BitBox02 (Multi and Bitcoin-only editions): what the sources say
Current 2 disclosed weaknesses 1 company incident
The questions, with sources
"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.
Five facts
- Shift Crypto AG (Switzerland) sells the BitBox02 in two editions with identical hardware, Multi and Bitcoin-only, which cannot be converted into each other [source 3].
- It uses a dual-chip design with an ATECC608B secure chip and Apache-2.0 open-source firmware with a documented verification procedure [source 4].
- A fix published on 2026-08-17 (firmware 9.26.5) addressed three firmware issues; BitBox reports no known stolen funds [source 10].
- On 2026-09-10 BitBox's newsletter provider account was breached and subscriber emails were exposed; BitBox says its internal systems and devices were not compromised [source 12].
- Works with desktop and Android over USB; iPhone/iPad need the newer BitBox02 Nova [source 1].
Audits
- date n/v Census Labs (plus unnamed third-party firms as consultants). Scope: BitBox02 firmware source
Publicly disclosed weaknesses
- 2026-08 BitBox 'Dixence' update (firmware 9.26.5, published 2026-08-17) fixes three issues: (1) bootloader issue allowing malicious firmware to be installed on a genuine BitBox02 after phishing the user into unlocking it (fixed earlier in 9.26.2, reported externally by SySS GmbH after internal discovery; BitBox02 through 9.26.1; Nova not affected); (2) memory corruption in the Multi edition before a wallet is set up with a malicious host (found internally; Multi through 9.26.4; Bitcoin-only not affected); (3) silent-payment flaw that could lock funds to an unintended address (found internally; 9.21.0 to 9.26.4). Seed not affected per BitBox. Funds lost: no. Fixed source
- 2019-11 CVE-2019-18673 (older than 5 years): power-consumption side channel in the row-based OLED display; an attacker who controls the USB connection (e.g. implant in the cable) could partly infer displayed secrets such as PIN or mnemonic while shown. CVSS 4.6 (Medium). The CVE page read does not describe a fix. Funds lost: not verified. Fix status not verified source
Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.
Incidents at the maker or its service providers
- 2026-09-10 Attackers exploited a flaw at Brevo, BitBox's newsletter provider, accessed BitBox's Brevo account, sent two phishing campaigns to subscribers (one claiming a 'Microcontroller Entropy' flaw and asking for recovery words) and downloaded the contact list. BitBox says only subscribed email addresses were exposed (no names, addresses, payment or order data) and that BitBox internal systems, BitBoxApp and hardware wallets were not compromised. Customer funds lost: not verified. Outcome: Malwarebytes (2026-09-11) reports no confirmed losses and that the number of recipients who fell for the emails is unknown; BitBox advises deleting/reporting the email and that recovery words are only entered on the device. source
These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.
Questions about BitBox02 (Multi and Bitcoin-only editions)
Is BitBox02 (Multi and Bitcoin-only editions) safe?
We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 2 publicly disclosed weaknesses and 1 company incident in our search. Read the sources above before you buy.
Does BitBox02 (Multi and Bitcoin-only editions) need an internet connection?
Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB. The companion app or software that builds the transaction is online.
Who found the weaknesses listed for BitBox02 (Multi and Bitcoin-only editions)?
The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.
Where this comes from
- [1] BitBox02 Multi - BitBox shop accessed 2026-10-11
- [2] BitBox02 Bitcoin-only - BitBox shop accessed 2026-10-11
- [3] BitBox02 edition comparison - BitBox support accessed 2026-10-11
- [4] BitBox02 security features - bitbox.swiss accessed 2026-10-11
- [5] BitBox home page (BitBox02 vs BitBox02 Nova, Shift Crypto AG) accessed 2026-10-11
- [6] BitBox02 Bitcoin-only page accessed 2026-10-11
- [7] BitBox02 optional passphrase - support accessed 2026-10-11
- [8] bitbox02-firmware repository (GitHub) accessed 2026-10-11
- [9] How to independently verify the BitBox02 firmware - BitBox blog accessed 2026-10-11
- [10] BitBox 08.2026 Dixence update - BitBox blog accessed 2026-10-11
- [11] CVE-2019-18673 - CVEfeed (NVD data) accessed 2026-10-11
- [12] Known BitBox phishing scams / Brevo disclosure - BitBox support accessed 2026-10-11
- [13] Crypto customers targeted by scammers after email marketing provider breach - Malwarebytes accessed 2026-10-11
- [14] Bitcoin Wallet Maker BitBox Says AI Found Severe Flaws in Firmware - Decrypt accessed 2026-10-11
- [15] BitBox breach listing (2025) - DataBreach.com accessed 2026-10-11
Not verified: List price in EUR/USD not verified (official shop pages as retrieved showed no device price). Secure-chip certification, Shamir/SLIP39, recovery service, Bitcoin-only FIDO support, audit date and full audit report not verified. A DataBreach.com listing (source 15) claims a July 2025 intrusion exposing customer records (attributed to a threat group by trackers); no BitBox statement or major news confirmation was found, so it is not recorded as an incident. 2-year warranty and Nova comparison come from the maker's pages.
See how we check. To report an error, use corrections and right of reply.