Morning Edition · Thursday, August 20, 2026Published at 1:47 AM EDT · New York
One flaw let a malicious computer run arbitrary code on an unconfigured device, weeks after a five-year-old flaw that weakened random number generation in Coldcard firmware was used to drain about 1,816 bitcoin.

The Swiss hardware wallet maker BitBox told users it fixed two severe firmware vulnerabilities in its August update, released as firmware version 9.26.5. The first is a memory-corruption defect affecting Multi editions of the BitBox02 and BitBox02 Nova up to version 9.26.4. It applies when a device has not yet been set up with a wallet and is connected to a malicious host computer, and it could allow that host to execute arbitrary code and install malicious firmware. The second affects the company's Silent Payments implementation and could lock bitcoin to an unintended address. BitBox said direct theft was not possible in that case, but an attacker could demand payment to help recover the coins. The company said it found no evidence of exploitation and no user funds lost, and that internal auditing assisted by artificial intelligence surfaced the flaws.
The context matters. Attackers began draining Coldcard-generated wallets on July 30 by exploiting a firmware bug from March 2021 that produced seeds with far weaker randomness than intended, cutting effective key strength to as little as 40 bits. TRM Labs, a blockchain analytics firm, put the total at roughly 1,816 bitcoin, about $116 million, from more than 5,200 addresses. Rekt, a site that tracks crypto security incidents, has since catalogued both devices in its incident archive.
Separately, Blockstream published benchmarks showing hash-based post-quantum signature schemes already run on current hardware wallets including Jade, Trezor, Ledger and the BitBox02. That is the same constrained firmware layer that just produced two severe bugs, which sets the practical standard that any migration to post-quantum signatures would have to meet.
BitBox gains reputational advantage from disclosing before losses occurred, custodians and exchange-traded products gain from doubt about self-custody firmware, and vendors marketing artificial-intelligence-assisted review gain a proof point.
Part of a tracked trend
Hardware-Wallet Trust Erodes
Recurring firmware and entropy defects in self-custody hardware, now surfaced faster by AI-assisted code analysis, will keep pushing risk-averse holders toward custodial and ETF products rather than personal key management.
Start a discussion in Townsquare.
More from this edition
The patch and both flaws are corroborated by multiple outlets, but "no funds lost" rests on BitBox's own assessment, and the Coldcard loss total is reported between $116 million by TRM Labs and roughly $130 million elsewhere, depending on address attribution and the bitcoin price used.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Self-custody hardware is being re-priced as a software risk rather than a physical one. The failure path in both incidents runs through firmware written years before the loss, which means the exposure falls on long-term holders who set up devices once and never updated them. Custodians, exchange-traded products and multi-vendor setups gain by comparison, because they spread the implementation risk across more than one codebase. The open question is whether AI-assisted review clears the backlog of latent firmware defects faster than attackers find them, and the next few disclosure cycles will show which side is moving faster.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Bitcoin Magazine · Blockstream Blog · Rekt News
Comments
0No comments yet.