Skip to content

Releases: BitBoxSwiss/bitbox-wallet-app

Release v4.25.0

27 Jan 12:26
v4.25.0
5804223
Compare
Choose a tag to compare

Release notes

  • Buy crypto inside the app through Moonpay
  • Protection against the nonce covert channel attack when signing Bitcoin/Litecoin transactions (antiklepto protocol).
  • Upgrade to BitBox02 Bitcoin-only firmware version 9.4.0
  • Upgrade to BitBox02 Multi firmware version 9.4.0

Verifying the release

Get benma's public key:

curl https://keybase.io/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import
# or via Tor hidden service
curl http://keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import

Download the app for your platform and the corresponding .asc file and place them in the same folder.

We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.

To verify the signature, execute:

gpg --verify BitBox-4.25.0-macOS.zip.asc

You should see the following output:

gpg --verify BitBox-4.25.0-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.25.0-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg:                using RSA key 2D8876810AB092E451DCA894804538928C37EAE8
gpg: Good signature from "Marko Bencun <marko@shiftcrypto.ch>" [ultimate]
gpg:                 aka "Marko Bencun <mbencun+pgp@gmail.com>" [ultimate]

(The [ultimate] could say [unknown] or something else depending on your trust level.)

Release v4.24.1

12 Dec 15:00
v4.24.1
9ac752c
Compare
Choose a tag to compare

Release notes

  • Fix compatibility with ElectrumX 1.16.0 and Electrs v0.8.6 full node backends
  • Small bugfix in the portfolio chart

Verifying the release

Get benma's public key:

curl https://keybase.io/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import
# or via Tor hidden service
curl http://keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import

Download the app for your platform and the corresponding .asc file and place them in the same folder.

We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.

To verify the signature, execute:

gpg --verify BitBox-4.24.1-macOS.zip.asc

You should see the following output:

gpg --verify BitBox-4.24.1-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.24.1-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg:                using RSA key 2D8876810AB092E451DCA894804538928C37EAE8
gpg: Good signature from "Marko Bencun <marko@shiftcrypto.ch>" [ultimate]
gpg:                 aka "Marko Bencun <mbencun+pgp@gmail.com>" [ultimate]

(The [ultimate] could say [unknown] or something else depending on your trust level.)

Release v4.24.0

03 Dec 16:33
v4.24.0
ab26beb
Compare
Choose a tag to compare

Release notes

  • Account summary page showing your portfolio (current and historical).
  • Added Singapore dollar to the conversion currencies
  • Added Bitcoin to the conversion currencies
  • New ERC20 tokens: WBTC and PAXG (thanks to @PalinuroSec for the contribution)
  • Upgrade to BitBox02 Bitcoin-only firmware version 9.3.1
  • Upgrade to BitBox02 Multi firmware version 9.3.1

Verifying the release

Get benma's public key:

curl https://keybase.io/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import
# or via Tor hidden service
curl http://keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import

Download the app for your platform and the corresponding .asc file and place them in the same folder.

We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.

To verify the signature, execute:

gpg --verify BitBox-4.24.0-macOS.zip.asc

You should see the following output:

gpg --verify BitBox-4.24.0-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.24.0-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg:                using RSA key 2D8876810AB092E451DCA894804538928C37EAE8
gpg: Good signature from "Marko Bencun <marko@shiftcrypto.ch>" [ultimate]
gpg:                 aka "Marko Bencun <mbencun+pgp@gmail.com>" [ultimate]

(The [ultimate] could say [unknown] or something else depending on your trust level.)

Release v4.24.0 - Release Candidate 1

25 Nov 11:49
v4.24.0-rc1
04d84ad
Compare
Choose a tag to compare
Pre-release

⚠️ This is a pre-release candidate intended for testing. ⚠️

Testing is recommended with accounts holding only a small amount of funds. Make sure your backups work before use.

Note: the release candidate installers and binaries are unsigned. Warnings about unknown publisher or similar may pop up.

macOS users: to open an unsigned app, you need to right-click or Control-click the app and select “Open”.

Release notes

  • Account summary page showing your portfolio (current and historical).
  • Added Singapore dollar to the conversion currencies
  • Added Bitcoin to the conversion currencies
  • New ERC20 tokens: WBTC and PAXG (thanks to @PalinuroSec for the contribution)
  • Upgrade to BitBox02 Bitcoin-only firmware version 9.3.0
  • Upgrade to BitBox02 Multi firmware version 9.3.0

Release v4.23.0

20 Oct 21:16
v4.23.0
1af1a1b
Compare
Choose a tag to compare

Release notes

Verifying the release

Get benma's public key:

curl https://keybase.io/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import
# or via Tor hidden service
curl http://keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import

Download the app for your platform and the corresponding .asc file and place them in the same folder.

We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.

To verify the signature, execute:

gpg --verify BitBox-4.23.0-macOS.zip.asc

You should see the following output:

gpg --verify BitBox-4.23.0-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.23.0-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg:                using RSA key 2D8876810AB092E451DCA894804538928C37EAE8
gpg: Good signature from "Marko Bencun <marko@shiftcrypto.ch>" [ultimate]
gpg:                 aka "Marko Bencun <mbencun+pgp@gmail.com>" [ultimate]

(The [ultimate] could say [unknown] or something else depending on your trust level.)

Update 2020-11-05: replaced the Android APK, as the previous upload had an installation issue.

Release v4.23.0 - Release Candidate 1

14 Oct 11:42
v4.23.0-rc1
08d1195
Compare
Choose a tag to compare
Pre-release

⚠️ This is a pre-release candidate intended for testing. ⚠️

Testing is recommended with accounts holding only a small amount of funds. Make sure your backups work before use.

Note: the release candidate installers and binaries are unsigned. Warnings about unknown publisher or similar may pop up.

macOS users: to open an unsigned app, you need to right-click or Control-click the app and select “Open”.

Release notes

Release v4.22.0

22 Sep 16:46
v4.22.0
Compare
Choose a tag to compare

Release notes

  • New expert feature: allow setting custom fees for Bitcoin and Litecoin in sat/vB.

Verifying the release

Get benma's public key:

curl https://keybase.io/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import
# or via Tor hidden service
curl http://keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import

Download the app for your platform and the corresponding .asc file and place them in the same folder.

We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.

To verify the signature, execute:

gpg --verify BitBox-4.22.0-macOS.zip.asc

You should see the following output:

gpg --verify BitBox-4.22.0-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.22.0-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg:                using RSA key 2D8876810AB092E451DCA894804538928C37EAE8
gpg: Good signature from "Marko Bencun <marko@shiftcrypto.ch>" [ultimate]
gpg:                 aka "Marko Bencun <mbencun+pgp@gmail.com>" [ultimate]

(The [ultimate] could say [unknown] or something else depending on your trust level.)

Release v4.22.0 - Release Candidate 1

15 Sep 12:47
v4.22.0-rc1
b2f3d26
Compare
Choose a tag to compare
Pre-release

⚠️ This is a release candidate intended for testing. ⚠️

Testing is recommended with accounts holding only a small amount of funds.

Note: the release candidate installers and binaries are unsigned. Warnings about unknown publisher or similar may pop up.

macOS users: to open an unsigned app, you need to right-click or Control-click the app and select “Open”.

Release notes

  • New expert feature: allow setting custom fees for Bitcoin and Litecoin in sat/vB.

Release v4.21.1

19 Aug 13:03
v4.21.1
39417a2
Compare
Choose a tag to compare

Release notes

Verifying the release

Get benma's public key:

curl https://keybase.io/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import
# or via Tor hidden service
curl http://keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import

Download the app for your platform and the corresponding .asc file and place them in the same folder.

We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.

To verify the signature, execute:

gpg --verify BitBox-4.21.1-macOS.zip.asc

You should see the following output:

gpg --verify BitBox-4.21.1-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.21.1-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg:                using RSA key 2D8876810AB092E451DCA894804538928C37EAE8
gpg: Good signature from "Marko Bencun <marko@shiftcrypto.ch>" [ultimate]
gpg:                 aka "Marko Bencun <mbencun+pgp@gmail.com>" [ultimate]

(The [ultimate] could say [unknown] or something else depending on your trust level.)

Release v4.20.2

12 Aug 16:09
v4.20.2
8e71b7c
Compare
Choose a tag to compare

Release notes

Android release skipped, as it is only a BitBox01 bundle release, which is not supported in Android.

Verifying the release

Get benma's public key:

curl https://keybase.io/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import
# or via Tor hidden service
curl http://keybase5wmilwokqirssclfnsqrjdsi7jdir5wy7y7iu3tanwmtp6oid.onion/benma/pgp_keys.asc?fingerprint=2260e48288882c76afaa319d67a2b160f74db275 | gpg --import

Download the app for your platform and the corresponding .asc file and place them in the same folder.

We will verify the signature of the macOS release as an example. The other files are verified in the same way by replacing the filename.

To verify the signature, execute:

gpg --verify BitBox-4.20.2-macOS.zip.asc

You should see the following output:

gpg --verify BitBox-4.20.2-macOS.zip.asc
gpg: assuming signed data in 'BitBox-4.20.2-macOS.zip'
gpg: Signature made <DATE AND TIME>
gpg:                using RSA key 2D8876810AB092E451DCA894804538928C37EAE8
gpg: Good signature from "Marko Bencun <marko@shiftcrypto.ch>" [ultimate]
gpg:                 aka "Marko Bencun <mbencun+pgp@gmail.com>" [ultimate]

(The [ultimate] could say [unknown] or something else depending on your trust level.)