We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
BitBox02 Nova review and Lightning setup in BitBoxApp
BitBox02 Nova keeps the compact design and touch controls of the original BitBox02, adding a tempered-glass display, a new secure chip, and support for iPhone and iPad. This review compares the two models, explains how they protect your wallet and what the August security update addressed, and helps you choose between the Bitcoin-only and Multi editions.
The second part covers the Lightning wallet introduced in the mobile BitBoxApp in September 2026: how to set it up, add funds, receive and send payments, and move funds back to a BitBox Bitcoin account. This wallet’s keys are stored on your phone, so read about its limitations and reliance on Spark before setting it up.
The instructions describe Lightning in BitBoxApp 4.52.0 with firmware 9.27.1 as of October 2026. Install the latest versions offered by the manufacturer. If menu labels change after an update, check the current instructions in BitBox’s official support documentation.
What is BitBox02 Nova, and how does it compare with the original BitBox02?
BitBox02 Nova continues the Swiss-made BitBox02 hardware wallet range. The original model remains available, giving you a choice between two devices with similar designs but different connection options and components.
Nova measures 54.5 × 25.4 × 9.6 mm, including the USB-C connector, and weighs 13 g. Its built-in USB-C connector lets you plug the wallet directly into a compatible laptop or Android phone. Capacitive touch sensors along the edges replace physical buttons and let you confirm actions and scroll through information on the screen. The controls take some getting used to, especially if your previous wallet had buttons.
Nova’s OLED display is protected by tempered glass, making it more resistant to scratches and easier to read. Its secure chip, OPTIGA Trust M V3, is EAL6+ certified under the Common Criteria international security evaluation framework.
Bluetooth Low Energy enables Nova to work with iPhone and iPad. The original BitBox02 cannot connect to these devices, although it works with a Mac over USB.
According to the current BitBoxApp compatibility guide, the app supports Windows 10+, macOS 12+, supported 64-bit Linux distributions, Android 9+, and iOS and iPadOS 16+. Android devices also need USB OTG support, which allows the phone to communicate with a connected USB device.
According to the manufacturer, Nova comes with a microSD card, a USB-C extension cable, USB-A and Lightning adapters, rubber pulls, and stickers. The Lightning adapter fits the connector on older iPhones and is unrelated to the Lightning payment network discussed later in this guide.
How BitBox02 Nova protects private keys
BitBox uses a dual-chip architecture. The main ATSAMD51J20A microcontroller runs open-source firmware, generates the seed (the secret from which the wallet’s keys are derived), signs transactions, and displays information on the screen. The secure chip stores a secret needed to decrypt the seed and limits password attempts. This division makes physical key extraction more difficult because both components contribute to protecting the keys.
The firmware’s source code is public, and it supports reproducible builds: a researcher can compile it independently and compare the resulting file’s hash with that of the official build. This lets them check whether the released firmware matches the published source code without access to the manufacturer’s internal systems.
The Anti-Klepto protocol provides additional protection. BitBoxApp contributes its own random value to the nonce, a one-time number used to create a signature. This prevents the device from freely choosing a nonce that would secretly leak sensitive information through transaction signatures on the blockchain. From version 4.52.0 onward, BitBoxApp only allows transaction signing on devices with firmware that supports Anti-Klepto.
Whenever you connect, BitBoxApp also checks device attestation — cryptographic proof of the device’s origin. If BitBoxApp reports a failed attestation check, stop the setup: do not create a wallet or send funds to it until you have resolved the issue with BitBox Support.
To unlock BitBox, enter the device password using the touch sensors on the wallet itself. After 10 failed attempts, the device resets to factory settings, and you will need your backup to regain access to your funds.
The August security update: which vulnerabilities were fixed?
In August 2026, BitBox released the Dixence update with firmware 9.26.5, fixing two vulnerabilities the manufacturer classified as severe. BitBox engineers discovered them during an internal code audit, with assistance from AI models. The manufacturer reported no known exploitation of these vulnerabilities in real-world attacks or theft of funds.
The first vulnerability affected the Multi editions of both BitBox02 and Nova running firmware up to and including 9.26.4, before a wallet had been created on the device. A memory-handling flaw could allow an attacker controlling the connected computer or phone to run arbitrary code on BitBox, including installing malicious firmware.
