Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
BitBox firmware vulnerability fixed as Coldcard’s flaw drains $115M in bitcoin

BitBox firmware vulnerability fixed as Coldcard’s flaw drains $115M in bitcoin

Cryptonomist2026/08/19 05:30
By: Cryptonomist
BTC+0.44%

A Swiss hardware wallet maker just gave the Bitcoin community a rare piece of good security news, and the timing could not be more pointed. BitBox disclosed and patched a BitBox firmware vulnerability that could have let an attacker trick users into installing malicious firmware and draining their funds, but the company says it caught the flaw before anyone lost a single satoshi. The disclosure lands just weeks after a similar-sounding firmware flaw in rival wallet Coldcard turned into one of the largest hardware wallet thefts on record.

Key takeaways

  • BitBox patched a severe firmware vulnerability that could have allowed attackers to push malicious firmware and steal funds, but reports no user funds were stolen.
  • The flaw affected only the Multi edition of the BitBox wallet; the Bitcoin-only edition was not affected.
  • BitBox users only need to update their firmware through the official BitBoxApp, not migrate funds to new wallets.
  • Coldcard’s Coinkite faced a much bigger crisis, with a firmware bug tracing back to March 2021 blamed for more than $115 million in stolen bitcoin, according to Galaxy Research.
  • According to Decrypt, BitBox credited AI-assisted testing with surfacing the vulnerabilities before they could be exploited.

BitBox patches severe firmware vulnerability

BitBox says it found and fixed two “severe vulnerabilities” in its hardware wallet firmware before attackers could use them against real users. The Swiss company laid out the details in a blog post published Tuesday, walking through exactly what went wrong and why customers shouldn’t panic.

Vulnerability details and affected models

One of the flaws could have let an attacker manipulate a user into installing tampered firmware, opening the door to fund theft. The second issue involved memory corruption that, in theory, could enable arbitrary code execution and the installation of malicious firmware, again risking a loss of funds. Crucially, BitBox confirmed the problem was tied to the Multi edition of its device. The Bitcoin-only edition never contained the affected code, so it was never exposed to this particular BitBox firmware vulnerability.

According to Decrypt, BitBox pointed to AI-assisted security testing as the method that helped surface the flaws, a detail that underscores how wallet makers are increasingly leaning on automated tools to hunt for bugs before criminals find them first.

User guidance on firmware update

BitBox has been direct with its customer base: there is no evidence of stolen funds and no reason to panic. Still, the company is urging every user to update to the latest firmware version, which it says resolves all the security issues described in the disclosure. The recommended path is simple — update through the official BitBoxApp, ideally by tapping the in-app prompt rather than hunting down update files elsewhere, since that reduces the risk of installing a fake or malicious version.

Unlike the crisis that hit Coldcard owners, BitBox users do not need to move their coins to a new wallet or generate fresh seed phrases. A firmware update is enough. That distinction matters a lot for anyone trying to gauge how seriously to treat this news.

Coldcard firmware bug causes massive Bitcoin theft

The backdrop to BitBox’s announcement is a much darker story still playing out in the Coldcard world. A firmware bug in Coinkite’s Coldcard devices triggered weak seed generation, and hackers turned that weakness into one of the costliest hardware wallet exploits in Bitcoin’s history.

Seed generation flaw and timeline

The root of the problem traces back to firmware version 4.0.1, released by Coinkite in March 2021. That update caused seed generation on Coldcard Mk3 devices to quietly fall back on a weak software pseudorandom number generator instead of the device’s dedicated hardware true random number generator. According to crypto.news, the flaw had reportedly been flagged to Coinkite by researchers in the past, meaning some affected seeds may have been sitting exposed for years before anyone acted on it.

Weak randomness in seed generation is a serious problem because it narrows the range of possible private keys an attacker needs to guess. Galaxy Research reported that the exploitation itself moved fast: on July 30, attackers drained roughly 1,083 BTC from more than 1,000 addresses in just 41 minutes, with additional waves of transfers following as the incident unfolded through mid-August.

Impact and official warnings

Coinkite first warned Coldcard users on July 31 that the bug allowed hackers to essentially guess investor seed phrases. Early tallies from crypto.news put stolen funds around $112 million, and that figure kept climbing as more affected devices came to light. According to Galaxy Research’s more recent figures cited by Bitcoin Magazine, the confirmed total has since surpassed $115 million in stolen bitcoin — and the real number could still be higher as the investigation continues.

