# BitBox

> Source: https://timechain.wiki/wiki/bitbox · TimechainWiki, the Bitcoin encyclopedia. (note · self-custody)

> BitBox, made by Shift Crypto (Zurich), is the Bitcoin-only hardware wallet most associated with Swiss-engineered minimalism, fully open-source firmware, and clean multi-vendor multisig pairing. The current product as of 2026 is the **BitBox02 BTC-only edition** ($137), USB-C with a dual-chip architecture (general-purpose microcontroller + Microchip ATECC608B secure element). A "multi" edition supporting altcoins exists at the same price, but the BTC-only variant is the principled choice for Bitcoin holders. Distinguishing features include a minimal-friction setup flow (with optional dice-entropy contribution), excellent multisig support pairing cleanly with Coldcard or Trezor in vendor-diverse 2-of-3 configurations, and the strongest open-source posture among devices with a dedicated secure element. Trade-offs: USB-only (no air-gap workflows), no native SLIP-39 (BIP-39 only), and a smaller community than Trezor or Coldcard. BitBox02 BTC-only serves as the canonical multi-vendor-multisig component — often the right second or third device alongside a Coldcard or Trezor.

---

## What this is

**Vendor**: Shift Crypto (Zurich, Switzerland). Founded by Douglas Bakkum and Jonas Schnelli (2014–2015 timeframe). Schnelli is a prominent Bitcoin Core contributor. The Swiss base and the deep Bitcoin Core developer involvement give BitBox a distinctive technical credibility.

**Product line as of 2026-07-15**:

- **BitBox02 BTC-only edition** ($137) — Bitcoin-only firmware; no altcoin support. The principled choice for Bitcoin holders.
- **BitBox02 multi edition** ($137) — same hardware, firmware supports Bitcoin plus several altcoins (Ethereum, Litecoin, Cardano historically). Same price as the BTC-only variant.

Shift has explicitly maintained the BTC-only variant as a separate product, signaling that the company takes the Bitcoin-only argument seriously rather than treating altcoin support as universally desirable. This is unusual in the hardware-wallet market and is part of BitBox's distinctive positioning.

**Firmware**: Fully open-source under Apache 2.0 (OSI-approved). The BTC-only firmware is a stripped-down version of the multi firmware; the build process is reproducible by independent reviewers.

**Hardware**: Designed in Switzerland, assembled in Switzerland and shipped from Switzerland. The supply-chain transparency is among the strongest in the industry — Shift publishes details of the components and assembly process.

**Secure element**: Microchip ATECC608B. EAL-certified; physical-attack resistance comparable to Coldcard's secure element. The dual-chip architecture (general MCU + secure element) is the standard pattern for modern hardware wallets.

---

## Who this is for

BitBox02 BTC-only is a strong fit for:

- **Multi-vendor multisig** — BitBox pairs cleanly with Coldcard, Trezor, or Foundation Passport. The minimal-friction UX makes it a natural choice for the "second device" in a vendor-diverse 2-of-3.
- **Open-source-aligned holders** — Apache 2.0 firmware; reproducible builds; Swiss supply-chain transparency
- **Bitcoin-only purists** — the BTC-only firmware genuinely removes altcoin code paths from the device
- **Holders who want simplicity without sacrificing capability** — the UX is more approachable than Coldcard, less mainstream-consumer than Trezor; a Goldilocks position
- **Holders concerned about supply-chain integrity** — Swiss assembly, transparent component documentation, clear vendor-buy direct channels

BitBox02 is **less appropriate** for:

- **Strict air-gap holders** — USB-only; no QR or MicroSD signing paths. Holders who want strict air-gap should use Foundation Passport or Coldcard.
- **SLIP-39 users** — BIP-39 only; no SLIP-39 support. SLIP-39 users should use Trezor.
- **BIP-85 power users** — supported but not as deeply as Coldcard
- **The mainstream-UX-seeking first-time user** — Trezor's touchscreen is friendlier; the BitBox02's touch-button input is functional but less intuitive

