This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com
NewsLayer PulseLIVEBTC$64,177+1.09%ETH$1,898+0.05%SOL$76.29+1.23%XRP$0.9971+0.02%DOGE$0.0698-0.29%ADA$0.1741+0.41%Total Cap$2.29T+0.60%Layer Index47 Neutral
External ReportingYayınlandı 5 saat önce

BitBox patches ‘severe’ wallet flaws that could put funds at risk

BitBox recommended all users update to firmware version 9.26.5 and said it had received no reports of exploitation or fund losses.

BitBox patches ‘severe’ wallet flaws that could put funds at risk
Yazan Cointelegraph by Ezra ReguerraPublisher Cointelegraph 2 dk okuma
Image via Cointelegraph
>$112MColdcard theft losses
1,778.6 BTCBitcoin swept from wallets
13,689Trezor customers exposed

Why This Matters

The patched flaws highlight that a compromised host can undermine hardware-wallet security before or during setup, potentially enabling malicious firmware installation or misdirected Bitcoin payments. While no exploitation was reported, the disclosure reinforces heightened operational and supply-chain risk for self-custody users amid recent wallet vulnerabilities and customer-data leaks that can facilitate targeted attacks.

Security Context

Affected ecosystemHardware wallet firmware security
Affected providersBitBox · Coldcard · Trezor · SafePal
MitigationFirmware update released

Market Context

Bitcoin

BTC

$64,177

+1.09% 24h

Layer Index

47

↑ 3 pts in 24h

Hardware wallet maker BitBox has released a firmware update that fixes two vulnerabilities it described as “severe” that could have enabled the installation of malicious firmware or put user funds at risk. 

In a security disclosure on Monday, BitBox said one involved memory corruption affecting Multi editions of BitBox02 and BitBox02 Nova that had not been configured with a wallet. A malicious host could exploit it to execute arbitrary code and potentially install malicious firmware, which could lead to lost funds. 

The second affected BitBox’s Silent Payments implementation and could have allowed a malicious host to lock Bitcoin to an unintended address. Direct theft was not possible, but an attacker could potentially demand a ransom to cooperate in recovering the coins, according to BitBox. The company said it had received no reports of either vulnerability being exploited or causing users to lose funds. 

The disclosure comes at a sensitive moment for self-custody, after a Coldcard firmware flaw was linked to more than $112 million in Bitcoin thefts, underscoring how weaknesses in devices designed to protect private keys can become points of failure.

Cointelegraph reached out to BitBox for more information but did not receive a response before publication. 

BitBox patch follows Coldcard thefts, wallet data leaks

The BitBox security update follows a wave of hardware-wallet incidents involving devices and the services surrounding them. 

The most damaging was the Coldcard flaw, which traced to a March 2021 firmware change that went undetected for more than five years. The vulnerability affected wallet-seed randomness, allowing attackers to brute-force impacted wallet seeds and derive their private keys without physical access. 

Galaxy Research said Friday that Coldcard-related losses had exceeded $112 million, with about 1,778.6 BTC swept from more than 8,600 addresses.

Related: Coldcard exploit pushes July losses to $247M as second-worst month of 2026

More recently, separate data breaches involving Trezor and SafePal exposed customer and order information belonging to more than 53,000 customers. Trezor attributed the exposure of 13,689 customers’ data to shipping provider ShipMonk, while SafePal said an authorization flaw in an order-tracking plug-in exposed details belonging to 39,798 customers.

Neither incident compromised devices, private keys or recovery phrases, but both companies warned that the information could enable targeted phishing and impersonation attacks. 

Magazine: Do the Coldcard attacks mean all hardware wallets are now insecure?

Son Dakika

Hiçbir son dakika haberini kaçırmayın

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by Cointelegraph

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

İlgili Haberler