On September 10, 2026, attackers exploited a security flaw at Brevo, the external provider we use for our newsletter and tutorial emails. They accessed our account, sent two phishing campaigns, and downloaded our contact list. The contact data exposed consisted of subscribed email addresses only.
Shop orders and customer order information are not affected. This incident did not compromise any of our internal systems, the BitBoxApp or BitBox hardware wallets.
The phishing emails falsely claimed a security flaw in the BitBox, and directed recipients to a website asking for their recovery words. We notified Brevo within the hour of this happening, and they quickly reacted by deactivating the links inside the phishing campaigns. The claim inside them was fabricated and you should not interact with this email, if you received it. Always remember that BitBox will never ask for your recovery words.
What happened at Brevo?
According to Brevo’s incident report, the vulnerability involved single sign-on (SSO), which lets users access services through a company login. Attackers set up their own Brevo organization with SSO and invited existing Brevo users. Using their own login system, they could then sign in as those users. Brevo incorrectly extended that access to other organizations those users could reach. Because of this failure to enforce separation between customer accounts, the attacker gained access to over 100 independent accounts, including other companies from the Bitcoin industry.

This flaw was therefore outside the control of BitBox, and therefore we had no chance to react until after the breach and subsequent phishing campaigns occurred.
Brevo reports that it identified the issue at 06:30 UTC and blocked the attack route at 08:30 UTC on September 10, signing out all users. No further attacker activity is reported after that time.
Phishing emails and our response
The attackers sent two campaigns from inside our Brevo account to our newsletter, affiliate and tutorial email lists:
- The first phishing campaign reached all newsletter and tutorial email subscribers.
- We sent our own phishing warning to our newsletter list within an hour of the first campaign.
- The second campaign contained the same message. It was stopped while sending, after reaching approximately half of the newsletter list.
We reported the phishing domains and had them taken down within minutes, shortening the time during which the websites could collect recovery words.
Because the messages went through Brevo’s legitimate infrastructure, they passed the usual email authentication checks, as Brevo explains in its report. In other words, the phishing emails appeared to have the same authenticity as an official newsletter, because technically they were.
Who is affected, and what was exposed?
Unfortunately, the breach affects the email addresses stored in our Brevo account for newsletter, affiliate and tutorial emails at the time of the incident. Brevo confirmed to us that the attackers downloaded the entire contact list, regardless whether a subscriber received the phishing emails or not.
The exported contact data contained email addresses only. As per our privacy policy, we do not share subscriber names, postal addresses, payment details or other order related information with Brevo.

Our webshop is self-hosted and we anonymize order information after 30 days. Placing an order does not make you affected by this breach. Only if you also opted in to subscribe to our newsletter, then the email address used for the subscription was exposed; your order information was not.
We want to emphasise that newsletter and tutorial subscriptions are always opt-in and you can use any email address you want. Our newsletter signup form explicitly names Brevo and explains that subscribers are handing an email address to an external provider outside BitBox’s control. We also recommend using an email alias containing no personal names to improve privacy.

An email address can reveal a name or be linked to information from other sources. Its presence on the BitBox mailing list can therefore help scammers tailor their messages. It does not give them access to your wallet or establish how much cryptocurrency you own, but it may result in an increased amount of phishing attempts sent to that address.
What should subscribers do?
If you only received the phishing email and did not interact with it, there is no need to reset your BitBox or move funds because of this incident. Delete or report the message and remain alert for follow-up attempts. Our phishing guidance explains what to do depending on whether you received a message, opened a link, installed software or shared information.
Never enter your recovery words into a website, the BitBoxApp, an email reply or a support form. Enter them only directly on your BitBox when restoring a wallet.
In case you entered your recovery words on the phishing website, please contact our support team for guidance on securing any remaining funds. Never include recovery words or wallet backups in your support request.
If you already used a temporary email alias with the BitBox news, we recommend deleting it and subscribing again with a fresh alias to avoid the risk of increased phishing attacks.
Why even use an external email provider?
Self-hosting email at scale is technically possible. However, delivering messages reliably to hundreds of thousands of inboxes, requires ongoing work on authentication, sending limits, spam complaints and sender reputation: the track record that receiving mail servers use to judge incoming email. Gmail’s requirements for bulk senders illustrate these demands. You can read more about it in this blog article.
Mass email is a highly centralized field. Running our own sending server would still leave us dependent on large mailbox providers and their delivery rules. In practice, meeting our requirements for reliable delivery makes relying on a relatively small pool of established sending providers difficult to avoid.
As we explained previously, operating our own services does not automatically give us the resources and expertise to deliver bulk email reliably. Not to mention that self-hosting our own email infrastructure may not protect us from becoming a target ourselves. We will continue to offer opt-in newsletter emails because they help subscribers learn about self-custody and receive product and security updates.
How we are proceeding
Although the vulnerability itself was very severe, Brevo responded quickly to this incident, locked out the attacker and provided a transparent explanation of the cause and containment measures. That response is a reason we are continuing with Brevo for now, while actively looking into alternatives.
In the current time of AI accelerated security research and more exploits than ever out in the wild, switching providers does not automatically guarantee better security. No provider can guarantee that this kind of security incident will never happen. Our approach remains to minimize the data we share, explain how it is used, and assess both a provider’s security and its response when something goes wrong.
For subscribers, the practical takeaway is to remain alert for further phishing and keep wallet backups private. Again, BitBox will never ask you to disclose your recovery words.
Don’t own a BitBox yet?
Keeping your crypto secure doesn't have to be hard. The BitBox hardware wallets store the private keys for your cryptocurrencies offline. So you can manage your coins safely.
Both the BitBox02 Nova and the BitBox02 also come in a Bitcoin-only edition, featuring a radically focused firmware: less code means less attack surface, which further improves your security when only storing bitcoin.
Buy the BitBox02 Nova or grab a BitBox02 in our shop!

Shift Crypto is a privately-held company based in Zurich, Switzerland. Our team of Bitcoin contributors, crypto experts, and security engineers builds products that enable customers to enjoy a stress-free journey from novice to mastery level of cryptocurrency management. The BitBox02, our second generation hardware wallet, lets users store, protect, and transact Bitcoin and other cryptocurrencies with ease — along with its software companion, the BitBoxApp!