
A severe USB vulnerability in BitBox02 hardware wallets could have allowed control-flow hijacking. CertiK uncovered the flaw; BitBox patched it in July. Wallet compromises cost $444M in H1 2026.
Alpha Score of 60 reflects moderate overall profile with strong momentum, strong value, moderate quality, poor sentiment.
Web3 security firm CertiK has identified a severe out-of-bounds write vulnerability in the BitBox02 hardware wallet. Researcher Guanxing Wen discovered that the flaw allowed potential control-flow hijacking through compromised USB commands.
BitBox already patched the issue in its July Oeschinen security update. The secret private keys stored inside the device were never directly exposed. Instead, the vulnerability sat in how the wallet communicated with a computer.
When receiving commands over USB, the wallet’s software blindly accepted instructions about how much data was coming in without checking whether it would fit into its temporary memory space. An attacker could exploit this by sending an oversized command to overflow that memory buffer, which BitBox noted could allow them to hijack control of the device.
CertiK noted that a connected computer or smartphone should always be treated as a source of untrusted input. Wallet firmware must safely process every command it receives.
The BitBox02 case is not isolated. Earlier in 2026, Ledger patched a MCU bootloader flaw after CertiK uncovered that host-provided reset handlers were not properly validated during firmware updates. Ledger said user funds were never at risk.
Wallet compromises have become the single most damaging threat in Web3. According to CertiK’s Hack3D H1 2026 Report, the first half of 2026 saw 344 security incidents resulting in more than $1.31 billion in total crypto losses. Wallet compromises alone drained over $444 million across just 33 separate attacks.
The BitBox02 case shows that hardware wallet security depends on more than isolating private keys. Firmware and communication protocols must also resist untrusted input. As wallet compromise becomes one of the costliest attack categories, users should keep firmware updated.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.