BitBox Patches Severe Firmware Vulnerabilities Found With AI

BitBox released its 08.2026 Dixence firmware update on August 17, patching two severe vulnerabilities found during internal audits that used frontier AI models. According to BitBox, there are no reports of stolen funds, but users running older firmware remain exposed to the disclosed issues until they install the update.
BitBox released its 08.2026 Dixence firmware update on August 17, patching two severe vulnerabilities identified during internal security audits that included the use of frontier AI models. The Swiss hardware-wallet maker recommended that all users update their devices, stating that the release addresses the security issues described in its advisory.
According to BitBox's release notes, the company has received no reports of stolen user funds, and existing wallet seeds are not affected by the update. The advisory nevertheless warns that firmware fixes protect users only after installation.
Vulnerabilities and exposure
BitBox reported that the release fixes two severe firmware vulnerabilities discovered internally by its engineering team. It also provided additional information about a bootloader vulnerability that had been fixed in an earlier release.
According to BitBox, exploitation of that earlier bootloader issue could have enabled an attacker to manipulate a user into installing malicious firmware on an authentic BitBox02 device. The company characterized the scenario as severe because malicious firmware could be used to steal funds, while noting that exploitation would require both significant technical capability and a successful phishing attack against the user.
The bootloader exploit was initially found by BitBox engineers and later independently disclosed by external researchers, according to the company's update.
AI-assisted auditing
In a separate August 4 post, BitBox wrote that AI tools can accelerate analysis of large codebases, identify suspicious patterns, and help fuzz interfaces at scale. The company described its latest firmware release as including fixes for issues identified by external researchers and internal audits using AI tools.
This account is a concrete example of AI being used as an assistive capability in security review rather than as a replacement for vulnerability validation, remediation, and disclosure processes. In security-sensitive embedded systems, automated code analysis and fuzzing can increase the number of findings, but signed update delivery and user patch adoption remain necessary controls.
For hardware-wallet users, the immediate action is operational rather than theoretical: install the current BitBox firmware through the BitBoxApp. For security teams building firmware-backed products, the disclosure also underscores a broader pattern in which faster AI-assisted discovery shortens the window between a vulnerability becoming known and the need for deployed devices to receive a patch.
Key Points
- 1BitBox patched two severe firmware flaws found during AI-assisted internal audits, making current firmware installation the immediate user protection.
- 2A previously fixed bootloader issue could enable malicious firmware installation after phishing, according to BitBox's security advisory.
- 3AI-assisted security research can accelerate findings, while signed updates, disclosure, and fleet patch adoption remain essential defensive controls.
Scoring Rationale
The disclosure provides a real-world example of frontier AI models contributing to severe vulnerability discovery in security-critical firmware. Its direct scope is limited to BitBox users, but the patching and update-adoption lessons are relevant to embedded-device and AI-assisted security teams.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

