Swiss hardware wallet manufacturer BitBox fixed « severe vulnerabilities » in its BitBox Multi firmware, with no funds reported stolen. One flaw could have allowed attackers to trick users into installing malicious firmware to steal their funds, while another was related to memory corruption. The Bitcoin-only BitBox edition was not affected by these vulnerabilities. BitBox urged all users to update their firmware via the official BitBoxApp without panic. This announcement follows the hack of Coldcard wallets by Canadian company Coinkite, where $115 million in bitcoin were stolen due to a similar bug affecting seed phrase generation.
Source: Read the original article

