If an unexpected email, letter, call, text message, social media message, or website claims to be BitBox and asks you to act, stop. Do not use its links, QR codes, downloads, phone numbers, or reply details. Choose the situation below that matches what has already happened.
BitBox never calls customers. If someone calls claiming to be from BitBox, end the call. BitBox Support communicates in writing.
Never share your wallet backup
Never enter your recovery words into a website, application, computer, smartphone, form, chat, or AI tool. BitBox Support will never ask for your recovery words or wallet backup. Exposed recovery words may allow an attacker to control wallets derived from that backup and move funds.
If you already entered or shared recovery words, go directly to If you entered recovery words or shared a wallet backup.
Choose what happened
You only received the message, letter, or call
Receiving suspicious contact does not by itself give the sender access to your wallet. Do not reply, scan a QR code, open an attachment, call a supplied phone number, or follow instructions from the communication.
If you did not interact, you do not need to reset your BitBox, move funds, or contact Support. If you would like BitBox to verify the contact, this is optional: open the official contact form independently and create a completely new inquiry.
For a structured check, continue with Check whether a BitBox contact is genuine.
You clicked a link or scanned a QR code but entered nothing
Close the page. Do not download or install anything, connect your BitBox, or approve an action on the device.
Continue with What to do after interacting with a phishing attempt.
You entered a password or other account information
Stop using the suspicious page. From a separate trusted device, independently open the official website of the affected email, exchange, broker, payment, or other account provider. Follow the account-information section of What to do after interacting with a phishing attempt. Never send BitBox Support the password or an authentication code.
You downloaded or opened a file, installed software, connected your BitBox, or approved an action
Do not open or run a downloaded file. If you already opened or ran it, installed software, or allowed remote access, stop using the affected computer for wallet, exchange, email, payment, or other sensitive activity. Disconnect your BitBox and approve nothing further.
Follow What to do after interacting with a phishing attempt, select the branch that matches what you did, and create a new Support inquiry through the independently opened official contact form.
You entered recovery words or shared a wallet backup
Treat the recovery words as compromised. They may allow an attacker to control wallets derived from that backup. If an optional passphrase is involved, never disclose it; tell Support only that one is used so the exact exposure can be assessed.
Go immediately to the recovery-words section of What to do after interacting with a phishing attempt. It explains when funds must be moved to a newly created wallet and which prerequisites must be met first.
Use a separate trusted device to open the official BitBox Support contact form and create a new inquiry. Never send Support recovery words, wallet backups, private keys, passwords, passphrases, PINs, or authentication codes.
You want to compare the contact with a known scam
See Known BitBox phishing and scam attempts for dated examples, including the September 2026 Brevo campaign, fake exchange-to-BitBox support calls, fraudulent websites, contact-form confirmation scams, and letters that use QR codes for supposed security or firmware updates.
What BitBox will never ask you to do
BitBox will never ask you to:
- reveal recovery words, a wallet backup, private keys, passwords, passphrases, PINs, or authentication codes;
- transfer funds to a “safe” or “secure” wallet as part of a support case;
- enter recovery words into a website or application;
- install remote-access software or unsolicited wallet software;
- continue a wallet-security case through an unsolicited phone call, callback, live session, or remote-access session;
- connect your BitBox to a website to verify, synchronize, restore, or secure the wallet; or
- update BitBox02 firmware outside the BitBoxApp.
BitBox02 firmware updates are delivered through the BitBoxApp. If a letter, message, caller, or website tells you to update the firmware anywhere outside the BitBoxApp, stop and do not follow those instructions. Use the official BitBox02 firmware update guide instead.
Verify BitBox contact independently
Do not verify suspicious contact using information contained in that same contact. Follow Check whether a BitBox contact is genuine, or compare an address with Official BitBox websites, email addresses, and support channels.
If the contact seems urgent and you are still uncertain, do not act under pressure. Open the official BitBox Support contact form yourself, create a completely new inquiry, and ask BitBox to verify the communication. BitBox can tell you whether it is genuine or fraudulent.
BitBox Support can help verify communications and product behavior, but it cannot access, freeze, move, or recover funds in your self-custody wallet.
Learn how scam emails work
For a deeper explanation of how fraudulent emails imitate trusted senders, create urgency, and try to obtain wallet backups, read Staying secure: understanding and identifying scam emails on the BitBox blog.
Report a phishing attempt
If you did not interact, reporting the attempt is optional. If you want to report it or ask whether it is genuine, independently open the official BitBox Support contact form and create a new inquiry rather than replying to the suspicious communication.
If you clicked, scanned, downloaded, installed, connected, entered information, or approved an action, follow the complete reporting guidance in What to do after interacting with a phishing attempt.
Include only non-sensitive sender details, website addresses, redacted evidence, and a short description of what happened. Never include wallet secrets.
If you received a phishing email, use your email application's export or print function to save the message as a PDF or text file and send it to BitBox Support with your report. Include the sender address, subject, date, and message text so we can document the attempt. Remove unrelated personal information and any secrets before sending it. Do not click links or open attachments in the email, and do not send suspicious attachments or software.