The second vulnerability affected both models running firmware 9.21.0 through 9.26.4 when sending funds to a Silent Payments address. This protocol provides reusable payment details while preserving the privacy of Bitcoin payments. Malware on the connected computer or phone could redirect funds to an address from which the owner could not recover them independently. Direct theft was not possible in this scenario, but an attacker could demand a ransom for helping the owner recover access.
In the same announcement, BitBox revised its assessment of a previously fixed bootloader vulnerability affecting the original BitBox02 with firmware up to 9.26.1. Its potential consequences were more serious than initially reported. The fix was already included in July’s firmware 9.26.2; Nova was not affected by this vulnerability.
Firmware 9.26.5 includes fixes for all the vulnerabilities described in that announcement; some had already been addressed in earlier updates. Update your device through BitBoxApp even if you did not use the affected features. Our hardware wallet firmware update guide explains how to prepare your backup and verify the source of an update.
What to check when your device arrives
Before connecting the device for the first time, inspect the packaging for damage, signs of opening, or resealing. During initial setup, BitBoxApp should offer to create a new wallet or restore an existing one. Do not use a device with a preconfigured wallet and a completed recovery phrase card, because someone else already knows that phrase.
After connecting, wait for the attestation check. If it passes, the packaging shows no signs of tampering, and the device is in its factory state, you can install the update and create your wallet.
Bluetooth on Nova: when you need it and how to disable it
Nova uses Bluetooth to exchange data with iPhone and iPad. The device must be connected to the phone or tablet for power, using USB-C or the included adapter for a Lightning connector. During the first connection, compare the pairing code on both screens and confirm it on Nova and in iOS. Android devices and computers exchange data over USB.
The Whisper protocol provides end-to-end encryption between BitBox and BitBoxApp, so intercepting the radio signal alone is not enough to read the data. You still review and confirm hardware wallet transactions on the BitBox screen.
If you do not need Bluetooth, connect Nova to a computer over USB and open Settings → Manage device → Device settings → Disable Bluetooth in BitBoxApp, then confirm the action on the device. To turn it back on, choose Enable Bluetooth in the same section. Both actions require a USB connection, so you cannot change this setting from an iPhone or iPad. See the Bluetooth settings instructions for the full procedure. If you do not want a device with a radio module at all, consider the original BitBox02.
Backups: microSD and recovery words
BitBox writes its backup to a microSD card inserted directly into the device. This takes a few seconds and lets you restore the wallet later without entering the recovery words manually. The microSD backup is not encrypted with the device password, so anyone who obtains the card can restore the standard wallet on another BitBox. Keep it separate from the device in a secure location; if you use a passphrase, you will also need that phrase to restore the corresponding wallet.
Flash memory can lose data over time, and a small card is easy to misplace, so we recommend also writing down the BIP39 words shown on the BitBox screen. A paper or steel backup in another secure location lets you recover access if the microSD card becomes unusable. Choose a steel backup with the risks of fire, flooding, and physical damage in mind. Our guide to storing a seed phrase covers storage media and how to keep a backup secure.
Do not photograph your recovery words or store them in notes, cloud storage, a password manager, or Telegram messages. Doing so places your wallet’s secret on a device or service that someone else may be able to access.
To use an additional passphrase, often called the 25th word, enable the feature in BitBox’s settings and enter the phrase on the device after unlocking it. Each passphrase opens a separate wallet, and you cannot restore access without the exact phrase, even if you have the seed. This also affects Lightning: the standard wallet and each passphrase wallet derive different Lightning wallets, so check which BitBox wallet is open during setup.
Multi or Bitcoin-only: which edition should you choose?
Both Nova editions use the same hardware and differ in their firmware. Bitcoin-only supports only bitcoin, and its smaller codebase reduces the attack surface — the number of features in which vulnerabilities could arise. Lightning works the same way in both editions.
Multi supports Bitcoin, Litecoin, Ethereum, ERC-20 tokens, and Cardano, but different assets require different apps. BitBoxApp itself manages BTC, LTC, ETH, and supported ERC-20 tokens on Ethereum. Cardano, other ERC-20 tokens, and Ethereum-compatible networks (EVM) require third-party wallets: for example, AdaLite or NuFi for ADA, and Rabby or MyEtherWallet for Ethereum-compatible networks. Your keys remain in BitBox when you use these wallets. Before buying, check the asset, network, and app you need against the official support table.
Choose Bitcoin-only if you only store BTC. You need Multi if you also use Ethereum, stablecoins on that network, or other supported assets. For DeFi — decentralized financial services — check compatibility with your chosen third-party wallet and dApp, or decentralized application.
