In brief
- The incident occurred at Brevo, BitBox's external email provider, not in BitBoxApp or the hardware wallets.
- The exported BitBox contact data contained subscriber email addresses only.
- Names, postal addresses, payment details, order records and wallet secrets were not part of the exposed list.
- SIAMBC customers are not affected by this incident. Buying a BitBox from SIAMBC does not add anyone to BitBox's Brevo mailing list.
- Anyone who independently subscribed to BitBox emails should remain alert for follow-up phishing attempts.
BitBox has disclosed an email-address exposure involving Brevo, the external platform it uses for newsletters and tutorial emails. Attackers exploited a flaw in Brevo's single sign-on controls, accessed multiple customer accounts, sent phishing messages and exported contact lists. The incident did not compromise BitBox's internal systems, BitBoxApp, customer orders or BitBox hardware wallets.
What happened at Brevo
On 10 September 2026, an attacker abused a boundary failure in Brevo's SAML single sign-on implementation. A login created for one organisation was incorrectly able to reach other organisations available to an invited user. This was an access-control failure at the email platform rather than a compromise of newsletter subscribers' passwords.
Brevo says 138 customer accounts were accessed. Six were used to send phishing campaigns and contacts were exported from 43. BitBox was among the affected organisations. Two fraudulent campaigns claimed that a BitBox security flaw required urgent action and directed recipients towards a site designed to collect wallet recovery words.
Brevo detected the activity at 06:30 UTC, closed the attack route and signed out all users at 08:30 UTC. BitBox reported the campaigns, helped disable the malicious destinations and issued its own warning shortly after the first message.
What was exposed and what stayed secure
| Data or system | Current status |
|---|---|
| Email addresses on BitBox mailing lists | Exported from the Brevo account |
| Customer names, shipping addresses and order records | Not stored in the affected mailing list |
| Payment information | Not affected |
| BitBoxApp and BitBox internal systems | Not compromised by this incident |
| BitBox02 and BitBox02 Nova devices | Device security and firmware were not affected |
| Private keys, recovery words and balances | Not part of the newsletter system |
An email address cannot unlock a wallet or move coins. It can, however, help scammers target people with convincing messages that mention the right brand and manufacture urgency. The meaningful risk is a later attempt to obtain recovery words, prompt an unsafe transaction or install malicious software.
Why SIAMBC customers are not affected
Customers who purchased BitBox products from SIAMBC are not affected by this incident. SIAMBC order data is not stored in BitBox's Brevo account, and purchasing from SIAMBC does not automatically subscribe a customer to BitBox communications.
There is one important distinction: a SIAMBC customer who separately chose to subscribe to BitBox's newsletter, tutorial emails or affiliate communications could still have that independently supplied email address in the affected list. The purchase itself is not the source of exposure.
Why the phishing emails looked genuine
The messages were sent through legitimate Brevo infrastructure from an account used by BitBox. That allowed them to pass normal sender-authentication checks and made them harder to distinguish from an ordinary newsletter. A familiar sender name is therefore not enough to establish that a request is safe.
Judge the requested action instead. BitBox will not ask you to type recovery words into a website, install unsolicited wallet software, connect a hardware wallet for an emergency verification or transfer funds to a supposedly secure address.
What to do based on your situation
- You only received the email: delete it or report it as phishing. There is no need to reset your BitBox or move funds solely because the message arrived.
- You opened the link but entered nothing: close the page, do not download anything and check updates by typing the official BitBox address yourself.
- You installed software or approved an action: disconnect the device, stop using the supplied software and open a fresh support request through the official website.
- You disclosed recovery words: treat the wallet backup as compromised. Use a trusted device to prepare a new wallet and seek guidance through an independently opened official support channel. Never include the recovery words, passphrase, private key or PIN in the support request.
Neither BitBox nor SIAMBC will ask for recovery words, a seed phrase, private keys, a passphrase or a PIN by email, chat, telephone or support form.
Practical ways to reduce phishing risk
- Bookmark official product and support pages instead of following links in unexpected messages.
- Use a separate email address or privacy-preserving alias for crypto newsletters.
- Read the hardware-wallet screen before approving every transaction.
- Keep recovery words offline and out of photographs, cloud storage and password managers.
- When a message creates urgency, pause and verify it through a second independently opened channel.
BitBox hardware wallets
This email-provider incident did not change the security of the devices. Choose between the current BitBox models according to connectivity, mobile support and the backup workflow you are comfortable maintaining.

BitBox
- Works with computers, Android and iPhone
- OLED display with touch controls
- Multi and Bitcoin-only editions
Selected variant: Multi / Midnight Black

BitBox
- Open-source firmware
- microSD backup option
- Designed for computers and Android
Selected variant: Multi
Frequently asked questions
Was BitBox hacked?
BitBox's internal systems, BitBoxApp and the hardware wallets were not compromised. The affected system was Brevo, an external email provider used for subscriber communications.
Can an exposed email address put coins at risk?
An email address alone cannot move funds. The danger is a follow-up scam that persuades someone to reveal recovery words, approve a harmful transaction or install malicious software.
Should I reset my BitBox or move my funds?
Not if you only received the email and did not submit information, install software or approve anything. Receiving a message does not grant the sender access to your wallet.
Are customers who bought from SIAMBC affected?
No. SIAMBC customer and order data was not part of BitBox's Brevo account. Someone who separately subscribed to BitBox communications should still remain alert.
Will BitBox or SIAMBC ever ask for recovery words?
No. Legitimate support does not need wallet secrets to inspect a device, confirm an order or verify an account.
Conclusion
This was an email-list exposure at a third-party newsletter service, not a hardware-wallet breach. BitBox order data, internal systems, BitBoxApp and the devices were not affected. SIAMBC customers are outside the incident unless they separately subscribed to BitBox communications themselves.
The practical response is not to move funds impulsively. Watch for targeted phishing, verify communications through official channels and never enter recovery words into a website or share them with anyone.
Updated 27 September 2026. Sources checked: BitBox's disclosure and Brevo's official incident report. This article is provided for security education and does not constitute investment advice.






Share:
Bitget Confirms $351.6M Wallet Breach and Pauses Withdrawals: What Users Need to Know
Where to Buy Ledger in Thailand: Authenticity, Authorized Sellers and Warranty