Multi. BitBox states that if the affected equipment were connected to the malicious mainframe, the assailant could have performed any code before the wallet was set.
Once used successfully, the attackers could theoretically install malicious solids and threaten the security of funds within the equipment during subsequent use. BitBox classified this as a high risk because it could weaken the hardware wallet to protect against unauthorized software.
Silent Payments achieves an address lockup risk
The second high-risk loophole appears in the Silent Payments function. This feature was intended to enhance the collection privacy of bitcoin and allow users to receive transfers without new addresses being disclosed.
BitBox states that the malicious mainframe may have used this deficiency to lock Bitcoin to the wrong address. The company indicated that this loophole, by itself, could not directly steal funds, but might prevent the user from recovering the relevant bitcoin on its own, and the attackers might even use it to demand a ransom.
- Affected products: BitBox02, BitBox02 Nova
- Main risk: malicious solid installation, bitcoin locked
- Corporate statement: No evidence of utilization, no financial loss report received
The security of the hardware wallet continues to be of concern.
Prior to the release of the update, there had been a series of security incidents in the hardware wallet industry. In January and July of this year, BitBox also repaired other loopholes through solider updates, including cross-border writing problems due to the lack of proof of length of USB requests.
Other producers in the industry have also faced security scrutiny in the recent past. The previously disclosed Coldcard solidware defect was associated with a theft of more than $112 million bitcoin by researchers. The problem stems from a lack of randomity in the generation of wallet seeds, and the aggressor can violently push the private key without having to contact the equipment.
In addition to the equipment itself, the risk of fishing is increased by the disclosure of customer data. Térezor and SafePal have recently disclosed successive exposures to orders or customer information, and the companies concerned alert the users to the resumption of fishing attacks disguised as official notices.
Additional information:BitBox mentioned this time that the first loophole was limited to the Multi version of the device that had not yet been initialized and that the wallets that had been set up were not within this exposure.
