Release notes
- Bundle BitBox02 firmware version v9.27.1
- Add a mobile-only beta Lightning hot wallet, with send, receive, Bitcoin top-up, and on-chain withdrawal flows.
- Require antiklepto-capable firmware for transaction and message signing
- Warn about potential security risks when restoring an external wallet
- Bitcoin: show account details for the persisted receive address type by default
- Add external block explorer links to used addresses
- Settings search
- Support macOS "Number Format" system setting
- Move insurance to Marketplace
- Add clear cache button to settings
- Restrict local permissions for BitBoxApp config files and directories
- Bitcoin: display zero amounts without decimal places
- Add option to navigate to "Used addresses" in sign-message workflow
- Floating mobile bottom navigation bar
- Revamp QR Scanner
- Mobile: Move settings into bottom navigation
- Enable Tether USDT for BTC Direct
- Allow users to upgrade firmware during setup
- Ethereum: improve QR code scanning and fix ERC20 QR payment requests
Verifying the release
Get a public key of security@shiftcrypto.ch with fingerprint DD09 E413 0975 0EBF AE0D EF63 5092 49B0 68D2 15AE:
curl https://bitbox.swiss/download/shiftcryptosec-509249B068D215AE.gpg.asc | gpg --import
Download the app for your platform and the corresponding .asc file and place them in the same folder.
We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.
To verify the signature, execute:
gpg --verify BitBox-4.52.0-macOS.dmg.asc
You should see the following output:
gpg --verify BitBox-4.52.0-macOS.dmg.asc
gpg: assuming signed data in 'BitBox-4.52.0-macOS.dmg'
gpg: Signature made <DATE AND TIME>
gpg: using RSA key DD09E41309750EBFAE0DEF63509249B068D215AE
gpg: Good signature from "ShiftCrypto Security <security@shiftcrypto.ch>" [ultimate]
(The [ultimate] could say [unknown] or something else depending on your trust level.)