OKX Banner
BTC $79,893.00 (+2.15%)
ETH $2,506.08 (+2.31%)
BNB $708.88 (+1.52%)
XRP $1.46 (+5.61%)
SOL $106.13 (+10.65%)
TRX $0.34 (+1.04%)
HYPE $83.55 (+2.40%)
DOGE $0.09 (+4.09%)
ZEC $795.49 (+3.53%)
RAIN $0.02 (+0.05%)
LINK $11.81 (+4.61%)
LEO $9.34 (+0.64%)
XMR $455.72 (+4.45%)
ADA $0.21 (+3.86%)
XLM $0.19 (+3.75%)
BCH $269.35 (+2.36%)
CC $0.12 (+1.41%)
GRAM $1.41 (+1.09%)
LTC $50.13 (+0.15%)
HBAR $0.08 (+2.73%)

BitBox02 Wallet Bug Could Have Let Hackers Hijack Signed Transactions

Share on X icon · Published 4 часа назад on August 27, 2026 · Nikolas Sargeant

CertiK uncovered an out-of-bounds write flaw in the BitBox02 hardware wallet, highlighting security risks across firmware and host-device communication.

BitBox02 Wallet Bug Could Have Let Hackers Hijack Signed Transactions

Web3 security company CertiK has identified an out-of-bounds write vulnerability in the BitBox02 hardware wallet, highlighting the risks that can arise when a secure device processes commands from a connected computer or smartphone.

According to the press release shared with Cryptowisser, BitBox disclosed and fixed the issue in its July Oeschinen security update, crediting CertiK researcher Guanxing Wen with discovering and responsibly reporting the flaw.

BitBox02 Flaw Affected USB Host-Device Communication

The vulnerability existed in the way the affected BitBox02 firmware handled a specific USB Human Interface Device control request.

During that process, the firmware accepted a host-controlled length value without verifying that it fit within the destination control buffer. A specially crafted request could consequently cause the wallet to write data outside the buffer’s allocated memory region.

BitBox said the vulnerability could allow control-flow hijacking, meaning malicious input could potentially influence how the firmware executes instructions.

The company addressed the flaw through its July security update. Users should ensure their devices are running the latest available firmware.

Hardware wallets are primarily designed to isolate private keys from internet-connected computers and mobile devices. Transactions, however, still originate outside the wallet.

A hardware wallet must receive external commands, parse transaction data, show confirmation details, and generate a signature after the user approves the request.

This process means the wallet’s security boundary includes more than the component holding the private key. It also covers firmware, communication protocols, memory handling, display logic, software updates and authorization processes.

The BitBox02 vulnerability arose along this wider host-device interaction path. A computer or smartphone connected to a hardware wallet may be compromised and should therefore be treated as a source of potentially malicious input.

Even if an attacker cannot directly extract the private key, they may attempt to interfere with how the wallet processes commands, interprets transaction data, or handles authorization and update operations.

A secure wallet must validate every incoming request before acting on it. It must also ensure that the information shown on the hardware wallet’s screen accurately corresponds with the transaction ultimately signed by the device.

The central security question is not only whether the private key remains isolated. It is also whether the device signs exclusively what the user has reviewed, understood, and approved.

Ledger Firmware Issue Highlighted a Similar Risk

The BitBox02 finding follows an earlier vulnerability Wen discovered in a separate Ledger hardware wallet component.

Ledger disclosed the issue in a 2026 security bulletin after Wen reported it through the company’s bug bounty program. The vulnerability was subsequently catalogued as CVE-2025-15645.

The flaw affected the microcontroller firmware update process. Ledger’s bootloader did not sufficiently validate a host-provided reset_handler address, creating a potential weakness in the device’s boot path.

Ledger fixed the vulnerability and said users’ funds were never at risk. Although the Ledger and BitBox02 issues affected different products and processes, both illustrate the same wider concern: every component capable of receiving, interpreting, or acting on external input forms part of a hardware wallet’s trust boundary.

CertiK’s Hack3D report recorded 344 Web3 security incidents during the first half of 2026, resulting in more than $1.31 billion in losses.

Wallet compromise was the most financially damaging attack category. CertiK attributed more than $444 million in losses to 33 wallet-related incidents.

The figures demonstrate why attackers increasingly target systems surrounding private keys, including wallet applications, APIs, authorization mechanisms, update services and device communications.

As wallets concentrate control over digital assets and transaction permissions, weaknesses anywhere in the signing process can carry substantial financial consequences.

Hardware Wallets Operate Within a Larger Signing Environment

A hardware wallet does not function as an isolated security product. It operates within a wider environment that includes companion applications, transaction-building services, backend infrastructure, and recovery mechanisms.

The full signing process can involve several components:

  • A computer or phone creates the transaction.

  • A companion application sends the transaction to the hardware wallet.

  • The wallet firmware parses the incoming request.

  • The device displays transaction details for confirmation.

  • The user approves or rejects the request.

  • The wallet signs the approved transaction.

  • The host application broadcasts it to the network.

A weakness at any point could affect whether the final signature corresponds with the user’s original intent.

Assessing only a wallet application, smart contract or secure chip may fail to reveal how malicious external input could influence a signature.

A comprehensive hardware wallet review should examine host-device communications, firmware logic, bootloader security, memory protections, update procedures and on-device confirmation flows.

Each layer must preserve the same transaction details, authorization policies and user approval from the moment a transaction is created until the final signature is produced.

The BitBox02 and Ledger findings demonstrate the value of examining low-level communication and boot processes alongside more visible wallet features.

Hardware wallet owners can reduce their exposure by following several security practices:

  • Install firmware updates from the manufacturer’s official channels.

  • Download companion applications only from verified sources.

  • Check addresses, asset amounts, and network fees on the hardware wallet’s display.

  • Reject unexpected signing or update requests.

  • Treat the connected computer or phone as potentially compromised.

  • Protect recovery phrases offline and never enter them into websites or unverified applications.

For wallet manufacturers, the findings reinforce the need to validate all host-controlled input and assess the complete signing environment rather than concentrating exclusively on private-key storage.

 

Nimiq Offers $17,000 to Developers Building Mini Apps for Its Payment App
Next article Nimiq Offers $17,000 to Developers Building Mini Apps for Its Payment App
Nikolas Sargeant
Nikolas Sargeant Editor-in-Chief

Nik is a content and public relations specialist with an ever-growing interest in Crypto. He has been published on several leading Crypto and blockchain based news sites. He is currently based in Spain, but hails from the Pacific Northwest in the US.