The first vulnerability involved memory corruption within unconfigured Multi editions of the BitBox02 and BitBox02 Nova. A malicious host connected to a new, uninitialized device could potentially execute arbitrary code, creating a pathway to install malicious firmware. Because firmware governs core cryptographic operations and transaction verification, BitBox categorized this flaw as severe for its potential to compromise device integrity.
A second issue affected the implementation of Silent Payments, a privacy feature that generates stealth addresses for Bitcoin transactions. An attacker could exploit this flaw to force Bitcoin to be locked to an unintended address, effectively rendering the funds inaccessible to the owner. While the vulnerability did not permit direct theft, it could have been used to coerce users into paying a ransom for the recovery of their assets.

Comments (0)
No comments yet. Be the first!