You can find the specifications and available versions on the BitBox02 Nova product page.
BitBox02 Nova
How Lightning works in BitBoxApp
The Lightning wallet was introduced as a public beta in the BitBox 09.2026 Meggen update. It is available in the mobile BitBoxApp: Android supports both the original BitBox02 and Nova, while iPhone and iPad require Nova. The desktop app does not include a Lightning wallet. The minimum versions for setup are BitBoxApp 4.52.0 and firmware 9.27.1.
This is a hot wallet because the keys used to sign payments are stored on your phone. Ordinary Lightning payments do not involve BitBox; you need the device to approve wallet creation, obtain the secret for recovery, or sign a top-up transaction from a Bitcoin account. These Bitcoin accounts are called on-chain accounts because their transactions are recorded directly on the Bitcoin blockchain.
Using BIP85, BitBox derives a separate secret from the wallet currently open on the device. BitBoxApp uses that secret to generate a Lightning seed without receiving the main recovery phrase. The same BitBox wallet reproduces the same Lightning keys, but the Lightning secret cannot be used to calculate the main wallet’s keys. This means Lightning does not need a separate backup, and stealing its keys alone does not give an attacker access to funds in your on-chain accounts.
BitBoxApp processes payments through Breez SDK, a toolkit for integrating Lightning, and Spark, an off-chain system maintained by a group of operators. Spark interacts with the Lightning network without recording every payment as a separate transaction on the Bitcoin blockchain. This integration lets you pay Lightning invoices and receive payments from compatible wallets without running your own node or managing payment channels and liquidity.
You can receive funds in three ways: a reusable, email-like Lightning address based on LNURL-Pay; a single-use BOLT 11 invoice requesting a specific amount; or LNURL-Withdraw, a withdrawal request provided by a service that supports this mechanism.
Risks of the BitBoxApp Lightning wallet
With keys stored on your phone, malware or someone gaining access to the unlocked device could cause you to lose your Lightning balance. The passphrase on BitBox determines which Lightning wallet is created, but after setup its keys remain on your phone, and payments do not need hardware wallet approval.
The feature is also still in beta. BitBox warns that it may contain bugs, behave unpredictably, or become unavailable, and recommends adding only an amount you are prepared to lose.
Recovery and withdrawals depend on Spark because your BitBox backup can recreate the keys but does not contain the wallet’s current balance or transaction data in Spark. To regain access to the balance on a new phone or withdraw funds to an on-chain account, Spark must be running and its operators must participate in the process.
The manufacturer describes the wallet as non-custodial because the user controls the keys. However, the current BitBoxApp does not support a unilateral exit that would let you move funds to the blockchain without the operators’ cooperation. The official explanation of Lightning in BitBoxApp describes the recovery and withdrawal conditions in more detail.
With Lightning in BitBoxApp, you can receive BTC from exchanges that support the network, send bitcoin to friends, and pay for services and gift cards where Lightning is accepted. You can add funds and move them back to your Bitcoin account in the same app you use for your on-chain accounts, without installing another wallet.
How to set up Lightning in BitBoxApp: step by step
You need a phone with the mobile BitBoxApp and a BitBox containing your wallet. If you have not created the wallet yet, complete its setup and check your backup first. The steps below follow the official Lightning setup instructions.
Step 1. Update BitBoxApp and the firmware
Visit the official BitBoxApp page and follow its link to the App Store or Google Play. Install mobile app version 4.52.0 or later, then connect your BitBox: use Bluetooth for Nova on iPhone or iPad, or USB-C for either model on Android.
If BitBoxApp offers a firmware update, install it: Lightning requires version 9.27.1 or later. The app and device firmware are updated separately, so check the firmware version on BitBox after updating BitBoxApp. Follow the app’s instructions and keep the device connected until the update is complete.
If the option to enable Lightning is missing, check the app and firmware versions and make sure you are using the mobile BitBoxApp. This option is not available in the desktop version.
Step 2. Open the BitBox wallet you want to use with Lightning
The Lightning wallet is derived from the wallet open on BitBox during setup. If you use a passphrase, enter the exact phrase for the wallet you want to link to Lightning, then confirm that BitBoxApp shows the expected accounts and balances.
Only one Lightning wallet can be active at a time in BitBoxApp on a phone. If another is already enabled, disable it in the Lightning settings first. Disabling a wallet does not withdraw or delete its funds.
