Hardware review — BitBox02
BitBox02 review: the quiet Swiss option
The BitBox02 gets talked about less than Ledger and Trezor and is arguably better engineered than either. Fully open firmware, a dual-chip design, the cleanest desktop app in the open-source group, and a microSD backup that removes the most common backup failure.
- 2 chips Secure element plus a separate microcontroller
- 100% Firmware published and reviewable
- microSD Encrypted backup, no transcription errors
- ≈NZ$330 Multi edition landed, indicative
At a glance
Quietly one of the best-built devices on the market, with the cleanest desktop app of the open-source group.
Best for: People who want Swiss engineering and microSD backup · Maker: Shift Crypto (Switzerland)
The device nobody talks about
There is a rough correlation in consumer hardware between marketing spend and recommendation frequency, and the BitBox02 is the exception that proves it. Shift Crypto is a small Zurich company with no celebrity endorsements and no presence in airport advertising, and it has built one of the two or three best-engineered signing devices you can buy.
The core of it is a dual-chip architecture. Rather than putting everything in one secure element, the BitBox02 splits responsibility between a secure element and a separate general-purpose microcontroller, arranged so that compromising either one alone does not yield the seed. It is a defence-in-depth approach with a real engineering rationale, and it means an attacker with physical access has to defeat two components with different failure characteristics rather than one.
Layered on top is fully open firmware, which puts BitBox in the camp alongside Trezor, Keystone and Blockstream — you or anyone else can read the code that touches the recovery phrase. Shift also publishes an unusually candid description of what its threat model does and does not cover, which is more useful than a certification badge.
Specifications
| Maker | Shift Crypto, Zurich, Switzerland |
|---|---|
| Editions | Bitcoin-only and Multi |
| Price | CHF 149 for the Multi edition; Bitcoin-only similar |
| Architecture | Dual chip — a secure element paired with a general-purpose microcontroller so neither alone holds the seed |
| Source code | Fully open — firmware published |
| Connection | USB-C direct, no adapter needed on most laptops |
| Input | Capacitive touch sliders on the device body |
| Backup | BIP39 recovery phrase plus optional encrypted microSD backup (card included) |
| Companion software | BitBoxApp — Windows, macOS, Linux, Android |
| Staking | No native staking |
| NZ availability | Direct import from bitbox.swiss; no local reseller |
| Last verified | September 2026 |
The microSD backup, which is genuinely clever
Of every feature across the eight devices we have graded, the BitBox02's encrypted microSD backup is the one we most wish everybody else copied.
The problem it solves is not glamorous. When someone loses cold storage permanently, the cause is very often a handwritten recovery phrase that turns out to be wrong — two words transposed, an ambiguous letter, a word written from a different device, or simply illegible handwriting three years later. It is a transcription failure, and transcription failures are what happens when you ask humans to copy twenty-four arbitrary words accurately under mild time pressure.
The BitBox02 lets the device write an encrypted copy of the seed to a bundled microSD card during setup. Recovery is inserting the card and entering your device password. No transcription, therefore no transcription error. It is faster, it is more reliable, and it means the test restore we bang on about is something you will actually do because it takes thirty seconds.
The obvious caveat: that card is now a wallet. An encrypted one, protected by your password, but an object that must be secured with the same care as written words — different building from the device, out of casual reach. And we would still write the phrase down as well. Two backup media that fail in different ways is strictly better than one, and the standard BIP39 phrase is what gives you portability to another brand if BitBox ever stops existing.
Do both
Encrypted microSD backup for reliability and easy testing, handwritten phrase for portability and independence from any one company. Store them in different places. This is the most robust backup arrangement available on any device in this price range.
Bitcoin-only firmware, and why it matters
BitBox sells two editions of the same hardware, differing only in firmware, and the distinction is more meaningful than it appears.
A multi-coin hardware wallet has to include code for every chain it supports — different address formats, different transaction structures, different signature schemes. Every one of those code paths is software that could contain a bug, and bugs in a device holding your keys are the thing you are paying to avoid. Bitcoin-only firmware removes all of it. What remains is a much smaller, much more heavily reviewed piece of software doing one job.
This is the same reasoning behind Coldcard and behind Blockstream Jade's Bitcoin focus, and we think it is correct. If you hold only Bitcoin — which describes a substantial share of long-term holders — the Bitcoin-only edition is the better purchase with no downside whatsoever. Do not take the Multi edition "in case I buy something else later"; you can always buy a second device, and the reduced attack surface is worth more than the optionality.
BitBoxApp
We score BitBoxApp at 8.4, and its main virtue is what it does not do. There is no buy panel pushing a third-party broker at you, no earn tab, no swap widget with an undisclosed spread. It shows your accounts, sends and receives, handles firmware updates, and can connect to your own Bitcoin full node. That is the whole application.
The weakness is the device rather than the software. Capacitive touch sliders on the device body are how you confirm actions, and they are less immediately obvious than buttons and less pleasant than a touchscreen — new users hesitate. And the screen is small, which makes careful verification of a long address more of a chore than it is on a Trezor Safe 5. Neither is a security defect, but both contribute to the friction that makes people use their cold storage less than they should.
