Hardware wallet news has been grim lately. This one goes the other way: the bugs were found, fixed and announced before anybody’s coins moved.
BitBox, the Swiss firm behind the BitBox02, says it has patched two severe flaws in its wallet firmware and is asking every owner to update to version 9.26.5. The company says it has had no reports of the bugs being exploited and no reports of lost funds. Per Decrypt, the flaws were turned up with the help of frontier AI models rather than by an attacker.
Firmware is the software running on the device itself, the code that handles your keys and signs your transactions. That matters because a hardware wallet is sold on the promise of staying offline, and it’s easy to assume offline means finished. It isn’t. The device is still a small computer, and its code can still have holes in it.
The catch is the obvious one. A patch only protects the people who install it, and hardware wallets tend to sit in drawers for months at a time. Older firmware leaves the exposure in place.
The update itself has since become bait. BitBox and Trezor have both warned that fake security alerts are going out in their names, telling owners their wallet is at risk and pointing them somewhere to fix it. Per Cointelegraph, BitBox says several bitcoin companies appear to have been targeted through a newsletter provider they share, and Trezor has confirmed a breach at its email service, which is part of why the senders can look genuine. Neither company has changed its firmware advice. What has changed is that an email telling you to act on it is now exactly the sort of thing an attacker would send.
This is the version of the story where the system worked. Compare it with the Coldcard episode, where owners were left waiting to find out whether their device was affected while money was already gone. Same category of product, opposite outcome. If you hold coins on any hardware wallet, updating is still the right move, but do it by typing the maker’s address into your browser yourself and checking its firmware page, not by following a link or a QR code from an email, however official the sender looks. No legitimate wallet maker needs your to install an update. Our self-custody guide covers the rest.