Step 3. Enable Lightning
Open Settings → Advanced Settings → Enable Lightning Wallet and read the introduction and terms of use. The app will ask you to confirm that you understand where the keys are stored, how recovery works, and why the wallet depends on Spark, and that you have read about the fees and beta limitations.
If you accept these conditions, continue setup and connect and unlock BitBox with the intended wallet when prompted. The device will display Create Lightning Wallet on host device. Approve this action only if you initiated this wallet setup in BitBoxApp.
Wait for the message confirming that the wallet is ready, then select Done. Lightning will appear in the Portfolio section of the main screen. If you decide against using the feature after reading the terms, leave the setup: your on-chain accounts remain available without Lightning.
Step 4. Check the wallet fingerprint
Once Lightning is enabled, Lightning Settings replaces Enable Lightning Wallet in Advanced Settings. Open it and check the BitBox wallet name and its fingerprint, a short identifier, under Wallet. Both should match the BitBox wallet you intended to link to the Lightning wallet.
This check is especially useful when you use a passphrase, because changing even one character opens a different wallet. You can record the fingerprint for future checks and keep it private: it cannot be used to spend funds, but it helps identify your wallet.
Step 5. Add funds from a BitBox Bitcoin account
A new Lightning wallet starts with a zero balance. You can fund it from your on-chain account or receive a Lightning payment from another wallet or an exchange. For an initial test, a direct Lightning transfer may be faster and cheaper if the service supports it and does not charge a high withdrawal fee.
To add funds from BitBox, open Lightning → Top Up, choose the Bitcoin account in the From field, and enter at least 1,000 satoshis (the smallest units of bitcoin). Make sure the account also has enough to cover the fee. Choose a transaction priority, which determines the network fee and estimated confirmation time, then select Review.
When BitBoxApp asks you to confirm the transaction on BitBox, compare the full destination address on the device screen with the address in the app, and check the amount and fee. This is an on-chain top-up address; ordinary Lightning payments use different receiving details. Confirm the transfer only after checking everything.
The app will first show Top Up Created. After the first blockchain confirmation, the amount will appear in the wallet, but it becomes spendable after three confirmations. This usually takes 30 minutes or longer, depending on network conditions and the priority you chose.
If a top-up has a yellow warning triangle and the status Claim required, open the transaction in your Lightning history, view its details, and select Claim top-up or refund. Claim credits the recoverable amount to your Lightning balance, while Refund returns it to a Bitcoin account. Both operations incur a fee, which the app displays before confirmation. If the claim or refund does not complete, do not submit repeated recovery transactions; contact BitBox Support.
Step 6. Receive a payment
Open Lightning → Receive: the Receive Lightning screen shows your Lightning address and its QR code. This email-like address can be reused for multiple payments, so you can copy it and share it with the sender.
If an exchange or another service asks for an invoice, select Create invoice, enter an amount in satoshis or the fiat currency chosen in the app’s settings, and optionally add a description. An amount is required, and the invoice can only be paid once, before it expires. Copy it before leaving this screen, because BitBoxApp does not keep a separate list of saved invoices.
When withdrawing through Lightning, use the receiving details required by the service: an invoice or a Lightning address. A regular Bitcoin address is for an on-chain transfer, so you cannot enter it in place of a Lightning invoice.
Some services display an LNURL-Withdraw QR code for withdrawals. Scan it through Lightning → Send, even though the result is an incoming payment. Make sure BitBoxApp recognizes the LNURL-Withdraw request, review its details, and confirm receipt.
You can choose a name for your Lightning address under Settings → Advanced Settings → Lightning Settings → Set Lightning address, or let the app generate one. You can change the address only once every 24 hours. After a change, the previous address stops accepting payments, although its name remains reserved for your wallet. The current version does not support transferring the address to another Lightning wallet.
The recipient does not pay a fee for a regular incoming Lightning payment; the sender pays it.
Step 7. Pay an invoice
Open Lightning → Send and scan the invoice’s QR code, or paste an invoice or the recipient’s Lightning address. Before confirmation, BitBoxApp shows the payment amount, fee, and total that will be deducted from your balance. Fees depend on the amount and route, so review them for every payment.
The payment is signed using a key on your phone, so you do not need to connect BitBox. For an initial test, send a few hundred satoshis to another wallet you own or to someone you know, and confirm that the payment arrived.
Step 8. Move funds back to your BitBox Bitcoin account
Open Lightning → Send → Enter address or invoice → Select an account and choose a BitBox Bitcoin account. The app automatically fills in that account’s next unused address. Select Continue, enter at least 294 satoshis, and review the destination account, transfer amount, network fee, and total deduction before selecting Send.
