Critical Security Update for Multisig Hardware Wallet
A Bitcoin multisig hardware wallet has rolled out a significant update to version v0.4.0, addressing two security vulnerabilities. The development team has stated that there is no evidence of any user funds being lost due to these issues.
Details of the Patched Vulnerabilities
The update resolves two distinct security concerns:
- Vulnerability FSA-2026-001: A maliciously crafted signature request could falsely label a transaction output as "belonging to the user's wallet." The previous device firmware failed to verify this claim and did not display the suspicious output on the final confirmation screen. This could have tricked users into approving transactions that sent funds to unfamiliar addresses.
- Vulnerability FSA-2026-002: This issue related to the handling of change addresses. Under certain conditions, a generated change address might fall outside the standard scanning range of the wallet's recovery phrase. During a backup restoration, this would make it appear as though some funds were "missing," even though they remained securely on the blockchain at the wallet's address.
What's New and User Action Required
Upon installing the v0.4.0 application, users will be prompted to upgrade their device's firmware. Beyond the critical fixes, this release introduces firmware downgrade protection, a feature designed to prevent the device from being maliciously rolled back to older, vulnerable firmware versions.
The team strongly advises all users to update both their companion application and device firmware as soon as possible. For multisig wallet holders, maintaining up-to-date software and hardware is a fundamental practice for safeguarding digital assets.