BitBox
BitBox, made by Shift Crypto (Zurich), is the Bitcoin-only hardware wallet most associated with Swiss-engineered minimalism, fully open-source firmware, and clean multi-vendor multisig pairing. The current product as of 2026 is the BitBox02 BTC-only edition ($137), USB-C with a dual-chip architecture (general-purpose microcontroller + Microchip ATECC608B secure element). A “multi” edition supporting altcoins exists at the same price, but the BTC-only variant is the principled choice for Bitcoin holders. Distinguishing features include a minimal-friction setup flow (with optional dice-entropy contribution), excellent multisig support pairing cleanly with Coldcard or Trezor in vendor-diverse 2-of-3 configurations, and the strongest open-source posture among devices with a dedicated secure element. Trade-offs: USB-only (no air-gap workflows), no native SLIP-39 (BIP-39 only), and a smaller community than Trezor or Coldcard. BitBox02 BTC-only serves as the canonical multi-vendor-multisig component — often the right second or third device alongside a Coldcard or Trezor.
What this is
Vendor: Shift Crypto (Zurich, Switzerland). Founded by Douglas Bakkum and Jonas Schnelli (2014–2015 timeframe). Schnelli is a prominent Bitcoin Core contributor. The Swiss base and the deep Bitcoin Core developer involvement give BitBox a distinctive technical credibility.
Product line as of 2026-07-15:
- BitBox02 BTC-only edition ($137) — Bitcoin-only firmware; no altcoin support. The principled choice for Bitcoin holders.
- BitBox02 multi edition ($137) — same hardware, firmware supports Bitcoin plus several altcoins (Ethereum, Litecoin, Cardano historically). Same price as the BTC-only variant.
Shift has explicitly maintained the BTC-only variant as a separate product, signaling that the company takes the Bitcoin-only argument seriously rather than treating altcoin support as universally desirable. This is unusual in the hardware-wallet market and is part of BitBox’s distinctive positioning.
Firmware: Fully open-source under Apache 2.0 (OSI-approved). The BTC-only firmware is a stripped-down version of the multi firmware; the build process is reproducible by independent reviewers.
Hardware: Designed in Switzerland, assembled in Switzerland and shipped from Switzerland. The supply-chain transparency is among the strongest in the industry — Shift publishes details of the components and assembly process.
Secure element: Microchip ATECC608B. EAL-certified; physical-attack resistance comparable to Coldcard’s secure element. The dual-chip architecture (general MCU + secure element) is the standard pattern for modern hardware wallets.
Who this is for
BitBox02 BTC-only is a strong fit for:
- Multi-vendor multisig — BitBox pairs cleanly with Coldcard, Trezor, or Foundation Passport. The minimal-friction UX makes it a natural choice for the “second device” in a vendor-diverse 2-of-3.
- Open-source-aligned holders — Apache 2.0 firmware; reproducible builds; Swiss supply-chain transparency
- Bitcoin-only purists — the BTC-only firmware genuinely removes altcoin code paths from the device
- Holders who want simplicity without sacrificing capability — the UX is more approachable than Coldcard, less mainstream-consumer than Trezor; a Goldilocks position
- Holders concerned about supply-chain integrity — Swiss assembly, transparent component documentation, clear vendor-buy direct channels
BitBox02 is less appropriate for:
- Strict air-gap holders — USB-only; no QR or MicroSD signing paths. Holders who want strict air-gap should use Foundation Passport or Coldcard.
- SLIP-39 users — BIP-39 only; no SLIP-39 support. SLIP-39 users should use Trezor.
