Bullish
BitBox Fixes Two Critical Hardware Wallet Vulnerabilities in v9.26.5
07:34
BitBox patches severe flaws allowing arbitrary code execution and fund redirection via malicious hosts. No exploits confirmed; users urged to update to v9.26.5 immediately.
Woofun AI reports that BitBox has remediated two critical security flaws in its hardware wallets through firmware version v9.26.5. An internal audit identified these issues alongside new details on a previously patched bootloader vulnerability. One flaw on BitBox Multi devices permitted malicious hosts to execute arbitrary code and install rogue firmware on unconfigured units. Another defect in Silent Payments could enable attackers to redirect Bitcoin to unintended addresses, potentially facilitating ransom scenarios. The bootloader issue might also trick users into installing malicious firmware capable of stealing funds. BitBox states there is no evidence of exploitation or fund theft and urges immediate updates.
WOOFUN AI
Impact Assessment · Quick Read
The disclosure of remote code execution and fund redirection vulnerabilities highlights persistent risks in hardware wallet supply chains and host-device interactions. While no exploits have been confirmed, the potential for ransom attacks via Silent Payments underscores the importance of timely firmware updates for securing 比特币 assets. This incident may prompt increased scrutiny on hardware wallet security audits and user education regarding device configuration states.
Generated by WOOFUN AI · For reference only, not investment advice
Comments
No comments yet.