Stop communicating with the sender and do not take any further action through the suspicious message, letter, call, website, or application. Follow the section below that describes the most consequential action you already took.
Never send wallet secrets to Support
Never send recovery words, a wallet backup, private keys, passwords, passphrases, PINs, or authentication codes to BitBox Support or anyone else. BitBox can help assess what happened without receiving these secrets.
You only received the message, letter, or call
Receiving suspicious contact does not by itself give the sender access to your wallet.
- Do not reply, click links, scan QR codes, open attachments, or call a supplied phone number.
- Block the sender or caller.
- Delete or safely archive the communication so that you do not interact with it accidentally.
No wallet reset, fund transfer, or Support inquiry is required solely because you received the communication.
If you want BitBox to verify it, this is optional. Manually open the official BitBox Support contact form, create a completely new inquiry, and describe what you received. Do not reply to the suspicious contact.
You received an unexpected support confirmation
A scammer may have entered your email address into a genuine support form. The resulting automated confirmation can be real even though you did not create the request.
- Do not treat a separate caller, message, or conversation as legitimate because of the confirmation.
- Do not reply to the unexpected confirmation or use case references, links, phone numbers, or employee details supplied by the other person.
- If you did not otherwise interact, no wallet action is required.
If you want BitBox to verify or close the unexpected request, manually open the official contact form and create a completely new inquiry. State that you did not submit the earlier request. This verification is optional when nothing else happened, but it is the safest route if the situation appears urgent or remains unclear.
You clicked a link or scanned a QR code but entered nothing
- Close the page.
- Do not download or install anything from it.
- Do not connect your BitBox or approve an action requested by the page.
- Record the website address without reopening it, then remove the page from your browser history if that helps prevent opening it again accidentally.
- Open the official BitBox website manually if you still need to complete a legitimate task.
A click or page display alone does not establish that your email account, computer, BitBox, or wallet was compromised. No wallet reset or fund transfer is required solely because you opened the page. If you are unsure whether something downloaded or opened automatically, or want BitBox to record the attempt, create a new inquiry through the official BitBox Support contact form.
If you also downloaded a file, installed software, connected your BitBox, entered information, or approved an action, use the corresponding section below.
You entered a password or other account information
Do not send the password, authentication code, or other account secret to BitBox Support. The response belongs to the provider that controls the affected email, exchange, broker, payment, or other account.
- Use a separate trusted device and independently open the provider's official website or application. Do not use a link or phone number from the suspicious contact.
- Change the affected password and any other account that reused it.
- Enable two-factor authentication and revoke unfamiliar or all active sessions where the provider offers these controls.
- Review recent activity, recovery details, connected applications, forwarding rules, and pending withdrawals or payments.
- Contact the provider through its official support route if access, a withdrawal, or another account action remains unresolved.
Clearing cookies or browser history does not remove malware and does not replace changing the password or revoking sessions through the provider. BitBox cannot secure an external account or cancel its pending withdrawal.
You downloaded a file but did not open it
Do not open or run the file.
- Record the filename and the website or message it came from without revisiting the site.
- Do not upload or forward the suspicious file unless BitBox Support gives you a specific safe submission method.
- Delete or quarantine the file when it is no longer needed as evidence, and empty it from the download location or trash without opening it.
If you are certain that the file was not opened or run, downloading it does not by itself establish that the computer is infected. If the browser may have opened it automatically or you remain uncertain, update the computer's built-in or otherwise trusted security software and run its full malware scan.
If you want BitBox to record the attempt, open the official contact form independently and provide the filename, source address, and a redacted screenshot. Downloading a file without opening it is different from running or installing it; state clearly that the file was not opened.
If you opened, ran, or installed the file, continue below.
You opened or ran a file, installed software, or allowed remote access
- End any active remote-access session.
- Disconnect your BitBox and do not approve further actions.
- Stop using the affected computer for wallet, exchange, broker, email, or payment activity.
- If a remote-access session may still be active, disconnect the computer from the network.
- Use a separate trusted device to contact BitBox and any affected account provider through their official websites.
