BitBox02: first-time setup
The microSD backup is what makes this device fast to set up and the part worth thinking hardest about. Here is how to use it without ending up with one fragile copy of everything.
Most hardware wallets back up by making you write twelve or twenty-four words on a card. The BitBox02 does that too, but its headline feature is a backup written to a microSD card in a few seconds — which is genuinely faster, genuinely less error-prone, and the one part of this setup that deserves a proper think rather than a shrug.
The rest is straightforward. Open-source firmware, a dual-chip design, touch sliders instead of buttons, and a Bitcoin-only edition that is locked to bitcoin at the factory. Half an hour is plenty.
A BitBox02 connected to a laptop by USB-C with a microSD card inserted, the small OLED screen lit, backup card and pen alongside.
Image to come
Before you start
- A BitBox02, unopened, bought from bitbox.swiss or an authorised reseller.
- The BitBoxApp, downloaded from bitbox.swiss typed by hand rather than reached from a search result.
- The supplied microSD card, plus a second one if you want a duplicate.
- A pen and a backup card or metal plate — you are doing both backups, for reasons explained below.
- No bitcoin. Move none until the recovery check at the end passes.
1Take the Bitcoin-only edition, and know it is permanent
The Bitcoin-only firmware edition is locked at the factory. It cannot later be switched to the multi-asset firmware, and that is the point rather than a limitation.
Less code means less that can go wrong, no handling logic for assets you do not own, and no path by which an unrelated coin's bug reaches your bitcoin. If bitcoin is what you hold, this is the edition to buy — but decide before ordering, because you cannot change your mind in software afterwards.
2Check the packaging and pair the device
Inspect the packaging for cuts, re-glued seams, or a second seal over the first, and the case for scratches around the seam. Then connect it over USB-C and let the BitBoxApp guide the pairing.
Pairing shows a code on both the device screen and the computer. Compare them and confirm on the device — this is what establishes that the app is talking to your device rather than something in between.
- A device that arrives already set up, already holding a wallet, or supplied with a printed recovery phrase is compromised. Stop and contact the vendor.
- Install firmware and the BitBoxApp only from bitbox.swiss. Files offered by an email, a message, or a support agent are the attack.
3Set the device password
The BitBox02 uses a device password rather than a numeric PIN, entered on the device itself with the touch sliders. It takes a moment to get used to; that is normal and worth the small learning curve, because the computer never sees what you enter.
- Choose something you can recall under stress and record it somewhere durable.
- Store it separately from your backups — finding one should not hand over both.
- Repeated wrong entries will reset the device, which is recoverable only from your backup.
4The microSD backup, and how to treat it
During setup the device writes your wallet backup to the microSD card. It takes seconds, there is nothing to transcribe, and it removes the single most common cause of unrecoverable wallets: a handwriting mistake nobody notices for three years.
It also means a physical object now exists which, together with your device password, can restore your wallet. So it gets stored with the same seriousness as a written seed — not left in the device, not in a drawer with the BitBox02, not in a laptop bag.
- Remove the card once the backup is written. A card left in the device is not a backup, it is the same object.
- Store it away from the device, so one theft or one fire cannot take both.
- Make a second card if you want redundancy, and store it somewhere else again.
- Label the cards in a way that means something to you and nothing to a stranger.
- Do not copy the backup file onto a computer, a cloud drive, or a phone to make an extra copy. That converts a controlled physical object into copies you cannot track.
- microSD cards fail. They are reliable enough for this and not reliable enough to be your only backup, which is what the next step is for.
5Write the words down as well
The device can also display your recovery words. Do this, and write them by hand, even though you already have the card.
Two reasons, and they are both practical rather than theoretical. Flash memory degrades, cards get bent, and a backup that depends on one small piece of electronics working in ten years is a backup with a shelf life. And the words are portable — they will restore into other wallet software if you ever want to move, whereas the card is a BitBox format.
The card is for speed, the words are for longevity
This is not belt-and-braces paranoia. They fail in completely different ways: the card protects you from mistranscribing, and the words protect you from the card dying or the format becoming inconvenient. Doing both takes ten extra minutes, once.
6Verify a receive address on the device
Malware that swaps addresses in the clipboard is common and cheap. The computer shows what an attacker wants you to see; the small screen on the device does not.
- Generate a receive address and display it on the device.
- Compare the whole string, not only the first and last few characters.
- Review the recipient and amount on the device before approving any send.
- Send a small test amount, confirm it arrives, and send it back out before committing real savings.
7Using it beyond the BitBoxApp
The BitBoxApp is a good guided starting point. The device also works as a signer for Sparrow, Electrum, and Specter, which is worth knowing once you want coin control, labelling, or a connection to your own node.
Your keys stay on the BitBox02 either way. You are changing which software builds the transactions, not where the signing happens.
What this device does not do
- No camera-based air gap. Normal use is connected over USB-C. If signing without ever touching a computer is what you want, this is the wrong device rather than a device to use differently.
- Limited iOS support on older hardware. The original BitBox02 does not work with iPhone or iPad — check the current model if that matters to you.
- It cannot save you from approving a bad transaction. If you confirm a payment to an attacker's address on the device screen, everything worked as designed.
Before you fund it properly
Run the drill in test your recovery — and test both backups. Restore from the microSD card, and separately confirm the written words produce the same wallet. Two backups you have never tested are two assumptions, not two safety nets.
Setup wording, model names, and app behaviour change between releases. Confirm the current flow against BitBox's own documentation and trust what the device screen tells you over any page, including this one.