Skip to content
Back to Guavy Wire
Crypto

BitBox Wallet Flaw Exposes Weakness Beyond Private Key Isolation

Share

The security of hardware wallets has been called into question after Web3 security firm CertiK discovered a severe out-of-bounds (OOB) write vulnerability in the BitBox02 wallet.

The flaw, which was patched in July's Oeschinen security update, allowed an attacker to hijack control of the device by sending an oversized command over USB.

CertiK researcher Guanxing Wen identified the issue, which sat not in the storage of private keys but in how the device communicated with a computer. The wallet's software blindly accepted instructions about data without checking if it would fit into its temporary memory space.

This is not an isolated incident, as Ledger patched a similar flaw earlier this year after CertiK uncovered that host-provided reset handlers were not properly validated during firmware updates.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc