If an exchange, broker, or other service asks you to verify ownership or prove control of a Bitcoin address, use the exact verification method it accepts. A signed message, an AOPP request, and a Satoshi test are different types of proof and are not interchangeable. If the request does not name an accepted method or format, ask the service before continuing.
When a service accepts the BitBoxApp's address type and message-signing format and does not require another named method, signing directly in the BitBoxApp is the simplest supported option. It creates a signature without sending bitcoin or paying a network fee.
Never share your wallet secrets
No exchange, broker, verification service, or BitBox Support representative needs you to disclose your recovery words, private keys, passwords, optional passphrase, or wallet backup to verify an address. Never send these secrets to anyone or enter them into a service website, support form, chat, or software supplied for verification. Stop if anyone asks for them.
Choose the method requested by the service
Match the wording or action in the request to the options below. Before continuing, make sure you also have the exact address and any message or transaction details supplied by the service.
| What the service asks you to do | Method to use | What to confirm |
|---|---|---|
| Sign a message or submit an address, message, and signature | Sign a Bitcoin message in the BitBoxApp | No transaction or network fee. The service accepts the BitBoxApp's address type and signing format. |
| Sign the message with Sparrow Wallet | Sign a Bitcoin message with Sparrow Wallet and BitBox | No transaction or network fee. The required Bitcoin account is connected to Sparrow Wallet, and the service accepts its signing format. |
| Sign the message with Electrum | Sign a Bitcoin message with Electrum and BitBox | No transaction or network fee. The required Bitcoin account is connected to Electrum, and the service accepts its signing format. |
| Complete an AOPP request, link, button, or QR code | Use the AOPP flow provided by the service | No transaction or network fee. The service has implemented AOPP and supplied the request. |
| Send an exact small amount from a specified Bitcoin address | Perform a Satoshi test with the BitBoxApp and BitBox | It moves bitcoin and incurs a mining fee. The service supplied the exact source requirement, destination, amount, and confirmation conditions. |
If the service only says “sign a Bitcoin message,” ask whether it accepts a signature created in the BitBoxApp. Do not choose Sparrow Wallet, Electrum, AOPP, or a Satoshi test merely because the requested method is unclear.
Sign a Bitcoin message
Message signing creates a cryptographic signature for one address without moving bitcoin. Use the native BitBoxApp workflow when the service accepts Native SegWit addresses beginning with bc1q and the BitBoxApp's signing format. The same workflow supports a previously used address or a new receiving address.
Follow How to sign a Bitcoin message in the BitBoxApp.
Use Sparrow Wallet or Electrum only when the service requires that wallet or confirms that it accepts the resulting address type and signing format. These applications have different account setup, signing, and verification steps, so follow the guide for the wallet you need.
Use AOPP when the service offers it
AOPP works only when both the wallet and the external service support it. Use AOPP when the intended service presents an AOPP request, link, button, or QR code. BitBoxApp support alone does not make AOPP available for a service, and you cannot start the process manually when the service has not implemented it.
The request lets you select an address and return a signed proof without creating a Bitcoin transaction or paying a network fee.
Before approving the request, confirm that it came from the service you expected and that the selected Bitcoin account and address are correct. If the request is unexpected, expired, or opens from an unfamiliar source, stop and return to the service through its official website or app.
The exact setup and verification steps depend on the external service. Examples of services that have implemented AOPP with BitBox include Pocket Bitcoin, Coinfinity, and Bittr. Follow the instructions shown by the service and, where available, its service-specific BitBox guide.
For an explanation of AOPP, what it does, and its limitations, read What is AOPP?. For additional background on how the protocol works and why BitBox supports it, read AOP protocol: Making self custody easier.
Perform a Satoshi test only when requested
A Satoshi test is an on-chain Bitcoin transaction. Unlike message signing or AOPP, it moves bitcoin, incurs a mining fee, creates a public transaction record, and cannot be undone after broadcast.
Continue only when the requesting service explicitly requires a Satoshi test and has supplied the exact source requirement, destination address, amount, and confirmation conditions. The specified source must have a confirmed spendable output that can cover the requested amount and mining fee. If it does not, stop and ask whether the service accepts another verification method; do not fund the address or make a preliminary transaction unless the service has confirmed that this is necessary.
Follow How to perform a Satoshi test with the BitBoxApp and BitBox.
For a deeper explanation of the trade-offs between Satoshi tests, manual message signing, and AOPP, read Satoshi Tests hinder self custody, but AOPP can fix it.
Understand what the proof confirms
A valid message signature or AOPP proof demonstrates control of the selected Bitcoin address. A Satoshi test demonstrates the ability to spend the selected output under the conditions of that transaction. None of these methods proves your identity, establishes legal ownership, or demonstrates control of every address in your wallet.
The requesting service decides whether the submitted proof satisfies its requirements. Sharing an address, signature, or transaction can also link you to that address and reduce your privacy, so provide the result only to the intended recipient.
You are ready to continue when you know the exact method and format the service accepts and have all address, message, or transaction details required by that method. If any of these details is unclear, ask the service before signing or sending anything.