Security starts at the device.

BitBox is designed around the idea that private keys should not be exposed to ordinary websites, browsers, or cloud storage.

1

Generate keys offline

Initialize the wallet on the hardware device and store the recovery phrase on paper or another offline medium.

2

Verify details physically

Use the device screen as the trusted confirmation surface. Review destination addresses and request details before approval.

3

Protect the backup

A recovery phrase controls access to funds. Keep it offline, private, and separated from cameras, screenshots, email, and cloud backups.

Security boundaries

BitBox provides hardware wallet information, device ordering support, and setup guidance. The company does not ask customers to disclose private keys, seed words, PINs, or recovery material.

Support will not request

  • Recovery phrase words or private keys.
  • Remote access to a wallet backup.
  • Photos, scans, or typed copies of recovery material.
  • Payment or asset movement approvals through a support channel.