BitBox Firmware Flaws Exposed After Internal AI Audit
BitBox, the Zurich-based maker of cryptocurrency wallets, has disclosed that its own internal AI audits uncovered two severe vulnerabilities in its firmware. The issues were found in the Multi edition of the BitBox before it was set up with a wallet and could have allowed arbitrary code execution if exploited by an attacker.
The first vulnerability was in the bootloader, which is the code that decides which firmware a device will accept. Although a fix for this issue was shipped in July's Oeschinen release (v9.26.2), BitBox now says that the original problem was worse than initially reported.
An attacker could have loaded malicious firmware onto a genuine BitBox02 by running a phishing scam, tricking a user into installing a fake BitBoxApp and unlocking the device. The second severe bug was also identified in the Multi edition of the BitBox and could have allowed an attacker to execute arbitrary code if paired with a hostile computer.
The issues were discovered during internal reviews that used frontier AI models. All three problems - including a third issue related to the wallet's silent-payment feature - have been fixed in v9.26.5. The company has emphasized that no user funds were stolen and there is no reason for users to panic.