- On the affected computer, update the operating system and its built-in or otherwise trusted security software, then run a full or offline malware scan where the operating system provides one.
Use the separate trusted device to open the official BitBox Support contact form and create a new inquiry. Describe the software, remote-access tool, and actions taken, but do not send the suspicious file or any wallet secret.
Full malware removal and computer recovery are outside the scope of this guide. Deleting the file, clearing browser data, uninstalling the visible application, or receiving a clean scan does not prove that the computer is free of malware. BitBox Support cannot inspect or certify the computer.
Use qualified device-security assistance before using the computer again for sensitive financial activity. If malware is detected, the scan cannot clean it, suspicious behavior continues, or you need the strongest practical recovery path, a qualified expert may recommend erasing the computer and reinstalling the operating system from a trusted manufacturer source. This is disruptive, can erase evidence, and can reintroduce malware if files are restored from an affected backup; it is not a routine response to clicking a link or merely downloading an unopened file.
If funds were stolen, law enforcement is involved, or the computer may contain evidence, do not delete files, reset, erase, or reinstall it until the responsible investigator or security professional tells you how to preserve that evidence.
If you also entered account credentials, recovery words, or approved a wallet action, follow the applicable higher-risk section as well.
You connected your BitBox to a suspicious website or application
- Disconnect the BitBox.
- Close the website or application.
- Do not approve another action on the device.
- Check the wallet only with the official BitBoxApp obtained from the official BitBoxApp download page.
The next response depends on whether you also entered account information or recovery words, opened or installed software, allowed remote access, or approved an action on the BitBox. Follow the applicable higher-risk section rather than treating the connection alone as proof that nothing else occurred.
Independently open the official contact form, create a new inquiry, and describe exactly what was connected and what, if anything, was displayed or approved on the BitBox. Do not include wallet secrets.
You approved an unexpected action or transaction
- Stop using the suspicious website or application.
- Open the official BitBoxApp and check the affected account and transaction history.
- Record the transaction identifier and displayed status, but do not share wallet secrets.
- Do not approve another action while you investigate.
Create a new inquiry through the official BitBox Support contact form so Support can help interpret BitBoxApp or device behavior.
If the action involved an exchange, broker, email, payment, or another external account, contact that provider through its independently opened official website. BitBox cannot freeze an external account or reverse a transaction confirmed on a blockchain.
If you are unsure whether a transaction was approved or broadcast, stop before taking further wallet action and ask Support to help interpret the non-sensitive information visible in the official BitBoxApp.
You entered recovery words or shared a wallet backup
Assume that the recovery words are compromised. Wallets derived from them without an additional uncompromised optional passphrase can be controlled by anyone who has the words.
If you use an optional passphrase, do not disclose it. Mention only that one is used in the new Support inquiry so the exact wallet exposure can be assessed.
If funds are held in a wallet exposed by those recovery words and you can still access them, move them to a newly created wallet with new recovery words and a new backup that have never been exposed. Follow How to move funds to a new wallet using a single BitBox02.
Do not reset the BitBox until you have met every prerequisite in the migration procedure. Do not send funds back to an address from the exposed wallet.
Use a separate trusted device to open the official BitBox Support contact form and create a new inquiry. Support can explain product behavior but cannot recover exposed recovery words, control the wallet, or reverse a confirmed transaction.
What to include in your new Support inquiry
Use only the official contact form opened independently. Do not reply to the suspicious communication or reuse its phone number, link, ticket code, or supposed employee contact.
Include only non-sensitive evidence:
- sender address or phone number;
- website address;
- date and communication channel;
- redacted screenshots or photographs;
- filename of a suspicious download; and
- a short description of what you clicked, scanned, downloaded, installed, connected, entered, or approved.
Never include recovery words, wallet backups, private keys, passwords, passphrases, PINs, or authentication codes. Cover personal information that is not needed to identify the attempt, and neutralize QR codes in screenshots unless Support provides a specific safe submission method.
The immediate response is complete when the suspicious interaction has stopped, you have followed the branch for the highest exposure, and any remaining uncertainty has been handed to the appropriate official support or account provider.