Unlike the BitBox fix, a firmware update alone does not protect Coldcard users whose seeds were already generated under the flawed system. Coinkite and other Bitcoiners have urged affected users to move their funds to new wallets immediately rather than simply patching and continuing to use the same seed phrase.

Comparing hardware wallet security risks and responses

Put side by side, these two incidents show just how differently a firmware flaw can play out depending on when it’s caught and how it’s handled. Why does this comparison matter? Because it draws a clear line between a near-miss and an actual catastrophe in the world of self-custody.

Differences in vulnerability scope and fixes

BitBox’s flaw was serious on paper — attacker-controlled firmware installation and memory corruption are not minor bugs — but it was discovered and patched before exploitation, and it never touched the seed generation process itself. Coldcard’s bug, by contrast, corrupted the randomness behind seed creation for years before anyone stopped the bleeding, which is why remediation required full fund migration rather than a simple software update.

Implications for Bitcoin security and self-custody

For everyday Bitcoin holders, the lesson isn’t that hardware wallets are unsafe — it’s that firmware integrity is now as important as the physical security of the device itself. A Coldcard seed bug that sat undetected since 2021 shows how a single overlooked line of code can eventually translate into nine-figure losses, while BitBox’s quick catch shows the same category of risk can be neutralized before it costs users anything. Both cases point to the same broader truth: hardware wallet security increasingly depends on how fast a manufacturer can find and fix firmware issues, not just on the cryptography baked into the chip.

That contrast is likely to shape how the market treats wallet makers going forward, with response speed and transparency becoming as important to buyers as the hardware specs themselves.

FAQ

What vulnerability was found in BitBox hardware wallet?

BitBox discovered severe firmware vulnerabilities in its Multi edition that could allow installation of malicious firmware leading to fund theft.

Do BitBox users need to migrate funds after the vulnerability?

No, users only need to update their firmware via the official BitBoxApp; fund migration is not necessary.

What happened with the Coldcard hardware wallet vulnerability?

A firmware bug in Coldcard starting from version 4.0.1 caused weak seed generation, allowing hackers to steal over $115 million in bitcoin.

What advice has Coinkite given to Coldcard users?

Coinkite advised Coldcard users to immediately move their funds due to the seed generation vulnerability.

{"@context":"","@type":"FAQPage","mainEntity":[{"@type":"Question","name":"What vulnerability was found in BitBox hardware wallet?","acceptedAnswer":{"@type":"Answer","text":"BitBox discovered severe firmware vulnerabilities in its Multi edition that could allow installation of malicious firmware leading to fund theft."}},{"@type":"Question","name":"Do BitBox users need to migrate funds after the vulnerability?","acceptedAnswer":{"@type":"Answer","text":"No, users only need to update their firmware via the official BitBoxApp; fund migration is not necessary."}},{"@type":"Question","name":"What happened with the Coldcard hardware wallet vulnerability?","acceptedAnswer":{"@type":"Answer","text":"A firmware bug in Coldcard starting from version 4.0.1 caused weak seed generation, allowing hackers to steal over $115 million in bitcoin."}},{"@type":"Question","name":"What advice has Coinkite given to Coldcard users?","acceptedAnswer":{"@type":"Answer","text":"Coinkite advised Coldcard users to immediately move their funds due to the seed generation vulnerability."}}]}

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

AI Data Centers Ignite Demand for Power Management Chips! Analog Devices (ADI.US) Achieves Record Q3 Revenue, Q4 Guidance Exceeds Expectations

Analog Devices outperformed expectations due to AI-driven demand for chips.

智通财经2026/08/19 13:36

Trending news

More
1
AI Data Centers Ignite Demand for Power Management Chips! Analog Devices (ADI.US) Achieves Record Q3 Revenue, Q4 Guidance Exceeds Expectations
2
Target Corporation stock holds uptrend after earnings beat, guidance hike

Crypto prices

More
Bitcoin
Bitcoin
BTC
$65,082.11
+1.49%
Ethereum
Ethereum
ETH
$1,930.61
+1.86%
Tether USDt
Tether USDt
USDT
$0.9992
+0.02%
USDC
USDC
USDC
$0.9999
+0.01%
XRP
XRP
XRP
$1.02
+2.00%
Solana
Solana
SOL
$78.42
+3.09%
TRON
TRON
TRX
$0.3325
+0.12%
Hyperliquid
Hyperliquid
HYPE
$58.94
-0.67%
Dogecoin
Dogecoin
DOGE
$0.07047
+1.01%
Zcash
Zcash
ZEC
$511.43
+1.52%
How to buy BTC
Bitget lists BTC – Buy or sell BTC quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter