TL;DR
The ATECC608B is a small secure chip from Microchip. In the BitBox02 it never sees your keys. It holds one of the secrets needed to decrypt your seed, limits how many passwords a thief can try, and adds randomness when a seed is created.
The BitBox dual-chip design
The BitBox02 has two chips. A general-purpose microcontroller runs the open-source firmware and does all the bitcoin work. The ATECC608B sits next to it as a guard. BitBox’s reasoning: code on a secure chip can’t be published because of non-disclosure agreements, so the bitcoin logic stays on the open chip and the secure chip only handles what it’s good at.
What it does
- Stores a random secret that is one of the ingredients needed to decrypt the seed.
- Slows down every password attempt and keeps a lifetime counter that eventually locks the chip. The 10-attempt limit itself is enforced by the main chip’s firmware.
- Holds an attestation key used to check that the device is genuine.
- Provides one of several sources of randomness for seed generation.
What that means for you
Someone who steals your BitBox02 has to get past both chips. And because the secure chip never learns anything about your bitcoin, you don’t have to trust its closed internals with your keys. More in open vs closed source hardware wallets.
The Nova uses a different chip
The newer BitBox02 Nova uses an Infineon OPTIGA Trust M V3, certified EAL6+. BitBox doesn’t advertise an EAL level for the ATECC608B in the original. See BitBox02 vs BitBox02 Nova and the BitBox02 review.
BitBox02: Buy from BitBox · Buy on Amazon