News
Weekly Brief 21.08.2026: BitBox Firmware Patch
Weekly brief for the Baltic and Nordic segment: BitBox's 17-18 August Dixence update addresses three firmware vulnerabilities in BitBox02 wallets; funds reportedly unaffected.
No new major developments in the segment over the past 24-48 hours, so here's a weekly brief. The clearly dateable turning point of the week is BitBox's August 17 Dixence security update, which fixes three firmware vulnerabilities in BitBox02 wallets (patch 9.26.5); no known losses. With Coldcard context.
Friday, 21 August 2026. This is a Week Brief publication. Over the past 24-48 hours, there have been no clearly dateable, new major developments in our segment - crypto exchanges and CASPs, hardware wallets, crypto cards, and tax tools serving the Baltics (LV, LT, EE) and Nordics (FI, SE, NO, DK). Therefore, we've opted for a weekly brief instead of a daily one: the most clearly dateable and significant development for the segment over the past seven days is the security disclosure by hardware wallet manufacturer BitBox on 17-18 August. We're treating this as the week's main news, while ongoing stories - the Coldcard incident and regulatory register movements - remain on our watchlist with precise previous dates, rather than being repeated as fresh news.
BitBox Dixence Update: Three Firmware Vulnerabilities, Funds Unaffected
Hardware wallet manufacturer BitBox (BitBox Swiss AG) published a security update on 17 August, codenamed Dixence, and simultaneously disclosed three firmware vulnerabilities affecting its BitBox02 series devices. The company emphasises that it has received no reports of stolen user funds and that the wallet seed was not compromised in any scenario.
The first vulnerability, classified as "severe", relates to the bootloader: in BitBox02 firmware versions up to 9.26.1, an attacker could theoretically manipulate users into installing malicious firmware. This is addressed by release 9.26.2 (Oeschinen). The second, also "severe" vulnerability, affected the Multi edition up to firmware 9.26.4 - memory corruption could allow arbitrary code execution if an uninitialised wallet device was connected to a malicious computer; the fix is included in 9.26.5. The third issue, rated as "potentially severe", in BitBox's Silent Payments implementation (firmware 9.21.0-9.26.4), if exploited, could "freeze" funds at an undesirable address in an extortion scenario; this was also fixed in version 9.26.5. Neither the BitBox02 Nova nor the Bitcoin-only edition were affected by the first vulnerability.
The company states that the issues were discovered during internal security audits, also utilising advanced artificial intelligence models, and that their exploitation would, in any case, require phishing or physical/logical access to the victim's computer. BitBox's recommendation to users is unequivocal: update the BitBoxApp and device firmware via the app's settings to the latest version (9.26.5).
It's worth maintaining a moderate assessment. The severity of the vulnerabilities and the firmware versions are specific, publicly disclosed facts from the manufacturer; the claim that funds are unaffected is currently based on BitBox's own investigation, and there is no independent public confirmation of zero losses. Proactive self-disclosure after an internal audit is a positive security practice, but the real protective step only occurs when the user actually updates the firmware.
Context: A Wave of Hardware Wallet Security in the Region
BitBox's disclosure does not appear in a vacuum. It follows the early August Coldcard (Coinkite) incident, where a multi-year-old firmware flaw allowed funds to be drained from specific models; industry estimates of the total losses grew throughout August and exceeded 1,500 BTC (approximately over 100 million US dollars), and this figure is still an estimate. Both cases together mark a clear trend: hardware wallet firmware - not just seed storage - is becoming a primary attack and audit surface.
The crucial difference for Baltic and Nordic users is that in the BitBox case, it's about a proactive manufacturer's fix with no known losses, whereas in the Coldcard case, it's about an actively exploited vulnerability with real losses. The practical conclusion in both cases is the same: self-custody does not negate the need to follow manufacturer security announcements and update firmware in a timely manner.
What This Means for Baltic and Nordic Users
There's no direct link to any local LV, LT, EE, FI, SE, NO, or DK platform this time - no regional exchange, card issuer, or tax tool has been affected. The impact is on hardware wallet users in the region who store assets on BitBox02 devices. Those using BitBox02 Multi or older BitBox02 firmware versions are advised to immediately check their firmware version and update it to 9.26.5. This recommendation also applies to those who store the device without an initialised wallet - this specific scenario was critical in the second vulnerability.
The broader picture for the regional segment remains unchanged: after the end of the MiCA transition period on 1 July, the main structural developments are still CASP licensing and hardware wallet security, rather than a return of retail volumes. This week, the security theme dominates the segment.
Watchlist (Ongoing Stories, Not Fresh News)
These points are not news from the last 24 hours; we keep them under observation with precise previous dates.
Coldcard (Coinkite) incident: We followed the draining of funds caused by a hardware wallet firmware defect in daily briefs on 2-4 August and weekly briefs on 9 and 12 August. The total drained amount, according to August estimates, exceeded 1,500 BTC and continues to be refined; we consider this an ongoing, not a new, event. The regional conclusion remains unchanged: the risk is tied to specific Coldcard models and firmware, not to any regional platform.
ESMA MiCA register: In the latest register updates (late July), newly added companies primarily came from Germany, Denmark, Bulgaria, and Latvia (including Bleap and Nodu Digital from Latvia in the July update), but the movement of new firms from Lithuania, Estonia, Finland, Sweden, and Norway remained limited. We are monitoring the next ESMA update as the most important structural indicator for the region's CASP segment.
Crypto card segment: Kraken launched a Mastercard network debit card in the EEA and UK on 14 July with up to 2% cashback in Bitcoin; the product is formally available to Baltic and Nordic EEA users, but a separate regional rollout has not yet been announced. No new announcements this week.
Nordic exchanges: Safello's Q2 report (7 August, revenue -33%) and the competitive dynamics of local operators - Safello, Firi, K33 - in the institutional segment remain in context. No new quarterly data or regulatory decisions this week.
Summary for Market Participants
Hardware wallet security is the dominant theme in our segment this week. BitBox's proactive Dixence fix - with no known losses - and the ongoing Coldcard incident with real losses together underscore that firmware updates are an integral part of self-custody, not an optional step.
For users in the Baltics and Nordics, the practical task is specific: check your hardware wallet model and firmware version and update it (to 9.26.5 in the case of BitBox02), and ensure your device was not affected by the previous Coldcard incident.
Evaluate manufacturer security announcements separately from independently verified facts: the claim of zero losses is currently based on BitBox's own investigation, and while reasonable, it is not independently confirmed.
The structural indicator for the segment remains the movement of the ESMA register - follow the next update regarding Baltic and Nordic firms.
Sources
- BitBox - BitBox 08.2026 Dixence security update (official announcement, 17.08.2026)
- Decrypt - Bitcoin Wallet Maker BitBox Says AI Found Severe Flaws in Firmware (18.08.2026)
- crypto.news - BitBox patches wallet flaws that could install malicious firmware (18.08.2026)
- Bitcoin Magazine - BitBox Warns Bitcoiners After Discovering 'Severe' Vulnerability In Firmware (18.08.2026)
- CoinDesk - Coldcard urges users to move bitcoin as active wallet exploit continues (04.08.2026)
- ESMA - Markets in Crypto-Assets Regulation (MiCA)