---

## Features and capabilities

### BitBox02 specifics

- **Touch-sensitive buttons** — the device uses capacitive touch zones rather than physical buttons; smooth UX once learned
- **OLED display** — clear, legible, 128×64 monochrome
- **USB-C** — modern connector
- **Dual-chip architecture** — general MCU + ATECC608B secure element
- **Microsoft Authenticator-style backup option** — BitBox can back up the seed to a microSD card (encrypted), enabling rapid restore. This is a feature some holders use and some explicitly avoid; the encrypted microSD backup is convenient but introduces a digital copy of the seed.
- **PIN entry on the device** — via touch buttons; not as fast as a touchscreen but adequate

### Common to BitBoxApp ecosystem

- **BitBoxApp companion software** — for Bitcoin-only holders, the BTC-only app is similarly stripped-down; pairs with the BTC-only device
- **PSBT v2 support** — modern PSBT handling
- **BIP-380 output descriptors** — for multisig
- **BIP-39 passphrase support** — entered via touch buttons; tedious for complex passphrases (the Coldcard Q's QWERTY is meaningfully better here)
- **Native multisig** — supports 2-of-3, 3-of-5, and other configurations; coordinator-agnostic

### BitBox-specific quirks

- **The microSD backup option** — controversial. Convenient (rapid restore from a microSD card) but introduces a digital copy of the seed. Holders should treat the microSD as seed-sensitive; many holders disable this feature.
- **Touch-sensitive button input** — different from Coldcard's keypad and Trezor's touchscreen. Some holders find it elegant; others find passphrase entry slow.
- **The "BIP-39 mnemonic display" verification** — BitBox displays the seed on the OLED for the holder to record; verification via on-device flow.

---

## Tradeoffs vs alternatives

| Dimension | BitBox02 BTC-only | Coldcard Q | Coldcard Mk4 | Trezor Safe 5 | Foundation Passport |
|---|---|---|---|---|---|
| Price | $137 | $249 | $150 | $129 | $199 |
| Bitcoin-only | Yes | Yes | Yes | No | Yes |
| Open-source | Yes (OSI Apache 2.0) | Source-available | Source-available | Yes (GPL) | Yes (OSI) |
| Secure element | Yes (ATECC608B) | Yes | Yes | Yes (EAL 6+) | Yes |
| Air-gap signing | No (USB only) | QR + MicroSD | MicroSD only | No (USB only) | QR only |
| Native SLIP-39 | No | No | No | Yes | No |
| BIP-85 | Good | Excellent | Excellent | Good | Limited |
| Passphrase entry | Good (touch buttons) | Best (QWERTY) | Tedious | Excellent (touchscreen) | Good (touchscreen) |
| Multisig pairing | Excellent (the canonical second device) | Excellent | Excellent | Excellent | Excellent |
| Supply-chain transparency | Highest (Swiss) | High | High | High | High |
| Lopp 100-input signing | Fast | Fast | Fast | Moderate | Fast |

The principal alternatives to BitBox in similar use cases:

- **Coldcard** — more features (BIP-85, air-gap); pricier; less mainstream UX. BitBox + Coldcard is the canonical multi-vendor multisig pairing.
- **Trezor** — SLIP-39 + touchscreen; multi-coin firmware (which BitBox-BTC-only deliberately avoids); broader community but less focused.
- **Foundation Passport** — strict air-gap (which BitBox isn't); pricier; Bitcoin-only like BitBox.

For most multi-vendor multisig configurations, BitBox + one other device (Coldcard or Trezor) is a strong baseline.

