The examples below are confirmed or observed BitBox-related scam patterns. Use them to recognize suspicious contact, but do not follow links, scan QR codes, call phone numbers, or open attachments from the communication you are checking.

If you already clicked, scanned, downloaded, installed, connected your BitBox, entered information, or approved an action, go directly to What to do after interacting with a phishing attempt. If you are still deciding whether a contact is genuine, follow Check whether a BitBox contact is genuine.


Fake Terms of Service and Privacy Policy update email

An observed phishing email claims that BitBox has updated its Terms of Service and Privacy Policy following a supposed company-name transition. It asks the recipient to review the documents by a deadline and threatens temporary restrictions on a “BitBox account” if the update is not acknowledged.

The email uses copied BitBox branding and real-looking company, product, partner, privacy, and support details. It also includes reassuring statements about self-custody and says that BitBox will never ask for a password or recovery phrase. These details are included to make the message appear credible; they do not authenticate the sender or its links.

The actual sender and document-review destination use an unofficial lookalike domain. The email directs the recipient to a review button and a supposed live-chat route.

This policy-update email is fraudulent

Do not use its document-review button, live-chat route, reply address, or any other link in the message. BitBox cannot restrict access to a self-custody wallet because you did not acknowledge an email.

 

A genuine BitBox email address written inside a message does not prove that the message itself is genuine. Check the complete sender and destination against Official BitBox websites, email addresses, and support channels.

If you only received the email and did not interact with it, no wallet action or Support inquiry is required. If you want BitBox to verify or record it, this is optional: independently open the official BitBox Support contact form and create a completely new inquiry. If you used a link, live chat, download, or form from the email, follow What to do after interacting with a phishing attempt.


Fake “Quantum Resistance” security-update letter

An observed postal phishing letter claims that BitBox users must complete a “Quantum Resistance security update”. It uses BitBox branding, the Shift Crypto AG company address, the recipient’s name and postal address, a deadline, and a QR code.

The letter threatens consequences such as limited BitBoxApp access, unavailable Clear Signing, or restricted future functionality if the recipient does not scan the QR code and complete the update.

This letter is fraudulent

Do not scan its QR code. BitBoxApp and BitBox02 firmware updates are delivered through the BitBoxApp. They are not activated through a QR code in an unsolicited postal letter.

 

This letter campaign is being distributed broadly and is not limited to BitBox customers or cryptocurrency users. BitBox has received inquiries from people who had never heard of BitBox, did not use BitBox products, and reported no connection to cryptocurrency.

Receiving a personalized copy therefore does not mean that the recipient owns a BitBox, has a crypto wallet, or was specifically targeted because of a customer relationship. It also does not by itself mean that a BitBox, wallet, or recovery words were compromised.

If you only received the letter and did not interact with it, no wallet action or Support inquiry is required. If you want BitBox to verify or record it, this is optional: manually open the official contact form and create a completely new inquiry.


Fake security or wallet warnings

These messages claim that:

  • your funds are in danger;
  • your wallet or “BitBox account” has been compromised;
  • your firmware is unsafe;
  • access will be blocked or restricted; or
  • an urgent verification, synchronization, migration, or security check is required.

The scam directs you to a link, attachment, QR code, phone call, chat, or supposed support employee. BitBox cannot freeze or unlock a self-custody wallet and will not ask you to complete an urgent wallet-security action through unsolicited contact.


Fake payment, transaction, or exchange alerts

A fraudulent email may appear to come from a payment provider, broker, or exchange. It can include a confirmation code for an unfamiliar transaction and a phone number to call if you did not request it.

The person answering may claim there was access from another country, that your device password was bypassed, or that your wallet is under attack. The phone number is part of the scam. Do not call it. Open the provider’s official website independently if you need to check the external account.


Contact-form confirmation scam

The scammer first contacts the recipient by phone, email, SMS, messenger, or another channel and learns which wallet, exchange, or broker they use.

The scammer then submits a real contact form on the official service using the recipient’s email address. The recipient receives a genuine automated confirmation from the official domain. The scammer uses that real confirmation, a ticket number, an employee name, or a supposed direct extension to make the original conversation appear legitimate.

A genuine automated confirmation does not authenticate a separate caller or message when you did not create the request. Do not reply to the unexpected confirmation or continue through the ticket information supplied by the scammer.

If you want BitBox to verify the situation, manually open the official BitBox Support contact form and create a completely new inquiry. State that you did not submit the earlier request. BitBox can confirm whether the communication is genuine or fraudulent. This is optional if you did not otherwise interact, but it is the safer route if the situation seems urgent or remains uncertain.


Fraudulent support calls and messages

The scammer impersonates BitBox or another provider through a phone call, SMS, Telegram, WhatsApp, Discord, social media, a forum, or a direct message. They may know personal details and ask you to keep the conversation private.

BitBox will not contact you first through these channels to discuss your wallet security. End and block the contact. Do not install software, provide remote access, connect your BitBox, transfer funds, or disclose information.


Fake BitBox websites and downloads

A fake website may copy BitBox branding, use a similar-looking address, or offer a malicious version of the BitBoxApp. It may ask you to restore, synchronize, verify, migrate, or unlock your wallet.

In one observed flow, a fake BitBox-branded “safety check” asked for the BitBox model and email address, declared the wallet compromised, and requested the 24 recovery words to generate a replacement backup.

A website cannot safely check, replace, or generate new recovery words for an existing wallet. Download the BitBoxApp only from the official BitBoxApp download page.


Exchange or broker escalation scam

After learning where a victim bought cryptocurrency, the scammer may impersonate that exchange or broker. They instruct the victim to convert assets into Bitcoin and send them to a wallet as part of a “security lock” or “account recovery”.

This is especially dangerous if the scammer already obtained the wallet’s recovery words, because those words may allow them to control wallets derived from that backup and move newly received funds.


Suspicious attachments and remote-access tools

Unexpected attachments may claim to contain security reports, account statements, wallet tools, update files, or recovery instructions. A scammer may also ask you to install a remote-support application so they can “secure” the computer or wallet.

Do not open the attachment or install the tool. BitBox will not send unsolicited wallet software or ask for remote access to perform wallet security work.


Learn how scam emails work

For general background about impersonation, urgency, malicious downloads, and recovery-word requests, read Staying secure: understanding and identifying scam emails on the canonical BitBox blog.


Choose the correct next step

  • If you have not interacted and still want to verify the contact, follow Check whether a BitBox contact is genuine. Verification is optional when nothing happened.
  • If you clicked, scanned, downloaded, installed, connected, entered information, or approved an action, follow What to do after interacting with a phishing attempt and create a new official Support inquiry.
  • If recovery words or a wallet backup were exposed, use the urgent recovery-words branch in the response article.

If you want to report a new or changed pattern without having interacted, this is optional. Use the official BitBox Support contact form, create a new inquiry, redact unrelated personal information, and neutralize QR codes before sharing screenshots unless Support provides a specific safe submission method.