BitBox Flags Two Critical Firmware Flaws, Ships Dixence Security Patch
AI مارکیٹ کا خلاصہ
BitBox disclosed two critical firmware vulnerabilities and a bootloader issue affecting older BitBox02 and certain multiversion devices, and released the Dixence security update. Exploitation reportedly requires phishing plus physical device tampering, with no reported fund losses or seed compromise. The news highlights ongoing hardware-wallet supply-chain and firmware risks, potentially increasing near-term security sensitivity among self-custody users until patches are widely applied.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+0.18%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
● Neutral
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
BitBox, the Swiss hardware wallet maker, said it has identified two critical security vulnerabilities and a separate bootloader issue following an internal AI-driven security review, and has rolled out the Dixence security update.
The company said exploitation would require a chain of events, including phishing and users unlocking devices that have been physically tampered with. BitBox added that it has seen no evidence of stolen user funds and that seed phrases have not been compromised.
One of the critical issues involves the bootloader on older BitBox02 models, which could allow an attacker to install malicious firmware and steal assets. BitBox noted the risk was partially addressed in the July Oeschinen update.
The second critical vulnerability affects the pre-initialization stage on Multiversion devices and could enable arbitrary code execution. A third issue relates to the silent payment feature; BitBox said it cannot directly drain funds but may be able to lock assets.
BitBox said the Nova version is not affected. Users running older firmware are urged to install Dixence as soon as possible. No user losses have been reported so far.