---

## Setup and operation

The setup flow:

1. **Verify packaging** — BitBox ships with tamper-evident seals
2. **Install BitBoxApp** — desktop app for first-time setup
3. **Connect via USB** — the device walks through setup
4. **Choose backup method** — microSD encrypted backup, paper-only, or both. Many holders choose paper-only to avoid the microSD digital copy.
5. **Generate seed** — BitBox displays 24 words on the OLED; the holder records them
6. **Verify the seed** — on-device check
7. **Optionally set up a passphrase** — entered via touch buttons
8. **Pair with a coordinator** — BitBoxApp for single-sig; Sparrow, Specter, Nunchuk for multisig

The signing flow:

- Coordinator builds PSBT
- Transfer to BitBox via USB
- BitBox displays transaction details on OLED; holder verifies addresses on the screen
- Holder confirms via touch
- BitBox signs, returns to coordinator
- For multisig, repeat with other devices

The simplicity of the USB-only workflow is part of BitBox's appeal — fewer transfer steps than air-gap devices, while preserving the keys-never-leave-device guarantee.

---

## Security considerations

### Strengths

- **Fully open-source firmware** (Apache 2.0, OSI-approved); reproducible builds
- **Swiss-based supply chain** with transparent component documentation
- **Bitcoin Core developer involvement** — Jonas Schnelli's reputation gives BitBox credibility
- **EAL-certified secure element** — physical-attack resistance
- **Bitcoin-only firmware option** — removes altcoin code paths
- **Reproducible firmware builds** — third parties can verify shipped firmware matches published source

### Known concerns

- **The microSD encrypted backup feature** — introduces a digital copy of the seed. Many holders disable this; some use it. The pattern is BitBox-specific and worth understanding before adopting.
- **USB-only signing** — no air-gap workflow; holders who want strict air-gap should use Passport or Coldcard.
- **Touch-button passphrase entry is slow** — for complex passphrases, the entry friction is notable. Pair BitBox with a different device if passphrases are a heavy part of the workflow.
- **Smaller community** — fewer third-party tutorials, fewer YouTube walk-throughs compared to Trezor or Coldcard. Official documentation is strong but the broader ecosystem is thinner.

### Supply-chain integrity

Buy directly from shiftcrypto.ch. Swiss assembly is the canonical claim; verify tamper-evident packaging on arrival.

The 2020 Ledger leak does not affect BitBox; Shift Crypto's customer database has not had a public leak. The Swiss jurisdiction provides additional regulatory protections for customer data.

---

## Pricing and acquisition

_As of 2026-07-15 (prices reverified; prior review 2026-05-14)_:

- **BitBox02 BTC-only**: $137 USD (typically CHF/EUR equivalent)
- **BitBox02 multi edition**: $137 USD (same price; different firmware)

**Authorized channels**: shiftcrypto.ch directly; some authorized resellers. Avoid generic marketplaces.

**Bulk and business pricing**: available for multisig configurations.

---

## Common pitfalls

**Buying the "multi" edition when you want Bitcoin-only.** The BTC-only firmware is a meaningful structural choice. The multi edition is fine for some holders but the principled position is BTC-only.

**Enabling microSD backup without understanding it.** The encrypted microSD copy is a digital seed copy. Holders should make a deliberate decision about this feature rather than defaulting to it.

**Treating BitBox as a standalone solution when a Coldcard or Passport would also fit.** BitBox is strongest as one of two or three devices in a multi-vendor multisig. Holders running single-sig may find Trezor's mainstream UX more comfortable.

**Skipping the BitBoxApp for non-multisig use.** For single-sig, BitBoxApp is well-designed and pairs cleanly with the device. Bypassing it for Sparrow or Electrum is fine but unnecessary for the simple case.

**Three BitBoxes in multisig.** Same vendor-diversity pitfall as with any other device. Pair BitBox with Coldcard, Trezor, or Foundation Passport.

**Passphrase-heavy workflows on BitBox.** The touch-button entry is slow for complex passphrases. If passphrases are central to the use case, Coldcard Q or Trezor Safe 5 is structurally better.