- BIP-85 power users — supported but not as deeply as Coldcard
- The mainstream-UX-seeking first-time user — Trezor’s touchscreen is friendlier; the BitBox02’s touch-button input is functional but less intuitive
Features and capabilities
BitBox02 specifics
- Touch-sensitive buttons — the device uses capacitive touch zones rather than physical buttons; smooth UX once learned
- OLED display — clear, legible, 128×64 monochrome
- USB-C — modern connector
- Dual-chip architecture — general MCU + ATECC608B secure element
- Microsoft Authenticator-style backup option — BitBox can back up the seed to a microSD card (encrypted), enabling rapid restore. This is a feature some holders use and some explicitly avoid; the encrypted microSD backup is convenient but introduces a digital copy of the seed.
- PIN entry on the device — via touch buttons; not as fast as a touchscreen but adequate
Common to BitBoxApp ecosystem
- BitBoxApp companion software — for Bitcoin-only holders, the BTC-only app is similarly stripped-down; pairs with the BTC-only device
- PSBT v2 support — modern PSBT handling
- BIP-380 output descriptors — for multisig
- BIP-39 passphrase support — entered via touch buttons; tedious for complex passphrases (the Coldcard Q’s QWERTY is meaningfully better here)
- Native multisig — supports 2-of-3, 3-of-5, and other configurations; coordinator-agnostic
BitBox-specific quirks
- The microSD backup option — controversial. Convenient (rapid restore from a microSD card) but introduces a digital copy of the seed. Holders should treat the microSD as seed-sensitive; many holders disable this feature.
- Touch-sensitive button input — different from Coldcard’s keypad and Trezor’s touchscreen. Some holders find it elegant; others find passphrase entry slow.
- The “BIP-39 mnemonic display” verification — BitBox displays the seed on the OLED for the holder to record; verification via on-device flow.
Tradeoffs vs alternatives
| Dimension | BitBox02 BTC-only | Coldcard Q | Coldcard Mk4 | Trezor Safe 5 | Foundation Passport |
|---|---|---|---|---|---|
| Price | $137 | $249 | $150 | $129 | $199 |
| Bitcoin-only | Yes | Yes | Yes | No | Yes |
| Open-source | Yes (OSI Apache 2.0) | Source-available | Source-available | Yes (GPL) | Yes (OSI) |
| Secure element | Yes (ATECC608B) | Yes | Yes | Yes (EAL 6+) | Yes |
| Air-gap signing | No (USB only) | QR + MicroSD | MicroSD only | No (USB only) | QR only |
| Native SLIP-39 | No | No | No | Yes | No |
| BIP-85 | Good | Excellent | Excellent | Good | Limited |
| Passphrase entry | Good (touch buttons) | Best (QWERTY) | Tedious | Excellent (touchscreen) | Good (touchscreen) |
| Multisig pairing | Excellent (the canonical second device) | Excellent | Excellent | Excellent | Excellent |
| Supply-chain transparency | Highest (Swiss) | High | High | High | High |
| Lopp 100-input signing | Fast | Fast | Fast | Moderate | Fast |
The principal alternatives to BitBox in similar use cases:
- Coldcard — more features (BIP-85, air-gap); pricier; less mainstream UX. BitBox + Coldcard is the canonical multi-vendor multisig pairing.
- Trezor — SLIP-39 + touchscreen; multi-coin firmware (which BitBox-BTC-only deliberately avoids); broader community but less focused.
- Foundation Passport — strict air-gap (which BitBox isn’t); pricier; Bitcoin-only like BitBox.
For most multi-vendor multisig configurations, BitBox + one other device (Coldcard or Trezor) is a strong baseline.
Setup and operation
The setup flow:
- Verify packaging — BitBox ships with tamper-evident seals
- Install BitBoxApp — desktop app for first-time setup
- Connect via USB — the device walks through setup
- Choose backup method — microSD encrypted backup, paper-only, or both. Many holders choose paper-only to avoid the microSD digital copy.
- Generate seed — BitBox displays 24 words on the OLED; the holder records them
- Verify the seed — on-device check
- Optionally set up a passphrase — entered via touch buttons
- Pair with a coordinator — BitBoxApp for single-sig; Sparrow, Specter, Nunchuk for multisig
The signing flow:
- Coordinator builds PSBT
- Transfer to BitBox via USB
- BitBox displays transaction details on OLED; holder verifies addresses on the screen
- Holder confirms via touch
- BitBox signs, returns to coordinator
- For multisig, repeat with other devices
The simplicity of the USB-only workflow is part of BitBox’s appeal — fewer transfer steps than air-gap devices, while preserving the keys-never-leave-device guarantee.
Recovery — restoring the wallet on a fresh device
As of 2026-09-12, checked against Shift Crypto’s own support pages (linked inline). The flow a holder — or someone recovering on the holder’s behalf — follows to get a BitBox02 wallet back from its backup: unlocking a device that still holds the seed, wiping it, restoring, applying the passphrase, and confirming the wallet in Sparrow.
What may be in hand
Two hardware models, each sold in a Multi and a Bitcoin-only edition: the original BitBox02 (USB-C only, black, standard OLED) and the BitBox02 Nova (USB-C plus Bluetooth for iPhone and iPad, glass display, three colours). Neither has a battery; the device draws power from whatever it is plugged into, so a dead-battery case does not exist. The edition is fixed in the secure bootloader and cannot be changed. The BitBoxApp (Windows, macOS, Linux, Android; iOS only with the Nova) is mandatory for setup, restore and firmware: a factory-fresh device ships without firmware and the app installs it at first connection. A firmware update never requires the recovery words.
Unlocking a device that still holds the seed
The unlock secret is the device password (Shift’s term, not “PIN”), typed on the device’s capacitive touch edges from a two-layout keyboard that shifts as you type; letters and digits only, no spaces or symbols. On connection: choose the screen orientation, compare and confirm the pairing code shown by the app and the device (the first time on each computer), enter the password, then the passphrase prompt if that feature is enabled. A correct password gives full access — balances, sending, showing the recovery words (Settings › Manage device › Backups › Show recovery words), creating a microSD backup, connecting to Sparrow.
Ten wrong passwords reset the device to factory settings. The screen counts down the remaining attempts, and confirming an empty entry counts as one. This is both the trap and the maker’s official route for a forgotten password: with the backup in hand, fail ten times on purpose and restore. There is no duress PIN, no decoy wallet, no anti-phishing words and no fingerprint reader; the pairing code is the only anti-tamper check.
Wiping the device
Two routes: the ten failed attempts above (no password needed), or from the app — Settings › Manage device › Expert settings › Factory reset, tick “I have a valid backup”, press the red Factory reset device button, confirm on the device. The private keys are erased; firmware and edition remain; coins on the chain are untouched. A factory reset followed by a restore is also the only way to change the device password.
Restoring from the backup
The BitBox has two backup formats, and a holder may have left either or both.
From the recovery words (12 or 24). Always entered on the device, never in the app — the maker states that an app asking for the words is a phishing attempt. In the BitBoxApp: “Set up your wallet” › Restore from recovery words › name the device › confirm the name and date on the device › choose 12 or 24 › type each word letter by letter on the touch edges (a word resolves after its first four letters; only the word actually displayed counts) › set a new device password. The app then synchronises. Any valid list of words opens a wallet, so a correct word in the wrong position produces an empty wallet with no error. Eighteen-word seeds are not offered on the restore page.
From the microSD card. The card is the BitBox’s default backup and is not encrypted — anyone holding it can restore. “Set up your wallet” › Restore from microSD card › insert the card text-side up › pick the backup by name, date and ID › confirm on the device › set a new password › “Backup Restored!” › remove the card. Neither the old device nor its password is needed. If no BitBox is available at all, Shift’s open-source backup-recovery tool (backup.html, run offline) extracts the words from the card file; the maker frames it as a last resort followed by moving the funds.
After a restore, an unexpectedly empty balance usually means a word out of place, an unfinished sync, an account not yet re-added, a passphrase not entered, or a wallet that used legacy 1… addresses (the BitBox derives native segwit bc1… addresses by default and does not show legacy ones). Additional accounts are re-added by hand. The seed is stored on the device after the restore; the device is not stateless.
The passphrase
Shift calls it the optional passphrase and treats “25th word” as a misleading name. It is off by default and must be enabled first: Settings › Manage device › Expert settings › Passphrase › Enable optional passphrase, confirm on the device, then reconnect. From then on the device asks for it after the password every session; leaving it empty opens the standard wallet. Up to 149 ASCII characters, spaces allowed, every character significant; the device shows the full passphrase back for checking before applying it. It is never stored and is in neither backup format. The only confirmation of which wallet is open is the root fingerprint (Settings › Manage device › Device information): a different passphrase gives a different fingerprint.
Connecting to Sparrow and confirming the first address
The BitBox02 is a USB device in Sparrow’s terms — Connected Hardware Wallet, with no QR or file export. The BitBoxApp must be closed first; the device talks to one application at a time. Shift’s own Sparrow guide: New Wallet › name › Connect Hardware Wallet › Scan › password on the device › confirm the pairing code in Sparrow and on the device (first time) › pick Keystore #0 (Account 1, m/84'/0'/0'; Account 2 is m/84'/0'/1') › Import Keystore › Native Segwit (P2WPKH) › Apply. Linux may need Sparrow’s udev rules (Tools › Install Udev Rules), and older BitBoxApp versions hold the device exclusively — unplug and reconnect. Sparrow no longer needs a prior BitBoxApp pairing as of v2.1.0, but the device must already be initialised. For watch-only, BitBoxApp › account › Account info › View account details shows the descriptor and xpub.
Address check, per Shift’s receiving guide: Sparrow’s Addresses tab › double-click an unused address › Receive › Display Address — the BitBox wakes and shows the address; compare, then tap the checkmark on the device. A mismatch means stop. A wrong derivation path shows an empty, unfamiliar account with nothing lost; correct the script type and derivation on Sparrow’s Settings tab.
Multisig
There is no configuration file to import. The BitBox02 registers a multisig setup on the device the first time a receive address is displayed for it — name the setup, confirm the cosigners’ xpubs against Sparrow’s Settings page — and stores a checksum so it can verify addresses independently; up to 25 setups. The wallet descriptor itself is in neither backup, so the Sparrow wallet file (Settings › Export › Sparrow Wallet file) or every cosigner’s xpub has to be kept alongside the seed. See Multisig setups and PSBT and wallet descriptors.
Security considerations
Strengths
- Fully open-source firmware (Apache 2.0, OSI-approved); reproducible builds
- Swiss-based supply chain with transparent component documentation
- Bitcoin Core developer involvement — Jonas Schnelli’s reputation gives BitBox credibility
- EAL-certified secure element — physical-attack resistance
- Bitcoin-only firmware option — removes altcoin code paths
- Reproducible firmware builds — third parties can verify shipped firmware matches published source
Known concerns
- The microSD encrypted backup feature — introduces a digital copy of the seed. Many holders disable this; some use it. The pattern is BitBox-specific and worth understanding before adopting.
- USB-only signing — no air-gap workflow; holders who want strict air-gap should use Passport or Coldcard.
- Touch-button passphrase entry is slow — for complex passphrases, the entry friction is notable. Pair BitBox with a different device if passphrases are a heavy part of the workflow.
- Smaller community — fewer third-party tutorials, fewer YouTube walk-throughs compared to Trezor or Coldcard. Official documentation is strong but the broader ecosystem is thinner.
Supply-chain integrity
Buy directly from shiftcrypto.ch. Swiss assembly is the canonical claim; verify tamper-evident packaging on arrival.
The 2020 Ledger leak does not affect BitBox; Shift Crypto’s customer database has not had a public leak. The Swiss jurisdiction provides additional regulatory protections for customer data.
