Stop communicating with the sender and do not take any further action through the suspicious message, letter, call, website, or application. Follow the section below that describes the most consequential action you already took.

Never send wallet secrets to Support

Never send recovery words, a wallet backup, private keys, passwords, passphrases, PINs, or authentication codes to BitBox Support or anyone else. BitBox can help assess what happened without receiving these secrets.

 

You only received the message, letter, or call

Receiving suspicious contact does not by itself give the sender access to your wallet.

  • Do not reply, click links, scan QR codes, open attachments, or call a supplied phone number.
  • Block the sender or caller.
  • Delete or safely archive the communication so that you do not interact with it accidentally.

No wallet reset, fund transfer, or Support inquiry is required solely because you received the communication.

If you want BitBox to verify it, this is optional. Manually open the official BitBox Support contact form, create a completely new inquiry, and describe what you received. Do not reply to the suspicious contact.


You received an unexpected support confirmation

A scammer may have entered your email address into a genuine support form. The resulting automated confirmation can be real even though you did not create the request.

  • Do not treat a separate caller, message, or conversation as legitimate because of the confirmation.
  • Do not reply to the unexpected confirmation or use case references, links, phone numbers, or employee details supplied by the other person.
  • If you did not otherwise interact, no wallet action is required.

If you want BitBox to verify or close the unexpected request, manually open the official contact form and create a completely new inquiry. State that you did not submit the earlier request. This verification is optional when nothing else happened, but it is the safest route if the situation appears urgent or remains unclear.


  • Close the page.
  • Do not download or install anything from it.
  • Do not connect your BitBox or approve an action requested by the page.
  • Remove the page from your browser history if that helps prevent opening it again accidentally.
  • Open the official BitBox website manually if you still need to complete a legitimate task.

Create a new inquiry through the official BitBox Support contact form and tell Support that you opened the link or QR-code destination but did not enter information. Include the website address without opening it again.

If you also downloaded a file, installed software, connected your BitBox, entered information, or approved an action, use the corresponding section below.


You downloaded a file but did not open it

Do not open or run the file.

  • Record the filename and the website or message it came from without revisiting the site.
  • Do not upload or forward the suspicious file unless BitBox Support gives you a specific safe submission method.
  • Remove the file when it is no longer needed as evidence.

Open the official contact form independently, create a new inquiry, and provide the filename, source address, and a redacted screenshot. Downloading a file without opening it is different from running or installing it; tell Support clearly that the file was not opened.

If you opened, ran, or installed the file, continue below.


You installed software or allowed remote access

  • End any active remote-access session.
  • Disconnect your BitBox and do not approve further actions.
  • Stop using the affected computer for wallet, exchange, broker, email, or payment activity.
  • If a remote-access session may still be active, disconnect the computer from the network.
  • Use a separate trusted device to contact BitBox and any affected account provider through their official websites.

Use the separate trusted device to open the official BitBox Support contact form and create a new inquiry. Describe the software, remote-access tool, and actions taken, but do not send the suspicious file or any wallet secret.

Full malware removal and computer recovery are outside the scope of this guide. Do not assume that uninstalling the visible application restores trust in the computer. Use qualified device-security assistance before using it again for sensitive financial activity.

If you also entered recovery words or approved a wallet action, follow that higher-risk section below.


You connected your BitBox to a suspicious website or application

  • Disconnect the BitBox.
  • Close the website or application.
  • Do not approve another action on the device.
  • Check the wallet only with the official BitBoxApp obtained from the official BitBoxApp download page.

The next response depends on whether you also entered recovery words, installed software, allowed remote access, or approved an action on the BitBox. Follow the applicable higher-risk section rather than treating the connection alone as proof that nothing else occurred.

Independently open the official contact form, create a new inquiry, and describe exactly what was connected and what, if anything, was displayed or approved on the BitBox. Do not include wallet secrets.


You approved an unexpected action or transaction

  • Stop using the suspicious website or application.
  • Open the official BitBoxApp and check the affected account and transaction history.
  • Record the transaction identifier and displayed status, but do not share wallet secrets.
  • Do not approve another action while you investigate.

Create a new inquiry through the official BitBox Support contact form so Support can help interpret BitBoxApp or device behavior.

If the action involved an exchange, broker, email, payment, or another external account, contact that provider through its independently opened official website. BitBox cannot freeze an external account or reverse a transaction confirmed on a blockchain.

If you are unsure whether a transaction was approved or broadcast, stop before taking further wallet action and ask Support to help interpret the non-sensitive information visible in the official BitBoxApp.


You entered recovery words or shared a wallet backup

Assume that the recovery words are compromised. Wallets derived from them without an additional uncompromised optional passphrase can be controlled by anyone who has the words.

If you use an optional passphrase, do not disclose it. Mention only that one is used in the new Support inquiry so the exact wallet exposure can be assessed.

If funds are held in a wallet exposed by those recovery words and you can still access them, move them to a newly created wallet with new recovery words and a new backup that have never been exposed. Follow How to move funds to a new wallet using a single BitBox02.

Do not reset the BitBox until you have met every prerequisite in the migration procedure. Do not send funds back to an address from the exposed wallet.

Use a separate trusted device to open the official BitBox Support contact form and create a new inquiry. Support can explain product behavior but cannot recover exposed recovery words, control the wallet, or reverse a confirmed transaction.


What to include in your new Support inquiry

Use only the official contact form opened independently. Do not reply to the suspicious communication or reuse its phone number, link, ticket code, or supposed employee contact.

Include only non-sensitive evidence:

  • sender address or phone number;
  • website address;
  • date and communication channel;
  • redacted screenshots or photographs;
  • filename of a suspicious download; and
  • a short description of what you clicked, scanned, downloaded, installed, connected, entered, or approved.

Never include recovery words, wallet backups, private keys, passwords, passphrases, PINs, or authentication codes. Cover personal information that is not needed to identify the attempt, and neutralize QR codes in screenshots unless Support provides a specific safe submission method.

The immediate response is complete when the suspicious interaction has stopped, you have followed the branch for the highest exposure, and any remaining uncertainty has been handed to the appropriate official support or account provider.