XKEYCHAINX LABS
BitBox / Public disclosure

Three security findings in Dixence disclosure

Older bootloader: malicious firmware. Uninitialized Multi: memory corruption. Silent Payments: funds lock.

Source date: 2026-08-17Reviewed: 11 October 2026

Affected scope

BitBox02 / Nova; scope differs by finding

What the attack requires

Malicious host; bootloader attack additionally requires tricking the user into installing firmware.

Response & remediation

What changed

9.26.5 covers all three; consult current vendor upgrade instructions.

What this finding establishes

Nova is outside the old-bootloader finding; Bitcoin-only firmware is outside the Multi finding. Vendor articles differ on the earliest bootloader fix; 9.26.5 covers this batch.