{"slug": "bitbox-patches-two-severe-firmware-flaws-found-in-ai-assisted-audits", "title": "BitBox Patches Two Severe Firmware Flaws Found in AI-Assisted Audits", "summary": "BitBox released firmware 9.26.5 on August 17 to patch a memory-corruption flaw and a silent-payment issue found during internal reviews that included frontier AI models. The company reported no known exploitation or stolen funds, but affected BitBox02 and BitBox02 Nova users need the Dixence update for protection.", "body_md": "# BitBox Patches Two Severe Firmware Flaws Found in AI-Assisted Audits\n\nBitBox released firmware 9.26.5 on August 17 to patch a memory-corruption flaw and a silent-payment issue found during internal reviews that included frontier AI models. The company reported no known exploitation or stolen funds, but affected BitBox02 and BitBox02 Nova users need the Dixence update for protection.\n\nBitBox released its **08.2026 Dixence** update on August 17, shipping firmware 9.26.5 to fix two severe issues found during internal reviews that included frontier AI models. The company reported no known exploitation or stolen funds and said existing wallet seeds are unaffected, while recommending that all users install the update.\n\n### The two Dixence fixes\n\nThe first issue is a memory-corruption flaw affecting the Multi edition of BitBox02 and BitBox02 Nova through firmware 9.26.4 when a device has not yet been set up with a wallet and is connected to a malicious host. BitBox says exploitation could permit arbitrary code execution and potentially malicious firmware installation. The Bitcoin-only edition does not contain the affected code.\n\nThe second issue affects silent payments on BitBox02 and BitBox02 Nova from firmware 9.21.0 through 9.26.4 when a transaction is created with a malicious host. BitBox says an attacker could direct funds to an unintended payment address and then demand cooperation for recovery. The company says the flaw does not enable direct theft and that it has no reports of failed silent payments tied to exploitation.\n\nFirmware 9.26.5 fixes both issues. Because the affected ranges and prerequisites differ, users should rely on the current firmware rather than trying to determine that their normal usage avoided every scenario.\n\n### A previously patched bootloader risk\n\nBitBox also expanded its disclosure of a separate bootloader issue already fixed in July's Oeschinen firmware 9.26.2. The company says a technically capable attacker first needed to phish a user into installing a malicious BitBoxApp and unlocking an authentic BitBox02, after which manipulated firmware could be installed. BitBox02 Nova was not affected by this bootloader path.\n\nThat earlier issue was initially found internally and later reported independently by external researchers. BitBox says it has no evidence it was exploited.\n\n### What AI contributed\n\nBitBox says its engineers used frontier AI models as part of extensive internal review. In a separate August 4 post, the company described AI tools as useful for scanning large codebases, flagging patterns and fuzzing interfaces, while emphasizing that findings still require validation, remediation and deployed updates.\n\nFor users, the action is to update through the official BitBoxApp or bitbox.swiss and never enter recovery words in response to an update prompt. For security teams, the episode illustrates the whole control chain: AI-assisted discovery can accelerate review, but signed delivery, precise affected-version guidance and patch adoption determine whether deployed devices are protected.\n\n## Key Points\n\n- 1Firmware 9.26.5 fixes a Multi-edition memory-corruption flaw and a silent-payment issue, each with distinct affected versions and attack prerequisites.\n- 2BitBox separately clarified a bootloader risk already fixed in firmware 9.26.2; exploiting it required phishing and did not affect BitBox02 Nova.\n- 3BitBox used frontier AI models during internal review, but protection still depends on validated fixes and users installing the official firmware.\n\n## Scoring Rationale\n\nThe release fixes severe flaws in security-critical wallet firmware and offers a concrete case of AI-assisted vulnerability discovery. Its scope is specific to BitBox devices, but the versioning, phishing and patch-adoption lessons generalize to embedded security teams.\n\n## Sources\n\nPrimary source and supporting public references used for this report.\n\nPractice interview problems based on real data\n\n1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.\n\n[Try 250 free problems](/problems)", "url": "https://wpnews.pro/news/bitbox-patches-two-severe-firmware-flaws-found-in-ai-assisted-audits", "canonical_source": "https://letsdatascience.com/news/bitbox-patches-severe-firmware-vulnerabilities-found-with-ai-b3754672", "published_at": "2026-08-18 18:06:42+00:00", "updated_at": "2026-08-18 21:13:18.915312+00:00", "lang": "en", "topics": ["ai-tools", "ai-research", "ai-safety"], "entities": ["BitBox", "BitBox02", "BitBox02 Nova", "Dixence", "Oeschinen"], "alternates": {"html": "https://wpnews.pro/news/bitbox-patches-two-severe-firmware-flaws-found-in-ai-assisted-audits", "markdown": "https://wpnews.pro/news/bitbox-patches-two-severe-firmware-flaws-found-in-ai-assisted-audits.md", "text": "https://wpnews.pro/news/bitbox-patches-two-severe-firmware-flaws-found-in-ai-assisted-audits.txt", "jsonld": "https://wpnews.pro/news/bitbox-patches-two-severe-firmware-flaws-found-in-ai-assisted-audits.jsonld"}}