BitBox does not need to sign this transfer because the funds are being spent from the Lightning hot wallet. You will need to connect the device if you have not saved the wallet in BitBoxApp using Remember Wallet and the app needs to retrieve its account list. After sending, wait for blockchain confirmations before treating the on-chain transfer as complete.
To withdraw the entire remaining balance and stop using the wallet, open Close and Withdraw Funds in Lightning Settings. Once the remaining funds, minus the fee, are transferred to the selected Bitcoin account, this Lightning wallet is permanently closed, and enabling Lightning again creates a new wallet.
Before closing, wait for all pending incoming payments and remove the Lightning address from your profiles and payment details. If you want to return to the same wallet later, you can disable it while keeping its balance.
Withdrawals and wallet closure are only possible while Spark is working. If the service is unavailable, leave the wallet enabled and try again once service is restored. The Lightning withdrawal instructions explain the conditions for both operations.
What to do if you lose your phone or BitBox
If you lose your phone, the keys to your on-chain accounts remain on BitBox. If you lose the hardware wallet itself, you can restore those accounts using your backup and the same passphrase, if you used one. The safety of your funds also depends on how well the lost device and your backup are protected.
If you lose your phone, restore the Lightning wallet on a new phone using BitBox and withdraw the balance to an on-chain account as soon as possible. Recovery does not remove the keys from the old phone, so the funds may remain accessible from both devices until the withdrawal is complete. Set up a strong screen lock and biometric unlocking on your phone in advance.
If you lose BitBox, restore its wallet on a replacement device using the microSD card or recovery words, along with the same passphrase if you used one. BitBox can then reproduce the Lightning keys, and BitBoxApp can retrieve the balance and transaction history from Spark, provided the service is running.
Common mistakes when using Lightning
Who is BitBox02 Nova for?
Nova suits iPhone and iPad owners who want to use BitBox, because the original model does not work with those devices. It is also a convenient option if you value open-source firmware and want to manage Bitcoin accounts and a small Lightning balance in one app.
For Android or desktop use, the original BitBox02 remains an alternative without a radio module. It uses a dual-chip architecture, supports the same backup method, and lets you use Lightning on Android. Lightning support alone does not require an upgrade to Nova if you already use the original BitBox02 with a compatible Android phone.
If you use altcoins and DeFi, check the networks and third-party apps you need in the compatibility table. Nova is not suitable if you want an air-gapped device that exchanges data through QR codes or microSD without a direct USB or Bluetooth connection to your phone or computer.
If you want to manage your own Lightning channels or choose a different payment infrastructure, you will need a separate wallet with those capabilities. You can still use BitBox to store your main funds. BitBoxApp’s built-in Lightning wallet is convenient for small payments if you accept keeping keys on your phone, the beta status, and the reliance on Spark.
Compare the devices on the BitBox02 Nova, BitBox02 Bitcoin-only, and BitBox02 Multi product pages.
BitBox02 Bitcoin-only edition
BitBox02 Multi edition
Further reading
Related Posts
Keystone 3 Pro setup: step-by-step guide from unboxing to your first transaction
Keystone 3 Pro setup should start with verifying the device and checking a few basic security settings. In this guide, we walk through the entire process step by step, from inspecting the box to signing your first transaction. We based the instructions on Keystone’s official documentation and kept menu labels exactly as they appear on …
Hardware Wallet Firmware Update: When to Update and When to Wait
A hardware wallet is supposed to sit in a drawer and stay out of your way. Most of the time, that is exactly what it does—until its companion app tells you that a hardware wallet firmware update is available. That is where people tend to make opposite mistakes: some stay on firmware with documented vulnerabilities …
Where to store USDT: which network and wallet to choose
If you are deciding where to store USDT, start with how often you actually use the funds. An exchange is convenient for trading and regular swaps, a mobile self-custody wallet works well for smaller day-to-day balances, and a hardware wallet makes more sense for long-term storage of the main amount. The second decision is just …
Trezor Safe 7 vs Ledger Flex: Which One to Choose in 2026
When comparing Trezor Safe 7 vs Ledger Flex, the differences go deeper than screen size or weight: both hardware wallets have a touchscreen, Bluetooth, and a battery, but they protect private keys and handle recovery in different ways. Before choosing a model, it’s worth understanding how its security works and how easy it will be …