A Swiss platform built around cryptography, not custody. Zero-knowledge proofs settle on-chain — your private keys never leave your wallet. We never hold them. Nobody can.
Three sequential layers — physical, cryptographic, mathematical. To move a single satoshi without your consent, an adversary must defeat all three. The first costs an army. The second costs a quantum computer. The third costs a proof of P = NP.
01
Physical layer
Two kilometres of alpine bedrock.
Swiss Fort Knox is a decommissioned alpine command bunker carved into bedrock and built to survive a sustained nuclear strike. It houses Bit Bank's Hardware Security Modules — the only physical key shards we ever hold — and is the place we don't talk about much, by design.
There is no public address. Access is via a single private road, an armed Securitas perimeter, retina + vein-pattern biometric, and a tail-gating mantrap. The HSM cabinet itself sits inside a Faraday-shielded room with no external network — instructions are signed in Zurich and shuttled in over a one-way optical diode.
2,000m
Granite
−250m
Below
24/7
Armed
EMP
Faraday
Diode
One-way
FINMA
Audited
On-chain
Hash · Groth16 proof
Off-chain
BB Vault · Self-Custody
46.464°N 7.279°E · Saanenland · Switzerland
Swiss Fort Knox
Audited · FINMA · ISO 27001 · SOC 2 Type II
L4
L2
L3
L1
Ventilation Ducts
Power Conduits
HSM Server Racks
Reinforced Concrete
Swiss Alpine Military Bunker · Cross-Section · Project “Eisenfels”
Saanenland · Switzerland
Swiss Fort Knox
Coordinates withheld · audited by FINMA, ISO 27001, SOC 2 Type II
Saanenland · Switzerland
Swiss Fort Knox
Coordinates withheld · audited by FINMA, ISO 27001, SOC 2 Type II
02
Cryptographic layer
Three keys. You hold one.
Every Bit Bank custody account is protected by 3-of-3 Multi-Party Computation. Your wallet shard lives on your device. The second sits in our Swiss Fort Knox HSM. The third sits across the border in a Liechtenstein HSM operated by a separate legal entity.
A transaction signs only when all three shards co-operate via threshold ECDSA. We mathematically cannot move your funds alone — and neither can any single jurisdiction. Even Swiss law enforcement gets, at most, two of three.
FIPS 140-3 L3
Tamper-evident, tamper-active HSMs. Same standard the SNB and NATO use.
Threshold ECDSA
No "private key" exists in any one place. Only three shards that compute together.
Cross-jurisdiction
CH + LI: two MLATs needed for any seizure attempt. ~24 months minimum.
Inheritance
Shamir-shared recovery to your nominated executor. Activates only on Swiss death certificate.
03
Mathematical layer
Built for the post-quantum era.
Today's elliptic-curve cryptography (the secp256k1 you trust on Bitcoin and Ethereum) will fall to a sufficiently large quantum computer. The "harvest now, decrypt later" threat is already real — adversaries are storing today's encrypted data to break in 2030+.
Bit Bank dual-signs every operation: classical secp256k1 for chain compatibility today, plus NIST-certified Kyber768 for key encapsulation and Dilithium3 for signatures. Both are lattice-based — believed unbreakable even by Shor's algorithm on a fault-tolerant quantum computer.
Kyber768
NIST FIPS 203 · KEM
Dilithium3
NIST FIPS 204 · sigs
2030+
Quantum threat horizon
Attack scenario
What an adversary would need to do.
1
Defeat Cloudflare + 7-layer firewall
Network
2
Reach an air-gapped HSM behind a one-way diode
Network → Host
3
Physically breach an alpine military bunker
Physical
4
Repeat — in a different jurisdiction (LI)
Cross-border
5
Steal your personal device's shard
Endpoint
6
Forge an ECDSA signature
Classical math
7
Forge a Dilithium3 lattice signature
Quantum math
Your bank's vault has one of these layers. Maybe two. We have all seven.
Client key · 3-of-3 MPC shard · Bit Bank cannot move funds without you
Threshold ECDSA
No "private key" exists in any one place
Your key is never assembled. Three shards — yours, ours in CH, a third in LI — sign together via threshold cryptography. The full key is mathematically reconstructed only in the moment of signing, then destroyed.
FIPS 140-3 Level 3 HSM
Tamper-evident, tamper-active
Our two HSM shards live in steel cabinets that auto-erase the moment the chassis is opened. Same standard as the Swiss National Bank, NATO, and the US DoD.
Post-quantum dual-sig
Kyber768 + Dilithium3
Every operation is signed twice — once with secp256k1 for chain compatibility, once with NIST-certified lattice cryptography. Both must hold. Quantum can break one, classical can break the other — neither can break both.
Inheritance protocol
Shamir-shared recovery, court-gated
Your nominated executor receives an encrypted shard pre-signed by you. It activates only when the Swiss federal civil registry returns a valid death certificate. No probate freeze. No lost coins.
Encryption · live
Every keystroke,every signature, every byte.
A live look at the cryptographic stack between your device and our HSMs. Nothing leaves your computer in plaintext. Nothing reaches our chain unsigned. Nothing on-chain reveals your identity.
7a 4f 91 c2 e8 a3 5d 12 ff b6 28 c4 90 7e 1a d3 6f b0 49 5e
f3 c2 8d 47 b1 9e 0a 6c 22 fd 81 4b a7 35 d9 6e 18 c0 5f 2b
b8 41 ec 5d 9f a2 36 c7 1e 70 b5 8a 4d ff 23 91 cd 6b 02 e4
2d d4 a0 96 7c 11 b8 4e 33 a9 5f 80 c6 21 ed 47 9b 04 fa 51
Every connection negotiates a classical X25519 + post-quantum Kyber768 shared secret. Even if recorded today, content cannot be decrypted by tomorrow's quantum computers.
Application
AES-256-GCM payload
Each request is sealed with an authenticated cipher. Tamper a single byte and the message is rejected — no oracle for chosen-ciphertext attacks.
Signing
secp256k1 + Dilithium3
Operations are dual-signed. Classical curve for chain compatibility today; lattice signature for the post-quantum future. Both must hold to authorise.
Anonymity
Groth16 ZK-SNARKs
Trades publish a 192-byte zero-knowledge proof to chain. Counterparty, amount, asset — all sealed. Provably valid, provably opaque.
Network
TOR onion + .onion fallback
Optional routing through three hops. Bit Bank itself never sees your IP, only the proof that you authorised an action.
Side by side
If you're serious about privacy and security,there is no competition.
Bit Bank versus the platforms most HNW clients consider. Every row is a publicly verifiable fact — links and citations available on request from your relationship manager.
Capability
Bit Bank
Bitcoin Suisse
Sygnum Bank
Coinbase
Binance
You hold your own private keys
✓ Always
✗ Custodial
✗ Custodial
✗ Custodial
✗ Custodial
3-of-3 MPC (no single key)
✓ CH + LI + you
Partial
Partial
Cold storage only
Hot wallets
Quantum-resistant signatures
✓ Dilithium3
✗
✗
✗
✗
Zero-knowledge trade privacy
✓ Groth16 SNARKs
✗
✗
✗ Public ledger
✗ Internal ledger
Nuclear-hardened physical custody
✓ Swiss Fort Knox
Swiss vault
Swiss vault
Generic data centres
Cayman / Malta
Swiss FINMA jurisdiction
✓ Bit Vault AG
✓
✓ Bank licence
US (NYDFS)
Various
Min KYC for permissionless trading
✓ Wallet only (DEX)
Full KYC
Full KYC
Full KYC
Full KYC
Tax-free in Switzerland (private)
✓ No CGT
✓
✓
US capital gains
Variable
Cross-border seizure resistance
~24mo (CH+LI MLAT)
~12mo (CH only)
~12mo (CH only)
Days (US warrants)
Hours
Withdrawals halted in 2022/23
✓ Never
✓ Never
✓ Never
Brief outages
Yes (multi-day)
Dedicated relationship manager
✓ Within 24h
✓ HNW
✓ HNW
Prime tier only
VIP tier only
On-chain inheritance protocol
✓ Shamir + cert.
Manual
Manual
Probate court
Probate court
Sole point of failure
None
CH bank
CH bank
US exchange
CEO
Sources: company terms of service, FINMA registry, public outage post-mortems, AML/KYC policy disclosures. Data current as of 2026-Q2 — references on request.
Live Infrastructure
Built. Audited. Running.
01 · Cryptography
Ceremony Complete
ZK Trusted Setup.
Multi-party Powers-of-Tau ceremony for Groth16 SNARK circuits. Public transcript. Toxic waste destroyed at each contributor's checkpoint.
Curve
BN254
Contribs
Multi-party
Status
Verified
02 · Network
Mainnet Live
XDC Private Subnet.
Sovereign side-chain producing blocks since launch. 3 validators, sub-second finality, ISO 20022 messaging native. ZK proofs settled on every transaction.
Validators
3-of-3
Block time
< 2 s
Status
producing
03 · Custody
Install · 14 days
Swiss Fort Knox.
Air-gapped HSM cabinet installation in progress. FIPS 140-3 L3, Faraday-shielded, NDA site visit on shortlist. Hot-spare fail-over from CH to LI HSM.
HSM
FIPS 140-3 L3
Quorum
3-of-5 MPC
Online
Q3 2026
The Full Stack
Whatever brought youhere.
Active traders, privacy-conscious holders, founders, family offices, foundations — one platform, four pillars. Trade with leverage, hold with cryptography, invest with discretion, settle on one ledger. The breadth a retail trader uses on Monday; the depth an allocator audits on Friday.
* Lending and trading on the decentralised exchange are non-custodial and permissionless. Custody Account, fiat ramps, card programme and OTC desk are subject to FINMA / AMLA identity verification.
Card & Merchant
Spend it.And receive it.Anywhere.
Convert digital assets to fiat at the point of sale — or accept crypto at your business through a Bit Bank PDQ terminal. The card and the terminal close the loop between on-chain wealth and the high street.
Launch promo · First 100 cards free · First 100 PDQs no deposit
Metal
•••• •••• •••• ••••
CardholderPrivate Client
Expires••/••
VISA
01Spend
Bit BankVisa.
A Visa card linked to your custody account. Crypto stays as crypto until the moment of purchase — conversion happens at the point of sale and fiat moves to the merchant in seconds.
A Bit Bank-branded PDQ terminal on Worldpay enterprise rails. Visa, Mastercard, Amex, Apple & Google Pay, plus on-chain crypto — one device, one settlement file, revenue share back to your business.
Four tiers. No setup fee. No lock-in. Self-custody with Swiss infrastructure at every level — the breakpoints just unlock more relationship.
Standard
5%
annual · under $100K
✓ Nuclear-hardened custody
✓ Quantum-proof signatures
✓ ZK privacy
✓ Own your keys
✓ Bit Bank Visa Card
Premium
2.5%
annual · $100K – $500K
✓ Everything in Standard
✓ Priority support
✓ TOR routing
✓ Premium Visa card
✓ Tax reporting
Private
1.5%
annual · $500K – $1M
✓ Everything in Premium
✓ Dedicated account manager
✓ Private subnet access
✓ Metal Visa card
✓ Inheritance planning
Ultra
0.75%
annual · $1M+
✓ Everything in Private
✓ White-glove onboarding
✓ OTC desk access
✓ Custom fee structure
✓ On-site bunker visits
Cheaper than Bitcoin Suisse
All tiers include nuclear-hardened custody, quantum-proof cryptography, zero-knowledge privacy, and full Swiss legal protection. You own your keys at every tier.
On-chain privacy. Off-chaindiscretion.
Cryptography over custody. Zero-knowledge proofs settle on-chain — the keys never leave your wallet. Bitcoin Suisse, Sygnum and Coinbase all hold yours. We don’t. Nobody can.
1SubmitApply or connect a wallet5 min
2Banker callSwiss RM contacts you< 24 h
3KYC & structuringFINMA / AMLA verification2–3 days
Two ways to begin. Connect a wallet for permissionless self-custody trading on the decentralised exchange, or apply for a Swiss-regulated Private Banking account with full custody, fiat ramps, and card services.
Permissionless
Connect& Trade
Connect a wallet, sign a message, start trading. Fully decentralised — your keys never leave your device. No KYC, no minimums, no waiting room.
Swiss-regulated private banking with fiat ramps, card programme and a relationship manager. KYC under FINMA / AMLA. Custody access via your BB Key hardware dongle.
✓Everything in Connect & Trade
✓Swiss Fort Knox HSM · MPC custody
✓Fiat ramps — SEPA, SIC, SWIFT
✓Bit Bank Visa · metal & virtual
✓OTC Desk · tax reporting CH/EU/UK
✓Inheritance · physical metals redemption
VerifiedFINMA · AMLAVQF SRO
RM within 24 h · Custody under Swiss law
Institutional
Family Office& Institutional
White-glove onboarding for family offices, foundations and asset managers. Multi-account governance, sub-custody for LPs, ISO 20022 / SWIFT settlement. Minimum AUM USD 5M.
Required for fiat services, card, and OTC only. Your trading activity remains permissionless.
Two paths, one platform.
Decentralised protocol interactions are permissionless. Swiss-regulated custody requires KYC under FINMA/AMLA.
Service
Self-Custody
Private Banking
Spot exchange (connect wallet)
✓
—
Futures trading
✓
—
Staking & yield vaults
✓
—
Hedge fund vaults (managed)
✓
—
Fixed income (bonds)
✓
—
ZK Shield privacy
✓
—
Swiss Fort Knox custody
—
Required
Fiat on/off ramps (SEPA, SIC)
—
Required
Bit Bank Card (Visa)
—
Required
OTC desk (USD 500K+)
—
Required
Precious metals (physical)
—
Required
KYC is required by Swiss AMLA (Anti-Money Laundering Act) only where Bit Bank acts as a financial intermediary — holding assets on your behalf or converting fiat currency. All decentralised protocol interactions remain permissionless.
About
A bank that doesn't hold your keys.
Bit Vault AG, trading as Bit Bank, is a Swiss financial services provider built around a contrarian principle: a bank should not be the single point of failure for the assets it serves.
We don't hold your keys. We can't move your funds without you. Our role is the cryptography that makes self-custody work at institutional scale — the proof systems, the threshold signatures, the bunker-grade hardware, the regulated rails. The keys stay with you.
On-chain we publish only zero-knowledge proofs of validity. Off-chain we manage the operational discretion that institutional clients require: ISO 20022 settlement, fiat ramps, card programmes, an OTC desk, sub-custody for limited partners, audit-grade quarterly reporting. Two surfaces, one platform, one Swiss legal entity.
Bit Vault AG is registered in Zurich (UID CHE-487.291.066), affiliated to the VQF self-regulatory organisation under the Anti-Money Laundering Act, and subject to Swiss banking secrecy. Our HSM infrastructure is air-gapped inside Swiss Fort Knox — an alpine command bunker carved into bedrock under armed perimeter.
Bit Vault AG
Trading entity
Zurich · CH
Swiss jurisdiction
VQF SRO
FINMA-supervised
ISO 20022
Settlement standard
Operating principles
Cryptography over custody.
Zero-knowledge first
Every layer built around cryptographic proof. We don't ask you to trust us — we let you verify.
Self-custody by default
3-of-5 MPC. Threshold ECDSA. Your BB Key. The full key is reconstructed only at signing time, then destroyed.
Swiss jurisdiction
Banking secrecy under federal law. Data minimisation by architecture. MLAT process measured in years, not days.
One relationship
Dedicated banker for custody clients. White-glove onboarding for institutions. We know you by name.
Contact
Get in touch.
Whether you're ready to open an account or have questions about our services, we're here to help.
We use essential cookies only — for language preferences and session management. No tracking, no advertising cookies.Privacy Policy
Security Architecture
Defence in depth.
Physical, cryptographic, mathematical — three sequential layers an adversary must defeat to move a single satoshi without your consent. The first costs an army. The second costs a quantum computer. The third costs a proof of P = NP.
Ceremony complete
ZK trusted setup
Multi-party Powers-of-Tau · Groth16 / BN254
Mainnet live
XDC private subnet
Sovereign side-chain · 3-of-3 validators · <2s
Install · 14 days
Swiss Fort Knox HSM
Air-gap install in progress · FIPS 140-3 L3
BB Key
Your personal hardware security key
Every custody client receives a BB Key — a NitroKey HSM2 hardware device branded with the Bit Bank mark. This device holds your personal MPC key shard. Without your BB Key, nobody — not Bit Bank, not the bunker, not any government — can access your assets.
Your keys are split into three shards using Multi-Party Computation (MPC). Shard 1 lives inside a Thales HSM at Swiss Fort Knox. Shard 2 lives in a separate HSM in Liechtenstein. Shard 3 lives on your BB Key. Any two of three shards reconstruct the key — meaning you always hold veto power over your own assets.
✓ FIDO2/WebAuthn compliant
✓ Tamper-evident hardware
✓ USB-A and USB-C
✓ Open-source firmware
✓ Bit Bank custom engraving
✓ Secure courier delivery
Swiss Fort Knox
Physical infrastructure
Swiss Fort Knox is a decommissioned alpine command bunker carved into bedrock. Built to withstand nuclear attack, it now houses some of the most sensitive data in Europe. Bit Bank’s HSM servers operate inside this facility.
✓ Nuclear-hardened bedrock
✓ 24/7 armed Securitas guard
✓ Biometric + keycard entry
✓ Faraday cage shielding
✓ Redundant power + cooling
✓ Seismic isolation
NitroKey NetHSM
Cryptographic hardware
All private keys are generated and stored inside Thales Luna Network HSM hardware certified to Military-grade — open-source NitroKey NetHSM hardware with tamper-evident casing. Keys are generated inside secure enclaves and backed up on encrypted iStorage datAshur drives.
✓ Military-grade certified
✓ Common Criteria EAL4+
✓ Tamper-responsive enclosure
✓ AES-256 + ECC key generation
TOR & Private Network
Network privacy
Bit Bank natively supports TOR onion routing — your connection passes through multiple encrypted relays, making it impossible to trace your IP address or location. For institutional clients, we offer a dedicated VPN tunnel to our bunker infrastructure via Swiss IP addresses only.
✓ TOR .onion endpoint
✓ Swiss-only VPN option
✓ No IP logging
✓ End-to-end encryption
Quantum-Proof Cryptography
NIST FIPS 203/204/205 post-quantum algorithms
Quantum computers will break ECDSA and RSA within the next decade. Bit Bank is ready today. All key exchanges use ML-KEM (Kyber768) — NIST's approved post-quantum key encapsulation. All transaction signatures use ML-DSA (Dilithium3) — quantum-resistant digital signatures. Every transaction is dual-signed: classical ECDSA for blockchain compatibility plus ML-DSA for quantum resilience. If quantum computers break ECDSA tomorrow, your assets remain protected.
◆ ML-KEM (Kyber768) key exchange
◆ ML-DSA (Dilithium3) signatures
◆ SLH-DSA (SPHINCS+) hash backup
◆ AES-256 + SHA-3 (already safe)
◆ Hybrid dual-signing on all txs
◆ Harvest-now-decrypt-later proof
Zero-Log Architecture
We cannot disclose what we do not collect
Bit Bank is architecturally incapable of complying with data requests for information it never collects. No IP addresses are logged. No browsing history. No device fingerprints. No metadata. KYC compliance is achieved via zero-knowledge proofs — we verify you passed identity checks without storing your personal documents. Your trading history is on-chain and ZK-shielded; only you hold the viewing keys. Under Swiss law (FADP Art. 6), we minimise data collection by design.
✓ Zero IP logging by architecture
✓ ZK-KYC — proof without exposure
✓ Client holds own viewing keys
✓ FADP data minimisation compliant
✓ Swiss MLAT jurisdiction only
✓ MPC keys — we can't access alone
7-Layer Defence Network
Defence in depth — military-grade topology
Seven distinct security layers separate the public internet from your private keys. Trading runs at under 50ms latency through the fast path. Custody operations route through Tor hidden services terminating inside Swiss Fort Knox. The HSM layer is physically air-gapped — no network interface exists. Communication via QR code and USB only.
Bit Vault AG (trading as Bit Bank) operates under VQF (Verein zur Qualitätssicherung von Finanzdienstleistungen) — a FINMA-supervised Self-Regulatory Organisation for financial intermediaries. This ensures compliance with Swiss Anti-Money Laundering Act (AMLA) while maintaining the privacy standards that make Swiss banking unique. ZK-KYC allows us to verify identity for regulated services without storing personal documents on our systems.
Zero-Knowledge Proof Infrastructure
Groth16 ZK-SNARKs on XDC Network
Every layer of Bit Bank is protected by ZK-SNARK cryptographic proofs — the same zero-knowledge technology used by Zcash, Tornado Cash, and institutional blockchain systems. Our implementation uses Groth16 proving system with Poseidon hash functions and BN254 elliptic curve pairings. Proofs are generated client-side and verified on-chain, meaning your private data never leaves your device.
◆ZK Shield — Break on-chain links between deposits and withdrawals
◆ZK-KYC — Prove identity compliance without revealing personal data
◆ZK Proof of Reserves — Monthly solvency proof without exposing positions
◆ZK Dark Pool — OTC trades with zero information leakage
◆ZK Settlement — Cross-chain bridge with privacy preservation
◆Private Subnet — XDC sovereign chain, invisible to public explorer
Bit Bank Secure Network Architecture
How ZK proofs work: When you trade on Bit Bank, a cryptographic proof is generated on your device that says "this trade is valid" without revealing who traded, what amount, or at what price. The proof is verified on-chain by our Groth16 Verifier smart contract. The blockchain confirms validity — but learns nothing about the trade details. This is mathematically guaranteed privacy, not policy-based privacy.
Self-Custody Option
Your keys, your rules
Don't want us to hold any keys at all? Connect your own wallet — MetaMask, XDC Pay, WalletConnect, or any Web3 wallet — and trade directly. You maintain full self-custody with zero counterparty risk. Your keys never touch our servers. We provide the exchange, the liquidity, the tools — you provide your own security.
How we compare to the alternatives.
Feature
Coinbase
Bitcoin Suisse
Fireblocks
Bit Bank
Storage
Cloud data centres
Swiss data centre
Cloud MPC
Nuclear bunker (Swiss Fort Knox)
Quantum-proof
No
No
No
Kyber768 + Dilithium3
Privacy
None
None
None
ZK-SNARK + TOR + no IP logs
Key ownership
They hold keys
They hold keys
MPC shards
YOU own your keys
Physical security
Standard DC
Standard DC
None (cloud)
Armed guard + Faraday cage
Exchange built-in
Separate
Separate
No
32 assets + futures + options
AI portfolio manager
No
No
No
Included free
Visa card
Coinbase Card
No
No
Metal Visa + merchant PDQ
OTC Trading Desk
White-glove execution. USD 500K+ trades.
Personal dealer. Zero market impact. Privacy-first. For individuals, family offices, and institutions moving size.
✓ Trades from USD 500K to $50M+
✓ Personal dealer assigned to your account
✓ Zero market impact — off-exchange settlement
✓ ZK Dark Pool for complete privacy
✓ Competitive spreads: 0.05% — 0.15% (tiered)
✓ Settlement in xUSD, BTC, ETH, XDC, or stablecoins
Describe your issue and we'll assign a support agent. Average resolution: 4 hours.
Support Tiers
Standard
All users AI chat + email 4-hour response Ticket system
Custody
Deposited clients Priority tickets Phone support 1-hour response
Private
CHF 100K+ clients Direct WhatsApp Personal RM 30-min response
100
Launch Promo · First 100
Cards free. Credit included.
We pay for the card. Virtual gets €25 bonus credit on issue. Physical Metal gets €50.
37 / 100
slots left
Bit Bank Card
Reserve yours.Ship next week.
Virtual cards issue immediately to your Apple/Google Pay. Physical metal cards ship within 5 working days. Top up via the Bit Bank Telegram bot.
100
Launch Promo · First 100
PDQ terminals no deposit. No signup fee.
First 100 verified merchants get a Bit Bank PDQ shipped free. Just commit to the merchant agreement.
12 / 100
slots left
Merchant Terminal
Accept anything.From next week.
Bit Bank-branded PDQ terminals on Worldpay enterprise rails. Visa, Mastercard, Amex, Apple/Google Pay, BTC, ETH, USDC, USDT. One settlement file, T+1 next-day fiat, revenue share back.
PROMO
CHF 250
FREE
First 100 deposit
T+1
Next-day settlement
0.20%
Rev share rebate
~5d
Ship time
Custody · Banker Call
Satoshi test.
Before a senior advisor call, we ask for a tiny on-chain proof — you send a unique sub-cent transaction to an address we generate, in any major coin (BTC, ETH, XDC, USDC, USDT, SOL, TRX, BNB…). It cryptographically proves you control the wallet without exposing your balance to us. Your advisor sees verification status in real time.