An optional passphrase is an additional secret that derives a separate wallet from your existing wallet backup. It is different from your device password: every exact passphrase opens its own wallet, while an empty passphrase opens your standard wallet.

This guide explains how to enable the optional passphrase on your BitBox hardware wallet, choose and store a strong passphrase, verify the correct wallet using its root fingerprint, test access safely, and disable or re-enable the prompt. Optional passphrases are part of the BIP39 standard and are not limited to one BitBox model.


Before you enable the optional passphrase

Continue only when:

  • You have a secure offline backup of your wallet, using either a microSD card or recovery words.
  • You have decided how to record and store the exact passphrase offline and separately from the wallet backup. The passphrase is not included in that backup and cannot be recovered by BitBox.
  • You understand how a passphrase creates separate wallets. If you need a refresher, read How does a passphrase work?

If you are still deciding whether the added security is worth the additional recovery responsibility, read Benefits and risks of using an optional passphrase before enabling the feature.

Passphrase recovery warning

If you lose the exact passphrase, your wallet backup alone cannot restore the passphrase-protected wallet. BitBox cannot recover or reset the passphrase, and losing it can permanently block access to the funds in that wallet.

 

Never enter your recovery words or passphrase into the BitBoxApp, a website, a password manager, a cloud service, a chat, or an AI tool. Enter and verify the passphrase only on your BitBox. BitBox Support will never ask you for it.


Enable the optional passphrase

  1. Open the BitBoxApp, connect your BitBox, and unlock it with the device password.
  2. In the BitBoxApp, open Settings and select Manage device.
  3. Under Expert settings, select Passphrase. Its current status should be Disabled.
  4. Select Enable optional passphrase and read the information shown in the BitBoxApp. On the final screen, select Enable passphrase.
  5. Confirm the change on your BitBox when prompted.
  6. Disconnect and reconnect the BitBox. After you enter the device password, it will now ask for an optional passphrase.

Enabling the feature does not create one fixed passphrase or store one on the device. The wallet that opens depends on what you enter at the passphrase prompt.


Choose and record a strong passphrase

Choose the passphrase before you enter it on the BitBox. It needs to be difficult for someone else to guess or brute-force, while remaining possible for you to record and reproduce exactly.

  • Length: Use at least 12 randomly selected characters. Longer can provide more strength when the additional characters are also unpredictable.
  • Randomness: Do not use names, dates, personal information, quotations, keyboard patterns, or another password you already use. A randomly generated sequence is safer than one composed from familiar information.
  • Character variety: A random combination of uppercase letters, lowercase letters, numbers, and symbols can provide strong protection. Simply adding predictable substitutions, such as replacing an a with @, does not make an otherwise predictable passphrase strong.
  • Accuracy: Record the passphrase exactly, including capitalization, spaces, and symbols. Store it offline and separately from your wallet backup. Do not rely on memory alone.

BitBox accepts passphrases of up to 127 characters. You can use standard ASCII characters:

  • Uppercase letters: A-Z
  • Lowercase letters: a-z
  • Numbers: 0-9
  • Spaces
  • Symbols: ! " # $ % & ' ( ) * + , - . / : ; < = > ? @ [ \ ] ^ _ ` { | } ~

Every supported character is significant. For example, a space, a capital letter, or a symbol produces a different wallet from an otherwise identical passphrase.


Open your first passphrase-protected wallet

  1. Unlock the BitBox with the device password.
  2. Enter the passphrase you intend to use and confirm the entry.
  3. Carefully check the complete passphrase shown on the BitBox display. Confirm it only if every character, including capitalization, spaces, and symbols, is correct.

The BitBoxApp now opens the wallet derived from your wallet backup and that exact passphrase. Do not receive a meaningful amount yet. First, record its root fingerprint and confirm that you can reopen the same wallet.


Record the wallet's root fingerprint

The root fingerprint is a short identifier derived from the wallet currently open. A different passphrase normally produces a different root fingerprint, making it useful for distinguishing your standard wallet from your passphrase-protected wallets.

  1. In the BitBoxApp, go to Settings and select Manage device.
  2. Under Device information, find Root fingerprint.
  3. Record the fingerprint with a name that clearly identifies this wallet. Keep the record available for future checks, but do not write the passphrase beside your wallet backup.

The root fingerprint is not a private key and cannot be used to spend funds. It is a short identifier rather than an absolute proof, so use it together with the reopening and small-amount test below. You can learn more in What account details mean in the BitBoxApp.


Confirm that you can reopen the same wallet

Complete this test before transferring a meaningful amount to the passphrase-protected wallet:

Do not transfer meaningful funds yet

A passphrase typo creates a different wallet without showing an error. Transfer a meaningful amount only after you have reopened the wallet, matched its root fingerprint, and confirmed a small test transaction.

 
  1. Disconnect and reconnect your BitBox.
  2. Unlock it with the device password, enter the exact same passphrase, and verify the complete entry on the BitBox display.
  3. Return to Settings → Manage device → Device information and confirm that the root fingerprint matches the one you recorded.
  4. Generate a receiving address and verify the complete address on the BitBox display. Send only a small practical test amount to that address and wait for the transaction to confirm.
  5. Disconnect and reconnect once more. Enter the same passphrase, compare the root fingerprint again, and confirm that the test transaction appears in the wallet.

You have successfully verified the setup when you can repeatedly open a wallet with the same root fingerprint and see the confirmed test transaction. Only then should you consider transferring a larger amount.

Setup verified

The setup is verified when the same passphrase repeatedly opens a wallet with the recorded root fingerprint and confirmed test transaction. Keep the passphrase recoverable and stored separately from your wallet backup.

 

Access your wallets later

When the optional passphrase feature is enabled, the entry at the passphrase prompt determines which wallet opens.

Open a passphrase-protected wallet

  1. Unlock the BitBox with the device password.
  2. Enter and verify the exact passphrase on the BitBox.
  3. In Settings → Manage device → Device information, compare the root fingerprint with the one you recorded for that wallet before receiving or sending a meaningful amount.

Open the standard wallet

  1. Unlock the BitBox with the device password.
  2. At the passphrase prompt, leave the entry empty and confirm it.

The standard wallet is derived from your wallet backup without a passphrase. It normally has a different root fingerprint from wallets derived using a passphrase.


If the wallet is empty or looks unfamiliar

An unexpected empty wallet usually means that the entered passphrase differs from the one used previously. Your original wallet has not been changed, but it can be opened only with the exact original passphrase.

Do not generate a receiving address or transfer funds while an unexpected root fingerprint is displayed.

  1. Compare the displayed root fingerprint with the identifier you recorded for the intended wallet.
  2. If it does not match, disconnect and reconnect the BitBox.
  3. Enter the intended passphrase again, carefully checking capitalization, spaces, symbols, and every other character on the device display.
  4. Continue only when the root fingerprint and expected wallet history both match.

BitBox cannot determine which passphrase you originally used or recover it for you. Never send a passphrase, recovery words, or wallet backup to Support.


Disable or re-enable the optional passphrase

Disabling the feature removes the passphrase prompt. It does not change or delete your standard wallet or any passphrase-protected wallet, and it does not move funds.

Before disabling the feature, make sure you still have the exact passphrase and the recorded root fingerprint for every passphrase-protected wallet you intend to access again.

  1. Open the BitBoxApp, connect your BitBox, and unlock it. You can perform this action while either the standard wallet or a passphrase-protected wallet is open.
  2. Go to Settings → Manage device → Expert settings → Passphrase.
  3. Select Disable optional passphrase and confirm the change on your BitBox.

After disabling the feature, unlocking the BitBox opens the standard wallet without showing a passphrase prompt. To access a passphrase-protected wallet again, return to the same setting, re-enable the feature, reconnect the device, and enter the exact passphrase. Confirm the expected root fingerprint before using the wallet.


Can you change a passphrase?

An existing passphrase cannot be edited or reset. Entering a different passphrase creates a different wallet; it does not change the passphrase of the original wallet.

To use a new, first create and verify the new wallet using the complete test above. You must then open the wallet associated with the old passphrase and transfer the funds to a receiving address from the newly verified wallet. Keep access to the old wallet until the transfer is confirmed in the new one.