BitBox issues a security update this week called Dixence. The company disclosed that its engineering team had identified two serious gaps in the BitBox02 solids in its internal audit, as well as a problem related to the start-up of the loading process, and that the repairs were on line with v9.26.5.
This disclosure did not show that loopholes had been used in practice. BitBox states that no user funds have been stolen and there is no indication that the wallets are at risk. However, the old version of the solidware equipment, which had not been upgraded, remained exposed.
Commencement of loading procedures to extend characterization
The first problem arises at the bottom of the bootloader, which is the process of determining which solids are acceptable to the equipment. BitBox states that most of the risks have been blocked with the restorations introduced in July with Oeschinen version v9.26.2, but the company now considers that the initial problem was more serious than earlier disclosures.
According to the company, if the attacker induces the user to install a forged BitBoxApp by fishing, and then the user unlocks a altered device, it is possible that the malicious solids will be included in the original BitBox02 and the encrypted assets in the device will be removed.
BitBox also stated that the newer BitBox02 Nova was not affected by this problem because of the different versions of bootloader.
Multi version affected before initialization
The second serious loophole appears in the BitBox02 Multi version and only until the device has not been initialized. The company claims that this RAM breach may result in arbitrary code enforcement and further loading of malicious solids in the case of a controlled computer.
BitBox indicates that the Bitcoin-only version does not contain the affected code and is therefore not in the loophole.
v9.26.5 Three issues repaired
The third problem is relatively low risk and involves the wallet function. According to the company, the issue cannot be directly stolen, but it may lock funds to the wrong address, with a similar effect of extortion.
- v9.26.2 Most bootloader risks repaired
- v9.26.5 Three disclosed issues repaired
- Unupdated old solid remains exposed
BitBox also indicated that the internal audit used front-line AI model-aided analysis and that the company provided a separate presentation on the use of AI audit solids. There have been recent security incidents in the hardware wallet industry and market concerns about equipment security are rising. Earlier, about 1,596 BTCs had been stolen as a result of the Coldcard solidware leak; the recent leak of SafePal also raised concerns about the exposure of hardware wallet holders.
