Costs, licensing, consumer protection Privacy, self-custody, censorship resistance

BitBox BitBox02 Multi edition

A plan byBitBox

4.4/5 4.9/5
Custody Self-custody

Data verified on unchanged since the sources

Worth it if you hold mostly Bitcoin: at €149 the Bitcoin-only edition runs code restricted to Bitcoin, with a secure element and open-source firmware.

Avoid it if you want an air-gapped device or manage many chains: BitBox connects over USB-C and covers 4 chains, fewer than broader multi-asset wallets.

BitBox is the hardware wallet from the Swiss company Shift Crypto. The BitBox02 comes in two editions sharing the same hardware but running different firmware: the Multi edition supports Bitcoin, Ethereum, Litecoin, Cardano and 1,500+ ERC-20 tokens, while the Bitcoin-only edition runs code restricted to Bitcoin to reduce the attack surface. Since 2025 the line-up also includes the BitBox02 Nova (€175), with an EAL6+ certified secure chip, a glass display and "Whisper" Bluetooth Low Energy for use with iPhone/iPad. The device connects over USB-C and is managed through the desktop/mobile BitBoxApp, which also embeds buy, sell and swap via third-party providers. Firmware and app are open-source and developed in Switzerland.

BitBox02 Multi edition

Price
€149

What's included

  • Secure element
  • USB-C
  • microSD backup
  • Bitcoin, Ethereum, Litecoin, ERC-20
Self-custody
Custody
Open-source
Source code
4+
Chains
€149
Price
65
Transparency: Medium
65/100 · see methodology
65
Data exposure: Medium
65/100 · lower is better for sovereignty · methodology

Data & conditions

Fund custody Self-custody (funds in your control)
Type Hardware (cold storage)
Source code Open-source
Recovery Seed phrase 12/24 parole (BIP-39); backup su microSD inclusa
Bitcoin-only No
Supported chains Bitcoin, Ethereum, Litecoin, Cardano
Price €149
Secure element Yes
Air-gapped No
Connectivity USB-C, microSD
Companion app BitBoxApp
Built-in swap Yes
Built-in staking No
Segment B2C
MiCA / License status Nessuna (hardware wallet self-custody)

Strengths

  • Open-source firmware and app, developed in Switzerland; integrated secure element; Bitcoin-only edition with reduced attack surface; easy USB-C setup.
  • Self-custody: funds stay in your wallet — the platform cannot touch them.
  • No KYC: usable without identity verification.
  • Open-source, verifiable code.
  • Self-hostable: you can run your own instance or node.

Weaknesses

  • USB-C connection, not air-gapped; narrower chain support than broader multi-asset wallets; smaller ecosystem than Ledger/Trezor.
  • No notable sovereignty drawback documented.

Verdict

A S ★ 4.4/5 ★ 4.9/5

Score 4.4/5, very strong profile. In its favour: open-source firmware and app, developed in Switzerland; integrated secure element; Bitcoin-only edition with reduced attack surface; easy USB-C setup. The trade-off to weigh: uSB-C connection, not air-gapped; narrower chain support than broader multi-asset wallets; smaller ecosystem than Ledger/Trezor.

On the Sovereignty lens the score is 4.9/5 (outstanding): the strength is fund control (5.0/5), while privacy & anonymity (4.7/5) is the weak link.

Privacy & anonymity 30% 4.7
Fund control 20% 5.0
Censorship resistance 20% 4.8
Trustless / auditability 20% 5.0

Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.

"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.

Reputation

What happened to people who used BitBox, and what users say. External signals: they do not feed the promp.it rating.

Incidents & regulatory actions

Notable incidents

Documented events with consequences still open. Each entry carries a source and a date.

