Skip to content

BitBox02 Review: How the Dual-Chip Design Works and What It Will Not Protect

Life sovereignty editorial illustration for The Unhacked

You plug in the hardware wallet. The address on your laptop screen looks right: first four characters match, last four match. You confirm, the coins move, and three weeks later the block explorer shows a destination one character off from the one you meant. Nothing inside the wallet failed. You trusted the screen in front of you, and that screen belonged to a computer that was lying. That gap is the problem this BitBox02 review is about.

The short version: The BitBox02 is a Swiss-made hardware wallet from Shift Crypto AG. It splits security across two chips, runs open-source and reproducible firmware, and asks you to verify transactions on its own screen with touch confirmation (tap, slide and hold). It costs €149, and a newer model, the BitBox02 Nova, costs €175 and adds iPhone and iPad support. Verdict: a strong fit if you want verifiable firmware and a plain, well-documented risk signal model, and a poor fit if you need a wide altcoin list or a long-established app ecosystem. Prices and specs checked against bitbox.swiss and shop.bitbox.swiss on 30 September 2026.

Why hardware wallets fail: the interface-dependency trap

Most people buy a hardware wallet and consider the problem solved. It is only part of the system you are trusting.

Free checklist: Secure Your Accounts in 30 Minutes

Get the free "Secure Your Accounts in 30 Minutes" checklist by email. You will also get four short follow-up emails over about two weeks (passwords, two-factor, optional tools, a recap). One of them includes affiliate recommendations: if you buy through our links we may earn a commission at no extra cost to you. Unsubscribe in one click, any time.
By subscribing you agree to receive this checklist and a short email series from The Unhacked (Dr. AshR), including affiliate recommendations, at the address you enter. See our Privacy Policy.

The weak point is usually the bridge between the wallet and your internet-connected computer. If the computer is compromised, harmful software can change the recipient address before it reaches the wallet. You see the address you intended; the transaction goes somewhere else. The defence is not a bigger vault. It is a device that shows you what is actually being signed, on a screen the computer cannot touch.

The BitBox02 review reframe: assume the computer is hostile

BitBox states its risk signal model plainly: it assumes your computer can be compromised and should not be trusted. Every design choice follows from that one question: how do you make sure that what you approve is what gets signed?

  • Verification happens on the device. Transactions, receive addresses and other data are checked on the built-in screen, with touch confirmation.
  • Your password is entered on the device, not in the desktop app, so a keylogger on the computer never sees it.
  • The USB channel is encrypted using the Noise protocol, so harmful software sniffing the USB bus cannot read the traffic between the host and the device.

How the dual-chip design works

The BitBox02 has two chips with different jobs. A microcontroller runs the open-source firmware. A separate secure chip (an ATECC608B in the BitBox02, an Optiga Trust M V3 in the Nova) hardens access to the wallet.

The detail that matters is how the seed is protected. It is stored encrypted on the microcontroller, and decrypting it takes three secrets together: a random secret on the secure chip, a random secret on the microcontroller, and your device password, which is not on the device at all. A thief who steals the device still has to guess the password. The microcontroller limits password attempts to 10, and as a fallback a monotonic counter in the secure chip limits total attempts, while password stretching slows each guess. While the device is in use the seed is kept encrypted in RAM and decrypted only when needed, for example to sign.

Two physical measures back this up: the chips are covered with epoxy to make invasive incidents harder, and the casing halves are glued so that opening the device breaks pins, which makes tampering visible.

Touch confirmation and what you verify

The BitBox02 has no physical buttons. Input comes from capacitive touch sensors: you tap, slide and hold. The display is a 128 x 64 pixel OLED on the BitBox02 and a glass OLED on the Nova. The point of confirming on the device is that you read the details on a screen harmful software cannot rewrite, so the check does not depend on your computer telling the truth.

Open-source firmware you can verify

BitBox publishes the firmware, the BitBoxApp and the hardware schematics. The firmware builds are reproducible: anyone can compile the source and check that the binary matches the official release, and the community publishes signatures asserting the correctness of releases. The reproducible build is also tested regularly by WalletScrutiny, an independent project.

The bootloader accepts only firmware signed by Shift Crypto, prevents downgrades, and can display the firmware hash before running it. The firmware was audited by Census Labs alongside other third-party reviews, and Shift Crypto runs a bug bounty. An audit is evidence, not a guarantee; it tells you the code was looked at, not that it is free of flaws.

Each device also carries a factory attestation key, so the BitBoxApp can check that it is talking to a genuine BitBox.

Backup and recovery

The BitBox02 backs up the wallet seed to a microSD card, and you can verify the backup at any time. You can also display and write down the 24 recovery words after re-entering your password. BitBox notes that a microSD backup avoids the risk of writing down a word wrongly and of someone watching you write. For non-key documents you want off big-tech servers, an encrypted store such as pCloud is a separate tool for a separate job; never store your recovery words in any cloud.

Wallet generation mixes five entropy sources (the secure chip, the microcontroller, a per-device factory value, entropy from the app on your computer, and a hash of your password), and the combined result is at least as strong as the strongest source. You can instead generate your own seed, for example by rolling dice, and import it. If you plan to recover on another wallet, confirm that wallet’s compatibility before you rely on it.

BitBox02 vs BitBox02 Nova: which to buy

The two share the dual-chip design, open-source firmware and microSD backup. The differences, from the maker’s own comparison:

Feature BitBox02 BitBox02 Nova
Price (shop.bitbox.swiss) €149 €175
Secure chip ATECC608B Optiga Trust M V3 (certified secure chip)
Mobile support Android iPhone, iPad and Android
Display Standard OLED Glass OLED, more scratch resistant
Communication USB-C USB, plus Bluetooth for iPhone and iPad
Colours Black Black, White, Orange
Editions Multi, Bitcoin-only Multi, Bitcoin-only

Both editions ship in a Multi version and a Bitcoin-only version. The Multi edition supports Bitcoin, Litecoin, Cardano, Ethereum, Chainlink, BAT and 1,500+ ERC-20 tokens. The Bitcoin-only edition runs limited firmware that supports only Bitcoin; less code means less risk surface. The bootloader will not let you install the firmware for the other edition.

Decision rule: which one, and when

  1. Choose the Bitcoin-only edition if you hold only Bitcoin. It is the narrower firmware, with nothing you do not use.
  2. Choose the Multi edition if you also hold Ethereum, Litecoin, Cardano, Chainlink, BAT or ERC-20 tokens on the supported list.
  3. Choose the BitBox02 Nova if you manage the wallet from an iPhone or iPad, or want the glass display. Otherwise the BitBox02 at €149 covers the same security design.
  4. Look elsewhere if the coins you hold are not on BitBox’s list. We have not compared Ledger or Trezor models here, because both ranges have changed and their specs are not re-verified in this review.

Setup: the sovereign custody checklist

  • Buy direct. Buy from shop.bitbox.swiss or an authorised reseller, never secondhand. Check that the casing pins are intact, and let the BitBoxApp confirm the device is genuine.
  • Back up twice. Make a microSD backup, verify it, and write the 24 words down separately. Store them apart from the device, in a different location.
  • Test recovery before you fund it. Prove you can restore from the backup while the balance is still zero.
  • Keep firmware current. Update only through the official BitBoxApp, and check the firmware hash if you enable that option.
  • Read every prompt. Confirm the recipient, amount and fee on the device before you slide to confirm.

For deeper sovereignty, run your own Bitcoin node next to this setup. BitBox lets you connect the app to your own full node, and a self-hosted option such as Umbrel keeps your transaction history off third-party servers. If you use Ethereum applications, also audit your token approvals regularly; see our Revoke.cash review.

What the BitBox02 does not protect against

Every honest security review needs this section. The BitBox02 has real limits.

Physical coercion. If someone forces you to unlock the device or reveal your recovery words, the hardware cannot stop them. Physical security and separating your backups matter as much as any chip.

A lost or forgotten secret. Lose your device password with no backup, or lose every copy of your recovery words, and no design can recover the funds.

Anything outside the device. Exchange balances, hot wallets and smart-contract approvals sit outside its scope. A standing approval you signed to a contract can still be abused regardless of where your keys live.

Blind signing of intent. The device shows you addresses and amounts, not whether the destination is honest. If you approve a payment to a scammer’s correct address, the wallet did its job and you still lost the money.

Supply-chain and social incidents. BitBox says it never offers phone support and will never ask for your recovery words. Anyone who does ask is a scammer. Buying from an unofficial seller is the easiest way to receive a tampered device.

Platform limits. The original BitBox02 lists Android as its mobile platform; iPhone and iPad need the Nova. Coin support is a fixed list, not everything.

Frequently asked questions

Can the BitBox02 be used on multiple computers?

Yes. The device works with the BitBoxApp on Windows 10 and later, macOS 12 and later, and Linux, and with Android. Your keys stay on the device, so you can connect it to more than one machine.

What if I lose the microSD backup?

You can still restore from your written-down 24 recovery words. The microSD card is a convenience layer, which is why you should also keep the written copy, stored separately.

Is the BitBox02 safe from harmful software that records my screen?

The design assumes your computer may be compromised. Verification happens on the device’s own screen, and your password is entered on the device, so a keylogger on the computer does not capture it. The device cannot help if you approve a payment to an address that is wrong on purpose.

How do I know the device has not been tampered with?

The casing is bonded so that opening it breaks pins, and each device carries a factory attestation key that the BitBoxApp checks. Buy only from the official shop or authorised resellers.

What happens if Shift Crypto stops operating?

The firmware and app are open source, so the code stays available. For recovery, confirm the compatibility of your recovery words with another wallet before you depend on it.

You started reading because of a quiet fear: that the address on the screen and the address that gets paid might not be the same. The BitBox02 is built around exactly that fear, with the check on a screen the computer cannot rewrite and firmware you can verify instead of trust. It does not remove the need for backups, careful buying and your own judgement. Buy from Shift Crypto directly, and keep your recovery words offline.

Related reading: Proton Drive Review: The Logic of Encrypted Persistence and the Data Sovereignty Unhack.

More in Digital Sovereignty.

Where to get it: Hostinger — web hosting, VPS and domains. Affiliate link — The Unhacked may earn a small commission at no cost to you; our verdict isn’t for sale.

Where to get it: Onboard self-custody wallet. Affiliate link — The Unhacked may earn a small commission at no cost to you; our verdict isn’t for sale.

Dr. AshR · Founder & Editor, The Unhacked

Dr. AshR is the founder and editor of The Unhacked, an independent publication on digital sovereignty — privacy, self-custody, health, and money. The Unhacked publishes disclosure-first, independently-tested guidance and never lets a commercial link change a verdict. More about our methodology →

The Signal - free dispatch

One practical email that makes your digital life calmer. Checklists, tool cautions, plain-English decisions. No noise.

Free. No spam. Unsubscribe any time.

Affiliate disclosure. The Unhacked may earn a commission when you use some links on this page. Recommendations remain editorially independent.
📡

Join the Inner Circle

Weekly dispatches. No algorithms. No surveillance. Just sovereign intelligence.

Zero spam · Fully private · Sovereign by design.