BitBox fixes severe Bitcoin wallet vulnerabilities discovered in AI-assisted security audit
Swiss hardware wallet manufacturer BitBox has released firmware version 9.26.5 to patch multiple severe vulnerabilities discovered during internal security reviews utilizing frontier AI models. No user funds have been stolen. The announcement follows a massive security failure in Coinkite's Coldcard Mk3 wallets, where a firmware bug resulted in weak seed generation and enabled hackers to steal up to $115 million in Bitcoin. The contrast highlights the limitations of AI-assisted code audits.
BitBox firmware vulnerability patches
▪Swiss wallet manufacturer BitBox stated that no user funds were stolen, no exploits were reported, and wallet seeds remained unaffected by the discovered firmware vulnerabilities.
▪A bootloader vulnerability in BitBox02 devices, previously fixed in firmware version 9.26.2, could have allowed attackers to install malicious firmware via a fake BitBoxApp.
▪Swiss wallet manufacturer BitBox urged users to update their device firmware and the BitBoxApp through official in-app prompts to resolve the security issues.
▪A memory-corruption vulnerability affected unconfigured BitBox Multi-edition devices connected to a malicious host, whereas Bitcoin-only editions were unaffected.
▪BitBox released firmware version 9.26.5 to fix two severe vulnerabilities and a silent-payment flaw discovered during internal security reviews using frontier AI models.
Coldcard weak seed generation
▪Coinkite's Coldcard Mk3 hardware wallets generated weak private keys using the device's serial number and internal clock starting in March 2021 due to a firmware bug.
▪The Coldcard firmware bug occurred when a safety check failed to detect that the hardware random number generator was disabled, reducing entropy from 128 bits to about 40.
▪Coinkite warned users on July 31, 2026, about the Coldcard Mk3 firmware bug, urging them to immediately migrate their funds to newly generated secure wallets.
Bitcoin wallet theft incident
▪Galaxy Research reported that the total stolen funds from the Coldcard vulnerability reached 1,367 Bitcoin, valued at approximately $88.6 million by August 2, 2026.
▪Bitcoin Magazine reported that hackers have stolen a confirmed $115 million in Bitcoin from Coldcard users according to updated figures from Galaxy Research.
▪An attacker exploited the Coldcard weak seed generation flaw to steal 594 Bitcoin from approximately 500 inactive wallets in 25 minutes on July 30, 2026.
AI security audit limitations
▪Coinkite ran an advanced AI security model over its Coldcard codebase weeks before the theft, but the AI review failed to detect the critical firmware vulnerability.
▪Security experts note that AI-assisted code reviews accelerate defensive asymmetry because defenders must find every vulnerability while attackers only need to find one exploitable path.
Hardware wallet defense asymmetry
▪The Coldcard seed vulnerability also compromised users who imported their generated seeds into multi-chain wallets, extending the security risk beyond the Bitcoin blockchain.
▪Unlike the Coldcard incident where users must migrate funds to new wallets, BitBox users only need to update their firmware to secure their devices.
Story comments
Loading comments…