In this article
- What the device does, and what stays on the blockchain
- BitBox02 and Nova serve different device setups
- Published prices and the costs beyond the device
- How the security architecture is designed
- Backups require their own protection
- The 2026 security history matters
- Who the product fits, and where its protection ends
A hardware wallet separates the device that holds signing keys from the computer or phone used to prepare a transaction. BitBox applies that principle through a small physical device, an on-device display and companion software. The separation is useful, but it only works as intended when users verify transactions, protect backups and keep firmware current.
BitBox is the hardware wallet brand of Shift Crypto AG, a privately held Swiss company whose imprint identifies Douglas Bakkum as CEO and a board member. It sells physical self-custody products rather than holding customer cryptocurrency. The company says its devices keep private keys locally and that it does not provide custodial or investment services.
What the device does, and what stays on the blockchain
Cryptocurrency does not move inside the hardware wallet when someone receives a payment. The blockchain records the assets, while private keys provide the authority to spend them. A hardware wallet's job is to protect that authority and approve transactions without handing its keys to the connected computer.
That distinction explains both the appeal and the responsibility of self-custody. Losing a working device need not mean losing access if a usable backup survives. Losing both the device and the information needed to recover its wallet can leave the owner without a practical recovery route. The broader guide to cryptocurrency wallets and recovery explains how this differs from relying on an account provider.
BitBox combines the hardware with BitBoxApp, which provides the interface for accounts and transactions. Its security model assumes that the connected computer could be compromised. The intended verification point is therefore the wallet's own screen, not merely the address or amount shown by an app on a larger display.
BitBox02 and Nova serve different device setups
The product family currently includes BitBox02 and BitBox02 Nova. Both come in Multi and Bitcoin-only editions. The Bitcoin-only edition deliberately excludes other assets, reducing the amount of cryptocurrency-specific code it needs. The Multi edition supports several networks, including Bitcoin, Ethereum, Litecoin and Cardano, along with supported Ethereum tokens.
These are meaningful purchasing choices. Nova's product page says its two editions cannot be converted into each other later. A buyer who wants to manage Ethereum and its transaction system should therefore check the Multi edition and the exact asset support list before buying. Support for an asset name does not establish support for every network on which a similarly named token circulates.
Nova was introduced in June 2025. Its changes included iPhone and iPad support, a glass display and an updated secure chip. The original BitBox02 supports desktop systems and Android; Nova extends the platform range to Apple's mobile devices. The comparison page lists USB connectivity for both, with Bluetooth used for Nova's iPhone and iPad connection.
Nova's wireless communication uses the company's Whisper architecture. BitBox describes a separate Bluetooth chip and encrypted communication, with the option to disable Bluetooth. This is a connected hardware wallet, so users still depend on correctly implemented communication and signing software. A wireless option does not remove the need to read the physical display.
Published prices and the costs beyond the device
On October 9, 2026, the official shop's euro-priced listing showed BitBox02 Nova at €175 and BitBox02 at €149. Those are dated storefront prices, not fixed international quotes. Currency presentation, the selected product and delivery destination should be checked again before payment.
The Nova package lists a microSD card, USB adapters and an extension cable alongside the device. Optional backup products are separate purchases. On the same shop listing, a Steelwallet metal backup was €65 and a two-pack of additional microSD backup cards was €25. These accessories serve different purposes, so their presence in the store does not make them necessary for every setup.
The purchase price also does not cover every future blockchain transaction. Sending funds can incur the relevant network fee. Optional buying, selling or swapping services inside wallet software introduce separate terms and transaction costs that should be reviewed at the point of use. A hardware wallet protects signing keys; it does not make a quoted exchange rate competitive or waive network charges.
How the security architecture is designed
BitBox describes a dual-chip architecture: a microcontroller runs open-source firmware, while a separate secure chip helps harden access to the wallet. The original BitBox02 uses an ATECC608B; Nova uses an Optiga Trust M V3. Nova's secure chip carries an EAL6+ certification, which describes that component's evaluation rather than proving that every wallet workflow is immune to attack.
According to the security documentation, access to the encrypted wallet seed depends on secrets held by the device's chips and the user's password. Signed firmware, a device authenticity check and reproducible firmware builds provide additional verification mechanisms. Open code permits outside inspection, but does not establish that every flaw has already been found.
The practical boundary remains human confirmation. A wallet cannot infer that a payment recipient is honest or that the user intended a different destination. Reading the address, amount and signing request is part of operating the device. For Bitcoin transactions, understanding what is being spent and where it is going is as relevant as understanding the hardware.
Backups require their own protection
The microSD backup is a distinctive part of the BitBox setup. It reduces the need to transcribe recovery words during initial configuration, and the device also allows users to display recovery words for another backup format.
The crucial detail is that BitBox's setup guidance says microSD backups are unencrypted by default. The card should be treated as sensitive recovery material, not as an ordinary accessory. The company instructs users to store it securely and separately from the hardware wallet. Keeping both together exposes them to the same theft, fire or accidental loss.
A backup is also different from a customer-service reset. Support should never need a copy of recovery words to diagnose an ordinary problem. Photographing a backup, uploading it to cloud storage or entering it into a website can defeat the separation that the hardware was purchased to create.
The 2026 security history matters
BitBox's published record includes security fixes, not an absence of vulnerabilities. In January 2026, it disclosed two Nova issues involving secure-chip configuration and an advanced physical attack scenario, with password reuse across devices relevant to the potential impact. The company said the issues were fixed and that it had no reports of lost funds or evidence of exploitation.
Its August 2026 Dixence release disclosed further severe issues, including a memory problem affecting uninitialized Multi devices used with a malicious host, and a silent-payment flaw that could lock funds. The release also revisited a previously patched original BitBox02 bootloader issue that could enable malicious firmware installation following user deception. Nova was not affected by that particular bootloader issue. BitBox said firmware 9.26.5 resolved the issues described in the August notice and reported no known exploitation of them.
A separate incident involved newsletter provider Brevo on September 10, 2026. BitBox's September 24 disclosure said attackers downloaded subscriber email addresses and sent phishing messages. It said wallet hardware, BitBoxApp, internal systems and order information were not compromised. Brevo's own incident report said it blocked the attack route and reported no further attacker activity after containment.
Containment does not erase an exposed email list. Affected subscribers can still receive tailored phishing attempts. The distinction matters: a reported provider breach is not evidence that private keys were extracted, but it is relevant to users deciding which messages and download prompts to trust.
Who the product fits, and where its protection ends
BitBox is relevant to users who want control over their signing keys and are willing to maintain a recovery plan. Edition selection, supported networks, phone compatibility and the ability to operate the small display are concrete considerations. Those decisions are more useful than treating every hardware wallet as interchangeable.
BitBoxApp also offers optional features beyond ordinary hardware signing. Its current app page distinguishes a smartphone Lightning hot wallet from the on-chain hardware wallet. Moving funds into that hot wallet changes how those funds are protected, even though the feature appears in the same application. Users should not assume every balance displayed by a companion app has identical custody properties.
The durable benefit of this design is separation of key storage from everyday computing. Its limits remain substantial: malicious approvals, exposed backups, outdated firmware and unsuitable recovery arrangements can undermine that separation. BitBox's product documentation makes the mechanisms visible; its security disclosures show why those mechanisms still require maintenance.