**Buying via marketplace.** Same supply-chain concern as with any hardware wallet. Direct from Shift.

---

## Tooling and resources

**BitBox documentation** _(as of 2026-05-14)_:

- shiftcrypto.ch — official site, in English/German/French
- BitBoxApp documentation — for single-sig workflows
- Shift Crypto blog — release notes, security advisories
- Jonas Schnelli's writing — both BitBox-specific and broader Bitcoin Core context

**Coordinator software supporting BitBox**:

- BitBoxApp — official, single-sig and basic multisig
- Sparrow Wallet — multisig-friendly
- Specter Desktop — multisig-focused
- Nunchuk — desktop and mobile
- Bitcoin Core (with PSBT)

**The synthesis document**: *Bitcoin Self-Custody & Security* (LegacyCipher, April 2026) — BitBox treated as the multi-vendor-multisig friendly Swiss-engineered choice.

_As of 2026-05-14_: BitBox02 has been in production since 2019; firmware is actively updated. No successor product has been announced; the BitBox02 platform appears stable for the next several years.

---

## Open questions for further development

- The microSD backup feature is a structural design choice that not all holders engage clearly. Should the framework recommend a specific stance (avoid it, use it carefully, or it's a free choice)?
- BitBox's Swiss positioning is genuine but the marketing emphasis sometimes overstates the security implications of "Swiss-made." How much weight does Swiss jurisdiction actually carry against the realistic threat models? The synthesis treats it as modest but real.
- The BTC-only firmware variant is unique in the market (no other major vendor maintains a strictly-Bitcoin separate firmware build). Is this a marketing differentiator or a meaningful structural difference?

---

## Related notes

**The framing context**:

- [Hardware wallets overview](https://timechain.wiki/wiki/hardware-wallets-overview.md) — the framework
- [Self-custody configuration ladder](https://timechain.wiki/wiki/self-custody-configuration-ladder.md) — BitBox fits across Configurations 1, 2, 4, 5

**Per-device alternatives**:

- [Coldcard](https://timechain.wiki/wiki/coldcard.md) — the power-user complement; canonical multisig pairing
- [Trezor](https://timechain.wiki/wiki/trezor.md) — the SLIP-39 alternative; mainstream UX
- [Foundation Passport](https://timechain.wiki/wiki/foundation-passport.md) — the strict-air-gap alternative
- [Blockstream Jade](https://timechain.wiki/wiki/blockstream-jade.md) — the budget alternative
- [Bitkey](https://timechain.wiki/wiki/bitkey.md)
- [Ledger considerations and tradeoffs](https://timechain.wiki/wiki/ledger-considerations-and-tradeoffs.md)

**Relevant capabilities**:

- [BIP-85 child seeds](https://timechain.wiki/wiki/bip-85-child-seeds.md)
- [PSBT and wallet descriptors](https://timechain.wiki/wiki/psbt-and-wallet-descriptors.md)
- [Passphrases and the 25th word](https://timechain.wiki/wiki/passphrases-and-the-25th-word.md) — passphrase entry UX is a BitBox limitation
- [Seed phrases and BIP-39](https://timechain.wiki/wiki/seed-phrases-and-bip-39.md)

**Custody configurations**:

- [Multisig setups](https://timechain.wiki/wiki/multisig-setups.md) — BitBox as a vendor-diverse multisig component
- [Collaborative custody services](https://timechain.wiki/wiki/collaborative-custody-services.md)

**Operational practice**:

- [Backup strategies for seeds](https://timechain.wiki/wiki/backup-strategies-for-seeds.md)
- [Recovery rehearsal practice](https://timechain.wiki/wiki/recovery-rehearsal-practice.md)
- [Common attack vectors](https://timechain.wiki/wiki/common-attack-vectors.md)

**The principal practitioners**:

- [Jameson Lopp](https://timechain.wiki/wiki/jameson-lopp.md)
- [Pieter Wuille](https://timechain.wiki/wiki/pieter-wuille.md) — Bitcoin Core context (Schnelli's collaborator)

**The sub-MOC home**:

- [Practical self-custody and sovereignty](https://timechain.wiki/wiki/practical-self-custody-and-sovereignty.md)