  1. Data breach Severe ● open

    Newsletter provider compromised: phishing delivered to BitBox subscribers through the official channel; on 10 September Brevo identified itself as the breached platform and closed the SAML SSO flaw, and on 11 September a BitBox spokesperson named Brevo to a news outlet, stating the email reached its entire newsletter and tutorial list — yet BitBox has still published nothing on its own channels and no subscriber count

    On the evening of 9 September 2026 BitBox warned on its official X account that «there is currently a phishing email going around that's pretending to come from us», urging people not to follow its instructions. At 23:03 CEST the company published its preliminary findings: the email had been «sent out to our newsletter subscribers» and it is «very likely that our newsletter provider got compromised»; moreover «multiple other Bitcoin companies got targeted as well, and it appears that we all share the same newsletter provider». BitBox said it had sent a phishing warning to all subscribers, contacted the provider and reported the fraudulent domains, «most of» which «appear to have been taken down already», and that it was still investigating. What matters for the user is that the message arrived along the legitimate channel, to the real subscriber list: checking the sender is not enough to tell it apart. According to Cointelegraph and Cyber Daily the fraudulent message raised the alarm about an alleged flaw in the device's random-number generation, the same scheme used the same day against Trezor customers, who attributed their campaign to the breach of a third-party email provider (see the Trezor entry). As of our verification date no source has confirmed any theft of funds or recovery phrases, and neither company has disclosed the provider's name, the number of subscribers reached or the date the compromise began. A note on method: third-party phishing against a service's users does not belong in this register; this entry exists because the compromise concerns a supplier in BitBox's own communication chain, as stated by the company itself. UPDATE OF 10 SEPTEMBER 2026, 14:00 CEST: the shared provider BitBox referred to now has a name, though it was given by another affected company. At 23:32 CEST on 9 September CoinTracking — a crypto tax-reporting service, not listed in this register — stated on its official X account that «our third-party email service provider Brevo has experienced a security breach», with a third lure tailored to its own service: an email titled «Data Breach Notice: Please refresh API Keys as soon as possible». BitBox and Trezor still do not name the provider, and at 12:00 UTC on 10 September Brevo's status page reads «fully operational», with no security notice. On the headers of the email received by Trezor customers, Decrypt and Cryptopolitan report — on the basis of recipients' screenshots, not of a company confirmation — the Sendinblue campaign path (Sendinblue is Brevo's former name) and a DKIM, SPF and DMARC pass: the technical explanation of what BitBox had already said in plain words, namely that the message arrives along the legitimate channel. BitBox's expectation about the «multiple other Bitcoin companies» hit therefore gains a third public confirmation. There is still no confirmation of stolen funds or recovery phrases; at 14:00 CEST on 10 September BitBox's latest public statement remains the one from 23:03 on 9 September, and no closing report has been published. UPDATE OF 12 SEPTEMBER 2026, 08:00 CEST — THE PROVIDER HAS ADMITTED IT, BUT IT WAS NOT BITBOX THAT SAID SO. What is written above as of 10 September needs correcting on one point: it is no longer true that the name circulates only through CoinTracking, and no longer true that «Brevo's status page shows fully operational with no security notice». On 10 September Brevo published a post-incident write-up on its own status page titled «Attacker gained access to client accounts»: at 06:30 UTC it identified «a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts». The mechanism, in Brevo's words: the attacker created a Brevo account, enabled single sign-on on it and invited legitimate Brevo users into that configuration, then signed in through their own identity provider acting as those users; the access was not properly scoped and, instead of being limited to the single organization where SSO was enabled, it «wrongly granted the attacker access to all organizations those users could reach». OFFICIAL BREAKDOWN OF THE 138 ACCOUNTS: 6 used to send phishing to the contacts stored in them, 43 with contacts exported, 93 with no meaningful activity. Brevo states it closed the vector at 08:30 UTC on 10 September, two hours after detection, signed out all platform users, deployed permanent fixes limiting SSO access to the owning organization, and disabled the links in the fraudulent emails. This is confirmation, from the source that counts, of what BitBox had inferred on 9 September when it spoke of a provider shared among several bitcoin companies. WHAT THIS ESTABLISHES FOR BITBOX AND WHAT IT DOES NOT: that BitBox subscribers received the phishing through the legitimate channel was stated by BitBox itself; which of Brevo's three buckets its account falls into — among the 6 used to send, among the 43 with contacts exported, or both — is stated by neither company, and we do not infer it. BitBox still has not published the number of subscribers reached and, as of 12 September, has neither publicly named the provider nor published a final report: its last statement on the case remains the one of 9 September. THE POINT OF COMPARISON, USEFUL BECAUSE IT MEASURES THE MISSING INFORMATION: Trezor, hit in the same wave through the same provider, published a notice on its blog on 10 September naming Brevo and quantifying the exposure — roughly 347,000 newsletter addresses, 2,500 clicks, domain taken down within 20 minutes (entry on the Trezor card). For BitBox, the equivalent of those figures does not exist as of today. WHY WE REMOVED THE «ONGOING» FLAG: the campaign is no longer in progress — the vector is closed on the platform operator's own statement, the phishing domains have been taken down, the sending has stopped. The entry remains unresolved because BitBox's own scope and a final report are missing, and because any exported addresses remain in circulation. As of 12 September no source, including BleepingComputer, SecurityWeek, Malwarebytes and The Record, has confirmed any theft of funds or recovery phrases traceable to this campaign. UPDATE OF 12 SEPTEMBER 2026, 13:30 CEST — BITBOX HAS SPOKEN, BUT TO A NEWSPAPER. What is written above as of 08:00 needs correcting on one point, and the correction is in BitBox's favour: it is no longer true that «its last statement on the case remains the one of 9 September», nor that as of 12 September it had not publicly named the provider. On 11 September Cointelegraph published statements from a BitBox spokesperson — the first time the company has described its own scope. WHAT BITBOX STATES, through the spokesperson: the unauthorised email was sent «through Brevo» — so the provider is now named by the company itself, no longer only by CoinTracking — and «appeared to have reached its full newsletter and tutorial list»; Brevo held «only email addresses and language preferences»; BitBox further states it found no evidence of compromised company credentials, downloaded contacts, lost funds or disclosed recovery phrases, and that it is treating the list as potentially accessed while awaiting Brevo's logs. HOW STRONG THIS SOURCE IS, STATED PLAINLY: these are the company's words, but gathered and reported by a single outlet, not published by BitBox on its own channels. At 13:00 CEST on 12 September the official blog (blog.bitbox.swiss) carries no article on the episode, and on its X account the latest statement on the matter remains the one of 9 September — this morning the account posted only an announcement of its presence at a trade fair. We therefore report the statement with its attribution in plain sight, not as an official communication. WHAT REMAINS OPEN: the number of subscribers reached still does not exist, because «the full list» is a scope and not a figure; and which of Brevo's three buckets the BitBox account falls into — among the 6 used to send, among the 43 with contacts exported, or both — is stated by neither company. There is, however, one substantial change since this morning: BitBox now says it has no evidence of downloaded contacts. That is not the same as ruling it out — the company itself is waiting for the provider's logs to know — but it is more than it had said so far. The point of comparison is unchanged: Trezor published a notice on its own blog with verifiable figures; BitBox answered a journalist.