The balance sheet
What we like, and what we don't
What it does well
- Fully open-source firmware, so security claims can be independently verified
- Dual-chip architecture means an attacker must defeat two different components with different properties
- Encrypted microSD backup eliminates the transposed-word failure that ruins so many paper backups
- BitBoxApp is the cleanest and least commercially cluttered desktop software of the open-source group
- A genuine Bitcoin-only firmware edition with a substantially reduced attack surface
- USB-C plugs straight into a modern laptop with no dongle, which sounds trivial and is not
- Swiss company with unusually good published documentation of its threat model
What we hold against it
- No New Zealand reseller — every purchase is a one to three week import
- No native staking at all, so proof-of-stake holders need another arrangement
- Touch sliders are less satisfying and less obvious than buttons or a touchscreen
- Small screen makes long address verification tedious compared with a Trezor Safe 5
- Lower brand recognition means fewer third-party integrations and less community troubleshooting material
- The microSD backup creates a second physical object that must be protected exactly as carefully as a written phrase
Getting one to New Zealand
This is the practical constraint. No New Zealand retailer stocks BitBox, so every purchase is a direct import from Switzerland, and you should plan for one to three weeks.
The tax position is straightforward and small. Overseas suppliers with more than NZ$60,000 of annual New Zealand sales are required to charge 15% GST at checkout on goods valued at NZ$1,000 or less, so it is usually already in the total and you will not be pursued at the border. From 1 April 2026, New Zealand Customs applies a Low-Value Goods levy of NZ$2.21 for air freight or NZ$2.09 for sea, plus GST, per consignment under NZ$1,000. On a CHF 149 device the incremental cost of importing is shipping plus a couple of dollars. Our GST and customs guide covers the arithmetic.
What you do not get, and should factor in, is cover under the Consumer Guarantees Act 1993. Buy from a New Zealand retailer and the goods must be of acceptable quality with local remedies if they are not; import directly and you are relying on Shift Crypto's own warranty policy and whatever your card issuer will do. For a device at this price the practical difference is modest, but it is real.
Who should actually buy this
Three groups, fairly specifically.
Bitcoin-only holders who want open firmware without Coldcard's learning curve. The Bitcoin-only BitBox02 gives you a genuinely reduced attack surface and published code in a device you can set up in fifteen minutes. Coldcard is more rigorous and considerably harder; this is the reasonable middle.
People who have already lost funds to a bad backup. If you have ever had a handwritten phrase fail to restore, the encrypted microSD backup will change how you feel about this whole exercise.
Anyone who wants software that is not trying to sell them something. BitBoxApp is the only companion application in this category with no commercial surface at all, and if the accumulating buy-sell-swap-earn panels in competing apps irritate you, that is a real reason to choose differently.
Who should not: anyone who needs staking, anyone who needs a device this week, and anyone who will be put off by touch sliders. For those cases the answer is a Ledger or a Trezor.
From our testing notes
We time how long it takes a new user to complete a wipe-and-restore, because that step is the one people skip and skipping it is the leading cause of permanent loss. With a written phrase it takes several minutes and involves squinting. With the BitBox02's microSD backup it took under a minute, and every tester did it without being nagged. Making the right behaviour effortless is worth more than most features that appear on a spec sheet.
BitBox02 FAQ
BitBox02 — questions New Zealanders ask
Is the BitBox02 available in New Zealand?
Not through a local reseller. BitBox ships internationally from Switzerland, so this is a direct import taking roughly one to three weeks. Fifteen percent GST is generally collected at checkout for goods under NZ$1,000, and from 1 April 2026 Customs adds a Low-Value Goods levy of NZ$2.21 for air freight plus GST per consignment. Landed cost for the Multi edition works out to roughly NZ$330 — indicative, not a quote. If domestic stock matters more to you than Swiss engineering, a Ledger Nano S Plus is NZ$99 from GROOV in Christchurch.
Should I buy the Bitcoin-only or the Multi edition?
Bitcoin-only if you hold only Bitcoin, without hesitation. The Bitcoin-only firmware strips out every other coin's code, which means dramatically less software to contain a bug and a correspondingly smaller attack surface. It is the same principle behind Coldcard and it is a genuine security improvement, not a marketing distinction. The Multi edition exists because most people hold more than Bitcoin, and if that is you, take it — but do not choose it "just in case".
How does BitBox02 microSD backup work?
Instead of only writing twenty-four words on paper, the BitBox02 can write an encrypted copy of the seed to the bundled microSD card during setup. Restoring means inserting the card and entering your device password. It is faster and less error-prone than transcribing words by hand, and it removes the transposed-word failure that ruins so many paper backups. It also creates a physical object that must be protected as carefully as a written phrase would be — a microSD card in a drawer is a wallet in a drawer. Keep the written phrase as well; belt and braces.
Is BitBox02 open source?
Yes, the firmware is fully published, which puts it in the same camp as Trezor, Keystone and Blockstream. Shift Crypto is also unusually transparent about its threat model and its dual-chip architecture, pairing a secure element with a general-purpose microcontroller so that neither alone holds enough to compromise the seed. For a company of its size the documentation quality is genuinely impressive.
Next in this cluster