AI Audit Triggers BitBox’s Dixence Patch After Critical Firmware Flaws Surface
Zurich-based BitBox used frontier AI to spot severe firmware bugs and shipped Dixence (v9.26.5). No funds lost, seeds safe—but older firmware remains exposed until users update.

Because Bitcoin
August 18, 2026
Hardware wallets are having a week. After a major Coldcard exploit and a fresh SafePal data leak, BitBox disclosed that an internal AI-led review uncovered serious firmware issues in its BitBox02 line—then pushed the Dixence update to shut them down. The company says there’s no evidence of exploitation, no user funds lost, and wallet seeds were never at risk. But if you haven’t updated, you’re leaving a door unlocked.
What the AI uncovered - Bootloader trust gap: The bootloader—the gatekeeper that decides which firmware the device will accept—could, under specific conditions, be coerced into running malicious code. The attack path required phishing a user into installing a fake BitBoxApp and then unlocking a tampered device; from there, an adversary could load rogue firmware and siphon coins. An initial mitigation shipped in July’s Oeschinen release (v9.26.2), but BitBox now characterizes the original weakness as more severe than first disclosed. The newer BitBox02 Nova was never exposed due to its bootloader version. - Pre-setup memory corruption: On the Multi edition, a memory-corruption flaw before wallet initialization could allow arbitrary code execution when paired with a hostile computer—again enabling malicious firmware. The Bitcoin-only edition did not include the affected code. - Silent payments edge case: A less dangerous bug in the silent-payment feature couldn’t directly steal funds, but it could lock coins to an incorrect address—effectively a ransom-style nuisance.
All three are fixed in Dixence (v9.26.5). The download is live at bitbox.swiss/download, and devices running older firmware remain vulnerable until updated.
My read: the human link is still the weakest link The technical root-of-trust matters, but the common thread here is user coercion. Each severe path depends on social engineering—tricking someone to install a fake app and unlock a compromised device. That’s the real-world boundary where “cold” storage becomes warm. Good bootloaders enforce signature checks; great products minimize the ways people can be tricked into bypassing them, with tighter UX around firmware provenance, clearer on-device attestations, and fewer pre-setup attack surfaces. AI finding the flaws is useful; AI shaping safer flows—detecting spoofed apps, flagging anomalous host behavior—would be the next step.
Why this disclosure lands now - Context isn’t friendly: a five-year-old firmware bug let thieves drain roughly 1,596 BTC (over $130 million) from Coldcard users this year—the largest hardware–wallet hack of 2026. Days ago, a SafePal breach exposed personal data, stoking fears of “wrench attacks” against identified owners. - Confidence vs. complacency: Frontier AI makes audits faster and broader, but it can also breed false comfort. BitBox’s staged fixes—first in v9.26.2, now finalized in v9.26.5—are a better signal: iterate, verify, and communicate promptly.
What to do now - Update to v9.26.5 (Dixence) immediately. - Verify downloads and app authenticity; avoid sideloaded clients posing as BitBoxApp. - Treat pre-initialization states and host computers as untrusted until proven otherwise.
Hardware wallets remain a strong choice for self-custody, but “bulletproof” isn’t the bar—continuous verification is. BitBox’s proactive AI-led audit is the right direction; the next win is reducing the room for phishing to matter at all.