Key Takeaways

  • BitBox users should update to firmware 9.26.5 to address two serious security vulnerabilities.

  • BitBox says there is no evidence the flaws were exploited or that user funds were stolen.

  • Existing wallet seeds remain safe, but users should stay alert to phishing and never share recovery words.

BitBox Discloses Critical Security Flaws

Hardware wallet maker BitBox has fixed two serious security vulnerabilities that could have put some users’ bitcoin at risk. The company released firmware version 9.26.5 to fix the problems and is urging users to update their devices.

BitBox said there is no evidence that either vulnerability was exploited or that users lost funds because of the flaws. The company also revealed more information about a separate bootloader vulnerability that had already been fixed in an earlier update.

The first vulnerability involved a memory corruption problem in the Multi version of the BitBox02 and BitBox02 Nova. It affected devices that had not yet been set up with a wallet and were connected to a malicious computer.

If an attacker successfully exploited the flaw, they could potentially execute their own code on the wallet. This could allow them to install malicious firmware, seriously weakening the wallet’s security and potentially allowing funds to be stolen later.

The Bitcoin-only version of the BitBox was not affected because it does not contain the vulnerable code. BitBox fixed the problem in firmware version 9.26.5.

The second vulnerability involved BitBox’s Silent Payments feature. Silent Payments allow people to receive bitcoin without publicly sharing a new address for every payment. BitBox found that a malicious host could potentially manipulate a Silent Payment transaction so that bitcoin was sent to an unintended address.

The attacker could not directly take the bitcoin, according to BitBox. However, the coins could become locked in a way that made them difficult for the owner to recover. This could potentially lead to a ransom situation, where the attacker demands payment in exchange for helping recover the coins.

BitBox said the vulnerability affected BitBox02 and BitBox02 Nova devices running firmware versions 9.21.0 through 9.26.4 when they were used to create Silent Payment transactions with a malicious host. The problem has also been fixed in version 9.26.5.

BitBox said it has received no reports of the vulnerability being exploited.

The company also provided new details about a bootloader vulnerability that was already fixed in firmware version 9.26.2. An attacker could potentially use this flaw to trick a BitBox02 user into installing malicious firmware.

However, exploiting the problem would have required a successful phishing attack first. For example, an attacker could have created a fake BitBoxApp and convinced a user to install it.

The user would then have to install the manipulated firmware and unlock the device.
If all those steps were successful, the malicious firmware could potentially steal funds.
BitBox said the BitBox02 Nova was not affected by this older attack because of the specific bootloader versions involved.

BitBox also said that the newly disclosed vulnerabilities did not tamper with seed generation functions, and all device-generated seeds are deemed safe.

“Your existing wallet seed is not affected in any way,” BitBox said. The company also said it has no evidence that the vulnerability was ever exploited.

BitBox emphasized that there is currently no reason for users to panic. “There are no reports of stolen user funds and there is no reason for users to panic,” the company said in its security disclosure.

Still, the company strongly recommends updating all BitBox devices to firmware 9.26.5.
Users should update through the BitBoxApp or the official BitBox website. BitBox warned that security announcements can also be used by scammers to launch phishing attacks.
The company said, “BitBox will never ask for your recovery words.”

Users should therefore never enter their recovery phrase into a website, computer or message. The recovery phrase should remain private and be entered only directly into a hardware wallet when necessary.

This announcement follows the recent COLDCARD wallet incident, in which a flaw in random number generation led to the creation of faulty seed phrases. The bug resulted in thousands of bitcoin being stolen from seed phrases generated on affected devices since 2021.

Shortly after the COLDCARD incident, Rob Hamilton, CEO at AnchorWatch, assembled a group called the “Bitcoin Red Team” to conduct further audits of Bitcoin-related projects using sophisticated AI methods. According to the team, the initiative has since led to the discovery of several critical vulnerabilities in these projects.

It is not yet known whether the BitBox issue was discovered by the Bitcoin Red Team or whether the BitBox team identified the security flaws independently.

100% of the sats go directly to the author

Latest on YouTube


Reply

Avatar

or to participate