If an unexpected email, letter, call, message, website, or download claims to be from BitBox, do not act through that communication until you have checked it independently. Do not use its links, QR codes, phone numbers, downloads, reply address, or support references to verify it.
A request for wallet secrets is always fraudulent
If anyone asks for recovery words, a wallet backup, private keys, a password, passphrase, PIN, or authentication code, stop. The request is fraudulent regardless of the sender name, branding, or apparent urgency.
If you already clicked, scanned, downloaded, installed, connected your BitBox, approved an action, or entered information, continue with What to do after interacting with a phishing attempt.
Start with what the contact claims
Treat the contact as fraudulent if it asks you to:
- reveal or type recovery words or a wallet backup;
- transfer funds to a “safe”, “secure”, or “protected” wallet;
- install remote-access software or an unsolicited version of the BitBoxApp;
- connect your BitBox to a website to verify, synchronize, restore, migrate, or secure it;
- approve a transaction or wallet action you did not initiate; or
- complete an urgent BitBoxApp or firmware update through a QR code, attachment, or separate download supplied by the sender.
Claims that your “BitBox account” has been compromised are also misleading. BitBox does not custody your funds and cannot freeze, unlock, move, or recover your self-custody wallet. BitBox Support cannot see or control your wallet and will not ask you to perform an urgent wallet-security action.
Check the communication channel
Check the complete sender address, not only the displayed name. Do not reply or follow an email link to verify the message.
Compare the sender with Official BitBox websites, email addresses, and support channels. A familiar address is not enough if the email is unexpected, creates pressure, or asks you to act on your wallet.
If you want BitBox to verify the email, independently open the official contact form and create a completely new inquiry. Do not reply to the suspicious email or continue through its links.
Letter or printed notice
Professional printing, BitBox branding, a Swiss company address, or your correct name and postal address do not prove that a letter is genuine.
BitBoxApp and BitBox02 firmware updates are delivered through the BitBoxApp. Do not scan a QR code in an unsolicited letter that claims you must complete a separate security or firmware update. Open the Support Hub yourself and use the official BitBox02 firmware update guide.
The observed fake “Quantum Resistance” letter has been sent broadly. BitBox has received inquiries from recipients who had never heard of BitBox, did not use BitBox products, and reported no connection to cryptocurrency. Receiving the letter therefore does not mean that the recipient is a BitBox customer or was individually selected because of a wallet.
Phone call, SMS, messenger, or direct message
BitBox will not contact you first by phone, SMS, Telegram, WhatsApp, Discord, social media, or a forum direct message to discuss your wallet security. End the contact and block the sender. Do not continue because the person knows your name, wallet brand, email address, phone number, or details about a supposed support ticket.
Website or download
A fraudulent website can copy BitBox branding and use a similar-looking address. Check the complete address and compare it with the official BitBox website and domain reference.
Download the BitBoxApp only from the official BitBoxApp download page. For additional verification, use the published procedures to verify the BitBoxApp signature or verify the BitBoxApp checksum.
Unexpected support confirmation
A scammer can submit a real contact form using your email address. You may then receive a genuine automated confirmation from the official service even though you did not create the request.
If you did not submit the request, the genuine confirmation does not make a separate caller, message, or conversation legitimate. Do not reply to the unexpected confirmation, use its case reference, or continue with the person who contacted you.
If you want BitBox to check the situation, manually open the official BitBox Support contact form and create a completely new inquiry. State that you did not create the earlier request and ask BitBox to verify it. BitBox can confirm whether the communication is genuine or fraudulent.
If you did not interact with the suspicious contact, this verification is optional. If something seems urgent or you remain uncertain, pausing and asking through a new official inquiry is safer than acting under pressure.
Warning signs that support the decision
Look for combinations of these signs:
- unexpected contact, urgency, threats, or a deadline;
- claims that funds are already being stolen or that access will be limited;
- a phone number you must call to cancel an unexpected transaction;
- claims about foreign logins, bypassed device passwords, blocked wallets, or urgent account locks;
- a support handoff with a ticket code, employee name, or direct extension you did not request;
- requests for secrets, screenshots, remote access, downloads, or wallet transfers;
- instructions to “verify”, “synchronize”, “secure”, “restore”, “migrate”, or “check” a wallet on a website; or
- links, attachments, or QR codes supplied through unexpected contact.
Spelling, grammar, branding, and personalization can provide context, but none of them proves that a communication is genuine.
Why you may have been contacted
Phishing campaigns are often distributed broadly rather than aimed only at known BitBox users. A recipient may have no BitBox product, no relationship with BitBox, and no connection to cryptocurrency. Scammers rely on reaching many people and finding the smaller number for whom the story appears relevant.
A personalized message also does not by itself mean that your BitBox, BitBoxApp, wallet, or recovery words were compromised. Scammers can combine public contact details, marketing lists, random dialing, social media information, unrelated third-party data leaks, and abused contact forms.
BitBox has disclosed past incidents that may explain some targeted contact:
- In July 2022, a breach at ActiveCampaign, a third-party marketing email provider, exposed email addresses and limited related data. Read the BitBox disclosure about the ActiveCampaign breach.
- A separate Twitter/X data leak exposed email addresses associated with Twitter accounts and may help scammers connect an address with public cryptocurrency-related activity. This was not a breach of BitBox systems. Read the BitBox statement about the Twitter/X leak.
Do not assume which source was involved in an individual case. For current information about support-data handling and deletion, see Why we delete your contact information and how we handle your data.
Verify through a new official inquiry
If you remain uncertain, open a new browser tab and manually enter contact.bitbox.swiss. Create a completely new inquiry and describe the communication you received. Do not reply to the suspicious contact or reuse its phone number, link, ticket code, or supposed employee contact.
If you did not interact, contacting Support is optional. If the communication appears urgent, asking BitBox through a new official inquiry before acting is the safer choice. If you already interacted, continue with What to do after interacting with a phishing attempt and contact Support through the new official inquiry.
The check is complete when you have either identified a categorical scam request and stopped, or BitBox has verified the communication through the independent inquiry.