cd /news/ai-tools/bitbox-patches-two-severe-firmware-f… · home topics ai-tools article
[ARTICLE · art-102022] src=letsdatascience.com ↗ pub= topic=ai-tools verified=true sentiment=· neutral

BitBox Patches Two Severe Firmware Flaws Found in AI-Assisted Audits

BitBox released firmware 9.26.5 on August 17 to patch a memory-corruption flaw and a silent-payment issue found during internal reviews that included frontier AI models. The company reported no known exploitation or stolen funds, but affected BitBox02 and BitBox02 Nova users need the Dixence update for protection.

read3 min views1 publishedAug 18, 2026
BitBox Patches Two Severe Firmware Flaws Found in AI-Assisted Audits
Image: Letsdatascience (auto-discovered)

BitBox released firmware 9.26.5 on August 17 to patch a memory-corruption flaw and a silent-payment issue found during internal reviews that included frontier AI models. The company reported no known exploitation or stolen funds, but affected BitBox02 and BitBox02 Nova users need the Dixence update for protection.

BitBox released its 08.2026 Dixence update on August 17, shipping firmware 9.26.5 to fix two severe issues found during internal reviews that included frontier AI models. The company reported no known exploitation or stolen funds and said existing wallet seeds are unaffected, while recommending that all users install the update.

The two Dixence fixes

The first issue is a memory-corruption flaw affecting the Multi edition of BitBox02 and BitBox02 Nova through firmware 9.26.4 when a device has not yet been set up with a wallet and is connected to a malicious host. BitBox says exploitation could permit arbitrary code execution and potentially malicious firmware installation. The Bitcoin-only edition does not contain the affected code.

The second issue affects silent payments on BitBox02 and BitBox02 Nova from firmware 9.21.0 through 9.26.4 when a transaction is created with a malicious host. BitBox says an attacker could direct funds to an unintended payment address and then demand cooperation for recovery. The company says the flaw does not enable direct theft and that it has no reports of failed silent payments tied to exploitation.

Firmware 9.26.5 fixes both issues. Because the affected ranges and prerequisites differ, users should rely on the current firmware rather than trying to determine that their normal usage avoided every scenario.

A previously patched boot risk

BitBox also expanded its disclosure of a separate boot issue already fixed in July's Oeschinen firmware 9.26.2. The company says a technically capable attacker first needed to phish a user into installing a malicious BitBoxApp and unlocking an authentic BitBox02, after which manipulated firmware could be installed. BitBox02 Nova was not affected by this boot path.

That earlier issue was initially found internally and later reported independently by external researchers. BitBox says it has no evidence it was exploited.

What AI contributed

BitBox says its engineers used frontier AI models as part of extensive internal review. In a separate August 4 post, the company described AI tools as useful for scanning large codebases, flagging patterns and fuzzing interfaces, while emphasizing that findings still require validation, remediation and deployed updates.

For users, the action is to update through the official BitBoxApp or bitbox.swiss and never enter recovery words in response to an update prompt. For security teams, the episode illustrates the whole control chain: AI-assisted discovery can accelerate review, but signed delivery, precise affected-version guidance and patch adoption determine whether deployed devices are protected.

Key Points #

  • 1Firmware 9.26.5 fixes a Multi-edition memory-corruption flaw and a silent-payment issue, each with distinct affected versions and attack prerequisites.
  • 2BitBox separately clarified a boot risk already fixed in firmware 9.26.2; exploiting it required phishing and did not affect BitBox02 Nova.
  • 3BitBox used frontier AI models during internal review, but protection still depends on validated fixes and users installing the official firmware.

Scoring Rationale #

The release fixes severe flaws in security-critical wallet firmware and offers a concrete case of AI-assisted vulnerability discovery. Its scope is specific to BitBox devices, but the versioning, phishing and patch-adoption lessons generalize to embedded security teams.

Sources #

Primary source and supporting public references used for this report.

Practice interview problems based on real data

1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.

Try 250 free problems

── more in #ai-tools 4 stories · sorted by recency
── more on @bitbox 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/bitbox-patches-two-s…] indexed:0 read:3min 2026-08-18 ·