BitBox patched two severe firmware vulnerabilities on Tuesday and told users to update now. The Swiss hardware-wallet maker found the flaws during an internal audit aided by frontier AI models. Either bug could have let an attacker steal funds.
No funds were taken. “There are no reports of stolen user funds and there is no reason for users to panic,” BitBox wrote in a blog post announcing what it called the Dixence security update.
The bugs hit the BitBox02 Multi edition. One was a memory-corruption flaw that could enable arbitrary code execution, opening a path to install malicious firmware and, in turn, potential loss of funds, Bitcoin Magazine reported. The second severe vulnerability would have allowed an attacker to manipulate a user into installing firmware that could lead to theft. The Bitcoin-only edition of the BitBox02 was not affected. Its firmware does not contain the compromised code.
What sets the disclosure apart is how the flaws surfaced. BitBox used two frontier AI models during its internal audit: Anthropic’s Claude discovered one bug, OpenAI’s GPT the other, Decrypt reported. BitBox told Decrypt it was the first time the company had used AI to find bugs in its firmware.
The fix is a firmware update pushed through the BitBoxApp. BitBox recommends users accept the in-app update prompt directly rather than searching for it independently. No fund migration needed. Updating the device is sufficient.
That last point matters more in light of what happened to Coldcard. Coinkite, the Canadian firm behind Coldcard, warned users July 31 about a firmware bug that caused weak seed generation on its Mk3 devices. The flaw had been present since version 4.0.1, released in March 2021. Hackers have since drained a confirmed $115 million in bitcoin from affected wallets, per Galaxy Research figures cited by Bitcoin Magazine, and the total could climb higher.
BitBox’s disclosure lands amid that scrutiny. Hardware wallets are sold on a simple promise: private keys stay offline, out of an attacker’s reach. A memory-corruption bug that enables arbitrary code execution on the device itself cuts against that promise. Even when no funds were moved. Even when the window closed before anyone tried.
Several details remain undisclosed. Neither source names the exact version number of the patched firmware. The timeline of when the bugs were found versus when the update shipped is not stated. No outside security firm was credited. The audit was internal, supplemented by the two AI models.
“We just released the Dixence security update,” BitBox said on X. “During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware.”
BitBox02 Multi edition owners running older firmware remain exposed until they update. The Bitcoin-only edition does not need the patch.


