In brief

  • The incident occurred at Brevo, BitBox's external email provider, not in BitBoxApp or the hardware wallets.
  • The exported BitBox contact data contained subscriber email addresses only.
  • Names, postal addresses, payment details, order records and wallet secrets were not part of the exposed list.
  • SIAMBC customers are not affected by this incident. Buying a BitBox from SIAMBC does not add anyone to BitBox's Brevo mailing list.
  • Anyone who independently subscribed to BitBox emails should remain alert for follow-up phishing attempts.

BitBox has disclosed an email-address exposure involving Brevo, the external platform it uses for newsletters and tutorial emails. Attackers exploited a flaw in Brevo's single sign-on controls, accessed multiple customer accounts, sent phishing messages and exported contact lists. The incident did not compromise BitBox's internal systems, BitBoxApp, customer orders or BitBox hardware wallets.

What happened at Brevo

On 10 September 2026, an attacker abused a boundary failure in Brevo's SAML single sign-on implementation. A login created for one organisation was incorrectly able to reach other organisations available to an invited user. This was an access-control failure at the email platform rather than a compromise of newsletter subscribers' passwords.

Brevo says 138 customer accounts were accessed. Six were used to send phishing campaigns and contacts were exported from 43. BitBox was among the affected organisations. Two fraudulent campaigns claimed that a BitBox security flaw required urgent action and directed recipients towards a site designed to collect wallet recovery words.

Brevo detected the activity at 06:30 UTC, closed the attack route and signed out all users at 08:30 UTC. BitBox reported the campaigns, helped disable the malicious destinations and issued its own warning shortly after the first message.

What was exposed and what stayed secure

Data or system Current status
Email addresses on BitBox mailing lists Exported from the Brevo account
Customer names, shipping addresses and order records Not stored in the affected mailing list
Payment information Not affected
BitBoxApp and BitBox internal systems Not compromised by this incident
BitBox02 and BitBox02 Nova devices Device security and firmware were not affected
Private keys, recovery words and balances Not part of the newsletter system

An email address cannot unlock a wallet or move coins. It can, however, help scammers target people with convincing messages that mention the right brand and manufacture urgency. The meaningful risk is a later attempt to obtain recovery words, prompt an unsafe transaction or install malicious software.

Why SIAMBC customers are not affected

Customers who purchased BitBox products from SIAMBC are not affected by this incident. SIAMBC order data is not stored in BitBox's Brevo account, and purchasing from SIAMBC does not automatically subscribe a customer to BitBox communications.

There is one important distinction: a SIAMBC customer who separately chose to subscribe to BitBox's newsletter, tutorial emails or affiliate communications could still have that independently supplied email address in the affected list. The purchase itself is not the source of exposure.

Why the phishing emails looked genuine

The messages were sent through legitimate Brevo infrastructure from an account used by BitBox. That allowed them to pass normal sender-authentication checks and made them harder to distinguish from an ordinary newsletter. A familiar sender name is therefore not enough to establish that a request is safe.

Judge the requested action instead. BitBox will not ask you to type recovery words into a website, install unsolicited wallet software, connect a hardware wallet for an emergency verification or transfer funds to a supposedly secure address.

What to do based on your situation

  1. You only received the email: delete it or report it as phishing. There is no need to reset your BitBox or move funds solely because the message arrived.
  2. You opened the link but entered nothing: close the page, do not download anything and check updates by typing the official BitBox address yourself.
  3. You installed software or approved an action: disconnect the device, stop using the supplied software and open a fresh support request through the official website.
  4. You disclosed recovery words: treat the wallet backup as compromised. Use a trusted device to prepare a new wallet and seek guidance through an independently opened official support channel. Never include the recovery words, passphrase, private key or PIN in the support request.

Neither BitBox nor SIAMBC will ask for recovery words, a seed phrase, private keys, a passphrase or a PIN by email, chat, telephone or support form.

Practical ways to reduce phishing risk

  • Bookmark official product and support pages instead of following links in unexpected messages.
  • Use a separate email address or privacy-preserving alias for crypto newsletters.
  • Read the hardware-wallet screen before approving every transaction.
  • Keep recovery words offline and out of photographs, cloud storage and password managers.
  • When a message creates urgency, pause and verify it through a second independently opened channel.

BitBox hardware wallets

This email-provider incident did not change the security of the devices. Choose between the current BitBox models according to connectivity, mobile support and the backup workflow you are comfortable maintaining.

BitBox02 Nova Multi in Midnight Black

BitBox

BitBox02 Nova

  • Works with computers, Android and iPhone
  • OLED display with touch controls
  • Multi and Bitcoin-only editions
Add to cart

Selected variant: Multi / Midnight Black

BitBox02 Multi Swiss hardware wallet

BitBox

BitBox02

  • Open-source firmware
  • microSD backup option
  • Designed for computers and Android
Add to cart

Selected variant: Multi

Frequently asked questions

Was BitBox hacked?

BitBox's internal systems, BitBoxApp and the hardware wallets were not compromised. The affected system was Brevo, an external email provider used for subscriber communications.

Can an exposed email address put coins at risk?

An email address alone cannot move funds. The danger is a follow-up scam that persuades someone to reveal recovery words, approve a harmful transaction or install malicious software.

Should I reset my BitBox or move my funds?

Not if you only received the email and did not submit information, install software or approve anything. Receiving a message does not grant the sender access to your wallet.

Are customers who bought from SIAMBC affected?

No. SIAMBC customer and order data was not part of BitBox's Brevo account. Someone who separately subscribed to BitBox communications should still remain alert.

Will BitBox or SIAMBC ever ask for recovery words?

No. Legitimate support does not need wallet secrets to inspect a device, confirm an order or verify an account.

Conclusion

This was an email-list exposure at a third-party newsletter service, not a hardware-wallet breach. BitBox order data, internal systems, BitBoxApp and the devices were not affected. SIAMBC customers are outside the incident unless they separately subscribed to BitBox communications themselves.

The practical response is not to move funds impulsively. Watch for targeted phishing, verify communications through official channels and never enter recovery words into a website or share them with anyone.

Updated 27 September 2026. Sources checked: BitBox's disclosure and Brevo's official incident report. This article is provided for security education and does not constitute investment advice.

Latest Stories

View all

Trezor Safe 3, Safe 5 and Safe 7 for managing Solana securely

Does Trezor Support Solana? Compatible Models, Tokens and Setup

Does Trezor support Solana? See which models work with SOL and SPL tokens, how to use Trezor Suite, stake SOL and transfer assets safely.

Read moreabout Does Trezor Support Solana? Compatible Models, Tokens and Setup

Bitwise NEAR ETF concept with the NEAR logo, exchange documents and a rising market chart

Bitwise NEAR ETF Moves Closer to Launch After NYSE Arca Approval

The Bitwise NEAR ETF has cleared major listing and registration milestones. Here is what NRR could mean for NEAR investors, direct ownership and SIAMBC customers.

Read moreabout Bitwise NEAR ETF Moves Closer to Launch After NYSE Arca Approval

Trezor Safe 3 and Trezor Safe 5 compared in a bright editorial product scene

Trezor Safe 3 vs Safe 5: Which One Is Better Value?

Compare Trezor Safe 3 and Safe 5 across security, display, controls, price and everyday use to find the right hardware wallet for your needs.

Read moreabout Trezor Safe 3 vs Safe 5: Which One Is Better Value?