TL;DR
A reproducible build means anyone can compile the published source code and get a file identical, bit for bit, to the firmware the maker ships. It closes the gap between “the code is public” and “my device runs that code”.
The problem it solves
A maker can publish perfectly clean source code and still ship firmware built from something else. Without a way to compare, you can’t tell whether your device runs the published code.
How it works
- The maker publishes the source code and exact build instructions, usually a container with fixed tool versions.
- Someone independent builds the firmware from that source.
- They compare the hash (a fingerprint of the file) with the firmware the maker released.
- If they match, the released firmware was built from the published code.
Who checks
You can do it yourself if you’re comfortable with the command line. Most people rely on others who do: security researchers and projects such as WalletScrutiny, which track which wallet releases have been reproduced.
Which wallets
BitBox makes reproducible builds a central part of its approach, Trezor’s firmware can also be reproduced, and Blockstream publishes build instructions for the Jade. Check WalletScrutiny for the current status of any device and firmware version, since it can change per release.
Why it matters in this setup
It’s one reason the BitBox02 is in the guide. Combined with a closed design from another maker, you’re not relying on any single kind of trust.