# BitBox Patches Two Severe Wallet Firmware Bugs Found by Its Own AI-Assisted Audit

One flaw let a malicious computer run arbitrary code on an unconfigured device, weeks after a five-year-old flaw that weakened random number generation in Coldcard firmware was used to drain about 1,816 bitcoin.

- Published: 2026-08-20T05:47:26.932Z
- Canonical: https://polylog.news/crypto/2026-08-20/bitbox-patches-two-severe-wallet-firmware-bugs-found-by-its
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Bitcoin Magazine](https://bitcoinmagazine.com/news/bitbox-warns-users-about-vulnerability), [Blockstream Blog](https://blog.blockstream.com/hardware-wallets-post-quantum-signatures/), [Rekt News](https://www.rekt.news/)

The Swiss hardware wallet maker BitBox [told users it fixed two severe firmware vulnerabilities](https://bitcoinmagazine.com/news/bitbox-warns-users-about-vulnerability) in its August update, released as firmware version 9.26.5. The first is a memory-corruption defect affecting Multi editions of the BitBox02 and BitBox02 Nova up to version 9.26.4. It applies when a device has not yet been set up with a wallet and is connected to a malicious host computer, and it could allow that host to execute arbitrary code and install malicious firmware. The second affects the company's Silent Payments implementation and could lock bitcoin to an unintended address. BitBox said direct theft was not possible in that case, but an attacker could demand payment to help recover the coins. The company said it found no evidence of exploitation and no user funds lost, and that internal auditing assisted by artificial intelligence surfaced the flaws.

The context matters. Attackers began draining Coldcard-generated wallets on July 30 by exploiting a firmware bug from March 2021 that produced seeds with far weaker randomness than intended, cutting effective key strength to as little as 40 bits. TRM Labs, a blockchain analytics firm, [put the total at roughly 1,816 bitcoin, about $116 million, from more than 5,200 addresses](https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack). Rekt, a site that tracks crypto security incidents, has since [catalogued both devices](https://www.rekt.news/) in its incident archive.

Separately, Blockstream published [benchmarks showing hash-based post-quantum signature schemes already run](https://blog.blockstream.com/hardware-wallets-post-quantum-signatures/) on current hardware wallets including Jade, Trezor, Ledger and the BitBox02. That is the same constrained firmware layer that just produced two severe bugs, which sets the practical standard that any migration to post-quantum signatures would have to meet.

## What this means

Self-custody hardware is being re-priced as a software risk rather than a physical one. The failure path in both incidents runs through firmware written years before the loss, which means the exposure falls on long-term holders who set up devices once and never updated them. Custodians, exchange-traded products and multi-vendor setups gain by comparison, because they spread the implementation risk across more than one codebase. The open question is whether AI-assisted review clears the backlog of latent firmware defects faster than attackers find them, and the next few disclosure cycles will show which side is moving faster.

## What to watch

- How quickly BitBox users apply firmware 9.26.5, because unpatched devices stay exposed and update rates are the only measure of whether a disclosure actually reduced risk.
- Whether other wallet manufacturers publish results from AI-assisted audits of their own firmware, which would show the defect backlog is industry-wide rather than specific to two vendors.
- Whether any wallet vendor ships an optional post-quantum signing mode following Blockstream's benchmarks, which would move quantum resistance from research to a shipping product decision.