    ↗ source

verified on

Public reviews

4.8/5 2,430 reviews
  • Trustpilot ↗ 4.9/5 2,130 reviews

    Trustpilot profile for bitbox.swiss (read via the DE domain; the .com returned 403).

  • Google Play ↗ 4.3/5 ~ 300 reviews

    BitBoxApp (ch.shiftcrypto.bitboxapp), developer Shift Crypto. ~300 count from aggregators (AppBrain/storespy): NOT confirmed on the Play page (truncated content), hence approximate.

  • App Store ↗ 4.5/5 6 reviews sample too small for the average

    BitBoxApp by Shift Crypto AG on the App Store (id 6670479223); tiny sample (6 ratings), low significance.

Weighted average across 2 public review platforms (2,430 reviews in total), weighted by volume. This is not our rating: it is those platforms’ average.

FAQ

How much does a BitBox02 cost?

Both BitBox02 editions (Multi and Bitcoin-only) cost €149 on Shift Crypto's official shop; the BitBox02 Nova, with an EAL6+ secure chip and Bluetooth for iPhone/iPad, costs €175.

What's the difference between BitBox02 Multi and Bitcoin-only?

The hardware is identical; the firmware differs. The Multi edition supports Bitcoin, Ethereum, Litecoin, Cardano and 1,500+ ERC-20 tokens (plus FIDO U2F); the Bitcoin-only edition runs code restricted to Bitcoin, reducing the attack surface.

Is BitBox open source?

Yes: the firmware and the BitBoxApp are open-source and public. The device also pairs a secure element for key protection.

Sources

Update history

✓ Terms unchanged since Jul 20, 2026

🔔 Notify me of changes

← All BitBox plans