Can you still trust hardware wallets?
Our co-founder Douglas answered it properly: entropy sources, dice rolls, firmware updates, and the design decisions behind USB and Bluetooth.
Watch it here 👇
BitBox
support@bitbox.swiss
npub1tg77...cxmt
Swiss-made 🇨🇭 Bitcoin hardware wallet for beginners and pros
Hi.
Every hardware wallet we sell can run the current firmware.
Bye.


We just released the Dixence security update.
During our internal audits, we were able to discover and fix multiple security issues in the BitBox firmware.
We recommend our users to update their BitBoxApp and device firmware through the BitBoxApp settings.


BitBox Blog
BitBox 08.2026 Dixence update
This update includes important security improvements for the BitBox firmware as well as smaller bug fixes.
As a hardware wallet user, one of the best ways to stay secure is to keep your wallet firmware up to date.
With AI models only getting better at finding and fixing bugs, expect regular updates for your hardware wallets in the near future.


BitBox Blog
Firmware updates in the age of AI: Staying up to date matters more than ever
AI helps researchers find bugs faster than ever – which means the fix is only ever one update away. Here's why updating regularly is the easiest ...
If you own a hardware wallet, you probably spent the last few days wondering what you're actually able to check for yourself.
Short answer: more than you'd think.
Here are the questions worth asking any manufacturer (us included):
- Where does the randomness come from?
Every wallet begins as one large random number. If that number is predictable, nothing built on top of it holds.
Ask how many independent sources of entropy the device combines and what happens if one of them turns out to be weak.
- Can I check that the firmware on my device matches the published code?
Reproducible builds let you verify the binary you're running was built from the source you can read.
Worth being precise: that proves the binary matches the source. It does not prove the source is correct.
- Who approves a change before it reaches my device?
Ask whether one person can ship firmware alone, or whether every change needs a second set of eyes.
This is unglamorous and it is where most of the real security lives.
- What happens when they find a bug?
Every manufacturer ships bugs. The question is what the process looks like afterwards.
Ask about the bug bounty. Ask how quickly users were told the last time something was found.
OUR ANSWERS
- The BitBox generates your wallet from five independent sources of entropy: Physical noise from the secure chip, physical noise from the MCU, randomness provided by the host device, a static random number set in the factory and your own device password.
The benefit of mixing entropy: Redundancy. All but one source can be compromised and your seed would still be secure.
- The BitBox firmware supports reproducible builds you can independently verify yourself (link in the comments)
That way you know the firmware you install matches the public source code.
However, it is generally very difficult to verify what code is actually executed on-device.
- All change requests to the BitBox firmware require an approved review by a maintainer to be merged.
- The BitBoxApp and BitBox firmware are fully open-source and part of our bug bounty program (link in the comments )
Bug reports are financially rewarded depending on their severity, encouraging security researchers to actually take a thorough look.
- We announce security updates publically on our channels, including detailed information on the vulnerability and how it might have affected users.
Wallets created on a BitBox are not affected by the Coldcard RNG vulnerability. A BitBox seed combines five independent entropy sources. One weak source does not compromise the result.
More here:


BitBox Blog
BitBox is not affected by the Coldcard RNG vulnerability
Addressing questions BitBox users might have in light of the recent Coldcard security advisory.
BitBox is not affected by the recent RNG vulnerability that affected one of our competitors.
More details coming soon.
Stay hydrated


Going somewhere? 🏝️
With the BitBox02 Nova you manage your savings straight from your phone, even on vacation;)


Sale season has begun


You can't control the market. You can own your keys.


The BitBox02 does something that other wallets don’t: it backs itself up. To a microSD card. In 60 seconds. 👀


Price, wars, markets: not your call.
Private keys, your stack, when you sell: all yours.
That's Bitcoin.


The 20 millionth bitcoin just got mined. 95% of all the bitcoin that will ever exist is now in circulation. The last 1 million will take until 2140.
Self-custody, so you make sure the ones you have are actually yours.


The hardest part of self-custody is the setup anxiety.
That’s why the BitBox uses a microSD card. It creates an instant, verified backup so you can secure your keys now and write down the 24 words later, with a clear head.
Loved by begginers (and the pros helping them) ❤️
May your days be calm, your food be amazing, and your bitcoin remain exactly where it belongs… in self-custody.


BitBox Black Friday is live 🖤
View all offers:


BitBox shop 🛒
Official store for BitBox hardware wallets and backup accessories

GM. We’re not the same


For us, it's a no-brainer: wallet first. If you want your bike to be safe, you get a solid lock first.
But we get it, some see it the other way around. What do you think?


You can now grab your BitBox while doing your groceries at REWE Teupe in Dortmund, Germany.
Right next to the fridges. Because cold storage belongs in cold places.

