
Web3 security firm CertiK has identified a severe out-of-bounds (OOB) write vulnerability in the BitBox02 hardware wallet. The flaw, discovered by CertiK researcher Guanxing Wen, allowed potential control-flow hijacking through compromised USB commands.
It highlights a growing concern in the digital asset space: keeping private keys offline is no longer enough to guarantee total asset safety.
How the BitBox02 Vulnerability Worked
Hardware wallets keep private keys off internet-connected devices. But every transaction still starts outside the wallet. The device has to receive commands, parse data, show confirmation details, and produce a signature.
Sponsored
As BitBox publicly disclosed the issue in its July Oeschinen security update, the secret private keys stored inside the wallet were never directly exposed. Instead, the issue sat in how the device communicated with a computer.
When receiving commands over USB, the wallet’s software blindly accepted instructions about how much data was coming in without checking if it would actually fit into its temporary memory space.
An attacker could exploit this by sending an oversized command to overflow that memory buffer, which BitBox noted could allow them to hijack control of the device.
CertiK noted that a connected computer or smartphone should always be treated as a source of untrusted input, meaning wallet firmware must safely process every command it receives. The fix was rolled into BitBox’s July update.
A Broader Pattern in Hardware Wallet Security
The BitBox02 case is not isolated. Earlier in 2026, Ledger patched a MCU bootloader flaw (CVE-2025-15645) after CertiK uncovered that host-provided reset handlers were not properly validated during firmware updates.
That flaw affected Ledger’s MCU firmware update process, where the bootloader did not sufficiently validate a host-provided reset_handler address. Ledger remediated the issue and said user funds were never at risk.
The stakes for Web3 security have rarely been higher. According to CertiK’s Hack3D H1 2026 Report, the first half of 2026 saw 344 security incidents result in more than $1.31 billion in total crypto losses.
Wallet compromises proved to be the single most damaging threat, draining over $444 million across just 33 separate attacks.
Why This Matters
The BitBox02 case shows that hardware wallet security depends on more than isolating private keys — firmware, communication protocols, and confirmation flows must also resist untrusted input. As wallet compromise becomes one of the costliest attack categories in Web3, this incident is a reminder for users to keep firmware updated.
Dive into DailyCoin’s hottest crypto scoops:
Bitcoin Slips as US Inflation Stays Hot — Now All Eyes Turn to Warsh
Crypto Advocacy Group Backs 32 CLARITY Act Supporters