Pricing and acquisition
As of 2026-07-15 (prices reverified; prior review 2026-05-14):
- BitBox02 BTC-only: $137 USD (typically CHF/EUR equivalent)
- BitBox02 multi edition: $137 USD (same price; different firmware)
Authorized channels: shiftcrypto.ch directly; some authorized resellers. Avoid generic marketplaces.
Bulk and business pricing: available for multisig configurations.
Common pitfalls
Buying the “multi” edition when you want Bitcoin-only. The BTC-only firmware is a meaningful structural choice. The multi edition is fine for some holders but the principled position is BTC-only.
Enabling microSD backup without understanding it. The encrypted microSD copy is a digital seed copy. Holders should make a deliberate decision about this feature rather than defaulting to it.
Treating BitBox as a standalone solution when a Coldcard or Passport would also fit. BitBox is strongest as one of two or three devices in a multi-vendor multisig. Holders running single-sig may find Trezor’s mainstream UX more comfortable.
Skipping the BitBoxApp for non-multisig use. For single-sig, BitBoxApp is well-designed and pairs cleanly with the device. Bypassing it for Sparrow or Electrum is fine but unnecessary for the simple case.
Three BitBoxes in multisig. Same vendor-diversity pitfall as with any other device. Pair BitBox with Coldcard, Trezor, or Foundation Passport.
Passphrase-heavy workflows on BitBox. The touch-button entry is slow for complex passphrases. If passphrases are central to the use case, Coldcard Q or Trezor Safe 5 is structurally better.
Buying via marketplace. Same supply-chain concern as with any hardware wallet. Direct from Shift.
Tooling and resources
BitBox documentation (as of 2026-05-14):
- shiftcrypto.ch — official site, in English/German/French
- BitBoxApp documentation — for single-sig workflows
- Shift Crypto blog — release notes, security advisories
- Jonas Schnelli’s writing — both BitBox-specific and broader Bitcoin Core context
Coordinator software supporting BitBox:
- BitBoxApp — official, single-sig and basic multisig
- Sparrow Wallet — multisig-friendly
- Specter Desktop — multisig-focused
- Nunchuk — desktop and mobile
- Bitcoin Core (with PSBT)
The synthesis document: Bitcoin Self-Custody & Security (LegacyCipher, April 2026) — BitBox treated as the multi-vendor-multisig friendly Swiss-engineered choice.
As of 2026-05-14: BitBox02 has been in production since 2019; firmware is actively updated. No successor product has been announced; the BitBox02 platform appears stable for the next several years.
Open questions for further development
- The microSD backup feature is a structural design choice that not all holders engage clearly. Should the framework recommend a specific stance (avoid it, use it carefully, or it’s a free choice)?
- BitBox’s Swiss positioning is genuine but the marketing emphasis sometimes overstates the security implications of “Swiss-made.” How much weight does Swiss jurisdiction actually carry against the realistic threat models? The synthesis treats it as modest but real.
- The BTC-only firmware variant is unique in the market (no other major vendor maintains a strictly-Bitcoin separate firmware build). Is this a marketing differentiator or a meaningful structural difference?
Related notes
The framing context:
- Hardware wallets overview — the framework
- Self-custody configuration ladder — BitBox fits across Configurations 1, 2, 4, 5
Per-device alternatives:
- Coldcard — the power-user complement; canonical multisig pairing
- Trezor — the SLIP-39 alternative; mainstream UX
- Foundation Passport — the strict-air-gap alternative
- Blockstream Jade — the budget alternative
- Bitkey
- Ledger considerations and tradeoffs
Relevant capabilities:
- BIP-85 child seeds
- PSBT and wallet descriptors
- Passphrases and the 25th word — passphrase entry UX is a BitBox limitation
- Seed phrases and BIP-39
Custody configurations:
- Multisig setups — BitBox as a vendor-diverse multisig component
- Collaborative custody services
Operational practice:
The principal practitioners:
- Jameson Lopp
- Pieter Wuille — Bitcoin Core context (Schnelli’s collaborator)
The sub-MOC home: