If an unexpected email, letter, call, text message, social media message, or website claims to be BitBox and asks you to act, stop. Do not use its links, QR codes, downloads, phone numbers, or reply details. Choose the situation below that matches what has already happened.
Never share your wallet backup
Never enter your recovery words into a website, application, computer, smartphone, form, chat, or AI tool. BitBox Support will never ask for your recovery words or wallet backup. Exposed recovery words may allow an attacker to control wallets derived from that backup and move funds.
If you already entered or shared recovery words, go directly to If you entered recovery words or shared a wallet backup.
Choose what happened
You only received the message, letter, or call
Receiving suspicious contact does not by itself give the sender access to your wallet. Do not reply, scan a QR code, open an attachment, call a supplied phone number, or follow instructions from the communication.
If you did not interact, you do not need to reset your BitBox, move funds, or contact Support. If you would like BitBox to verify the contact, this is optional: open the official contact form independently and create a completely new inquiry.
For a structured check, continue with Check whether a BitBox contact is genuine.
You clicked a link or scanned a QR code but entered nothing
Close the page. Do not download or install anything, connect your BitBox, or approve an action on the device.
Continue with What to do after interacting with a phishing attempt.
You downloaded or installed software, connected your BitBox, or approved an action
Disconnect your BitBox, close the suspicious website or application, and do not approve any further actions. Do not continue using software or remote-access tools provided through the suspicious contact.
Follow What to do after interacting with a phishing attempt, select the branch that matches what you did, and create a new Support inquiry through the independently opened official contact form.
You entered recovery words or shared a wallet backup
Treat the recovery words as compromised. They may allow an attacker to control wallets derived from that backup. If an optional passphrase is involved, never disclose it; tell Support only that one is used so the exact exposure can be assessed.
Go immediately to the recovery-words section of What to do after interacting with a phishing attempt. It explains when funds must be moved to a newly created wallet and which prerequisites must be met first.
Use a separate trusted device to open the official BitBox Support contact form and create a new inquiry. Never send Support recovery words, wallet backups, private keys, passwords, passphrases, PINs, or authentication codes.
You want to compare the contact with a known scam
See Known BitBox phishing and scam attempts for dated examples, including fake support calls, fraudulent websites, contact-form confirmation scams, and letters that use QR codes for supposed security or firmware updates.
What BitBox will never ask you to do
BitBox will never ask you to:
- reveal recovery words, a wallet backup, private keys, passwords, passphrases, PINs, or authentication codes;
- transfer funds to a “safe” or “secure” wallet as part of a support case;
- enter recovery words into a website or application;
- install remote-access software or unsolicited wallet software;
- connect your BitBox to a website to verify, synchronize, restore, or secure the wallet; or
- complete a BitBoxApp or BitBox02 firmware update by scanning a QR code in an unsolicited letter.
BitBox02 firmware updates are delivered through the BitBoxApp. If a letter, message, or website claims that a separate QR-code update is required, do not continue through that QR code. Use the official BitBox02 firmware update guide instead.
Verify BitBox contact independently
Do not verify suspicious contact using information contained in that same contact. Follow Check whether a BitBox contact is genuine, or compare an address with Official BitBox websites, email addresses, and support channels.
If the contact seems urgent and you are still uncertain, do not act under pressure. Open the official BitBox Support contact form yourself, create a completely new inquiry, and ask BitBox to verify the communication. BitBox can tell you whether it is genuine or fraudulent.
BitBox Support can help verify communications and product behavior, but it cannot access, freeze, move, or recover funds in your self-custody wallet.
Learn how scam emails work
For a deeper explanation of how fraudulent emails imitate trusted senders, create urgency, and try to obtain wallet backups, read Staying secure: understanding and identifying scam emails on the BitBox blog.
Report a phishing attempt
If you did not interact, reporting the attempt is optional. If you want to report it or ask whether it is genuine, independently open the official BitBox Support contact form and create a new inquiry rather than replying to the suspicious communication.
If you clicked, scanned, downloaded, installed, connected, entered information, or approved an action, follow the complete reporting guidance in What to do after interacting with a phishing attempt.
Include only non-sensitive sender details, website addresses, redacted evidence, and a short description of what happened. Never include wallet secrets.