How to protect yourself from phishing and smishing: Bit2Me security guide
⚠️ Active security alert: We are detecting active phishing (fake emails), smishing (fake SMS), and vishing (fake calls) campaigns impersonating Bit2Me. If you have received a suspicious communication, do not click on any links, do not call back, and do not share any data. Read this guide to learn how to identify them and what to do. |
At Bit2Me, your account security is our top priority. These attacks aim to steal your access data or funds by impersonating our company through three main channels: phishing (fake emails), smishing (fraudulent text messages), and vishing (fake phone calls). Below, we explain how they work and what measures you can take to protect yourself.
- What is phishing and how does it affect you?
- The 8 golden rules to identify and avoid fraud
- What should you do if you click on a suspicious link?
What is phishing and how does it affect you?
Phishing is a fraud technique where attackers send communications (emails, SMS, chat messages) that appear legitimate, imitating Bit2Me's visual identity and language. The main goal of these frauds is to get you to click on a malicious link or enter your credentials (password, 2FA codes) on a fake website.
The 8 golden rules to identify and avoid fraud
To secure your account, you should be familiar with Bit2Me's communication patterns and keep the following in mind:
Be wary of SMS messages asking you to act: smishing: Text messages are one of the most common vectors for fraud, precisely because they reach your mobile directly and create an immediate sense of urgency. This technique is known as smishing (SMS + phishing) and always follows the same pattern: an urgent-sounding message with a link asking you to do something now.
SUSPICIOUS: SMS messages that pretend to be from Bit2Me indicating that your account has been suspended, that there is a pending operation to confirm, or that you must verify your data immediately.
- SUSPICIOUS: Messages that include shortened links (bit.ly, tinyurl, or others) or domains that are not exactly https://bit2me.com.
SUSPICIOUS: SMS messages that include a phone number you must call to "resolve the problem".
OFFICIAL: Bit2Me will never send you an SMS with a direct link for you to log in, confirm security data, or authorize any operation. If you receive one, it is not from us.
Beware of fake calls: vishing: Scammers also impersonate Bit2Me over the phone. This technique is known as vishing (voice + phishing): they might know some of your personal data and can even spoof the number that appears on your screen to make the call seem real. Bit2Me may call you on certain occasions, but you should never call back the number that appears or any number provided to you during the conversation.
SUSPICIOUS: Calls asking you to "move your funds for security" to another account or wallet, or to add or confirm a new withdrawal address.
SUSPICIOUS: Calls asking for your password, your 2FA codes, or the verification codes you just received via SMS or email.
SUSPICIOUS: Calls that pressure you to act during the conversation itself or ask you to install an application on your mobile or computer.
WHAT TO DO: If you have any doubts, hang up and do not call back the displayed number. Contact us via WhatsApp or through official channels (support chat on our website or app) to confirm if the call was legitimate.
OFFICIAL: Bit2Me will never ask you for your credentials or 2FA codes over the phone, nor ask you to move your funds or confirm a withdrawal address during the call.
- Verify the email address: The most important indicator of authenticity is the sender's domain.
- OFFICIAL: Bit2Me communications always come from official verified domains, such as @bit2me.com.
SUSPICIOUS: Domains with typos or slight modifications (e.g., @bit2me-support.com, @bit2me.net, @bit2meapp.com).
Analyze links: Before clicking any link, hover your mouse over it (without clicking!):
OFFICIAL: The URL should direct you to the main domain: https://www.bit2me.com/ .
SUSPICIOUS: Any link that directs you to a URL other than the main domain (e.g., bit2me.xyz/login).
Tip: If in doubt, DO NOT CLICK. Instead, open your browser and manually type [www.bit2me.com](https://www.bit2me.com) to log in securely.
Urgency is a fraud tactic: Phishing and smishing attacks always try to create panic or urgency to make you act without thinking. If a message pressures you to act immediately, it's a clear red flag. Take a moment, breathe, and verify the source before doing anything.
SUSPICIOUS: Messages saying "Your account has been locked" or "Your balance will be suspended in 2 hours".
SUSPICIOUS: "We have detected unauthorized access to your account. Verify your identity now or you will lose access".
SUSPICIOUS: "Your €2,500 withdrawal is pending confirmation. If this wasn't you, cancel now".
Never share your credentials or 2FA codes: Bit2Me will never ask you for sensitive information via email, SMS, or call:
SUSPICIOUS: We will never ask for your password, recovery phrase (seed), or Two-Factor Authentication (2FA) codes through any external means.
Key Tip: If you receive a 2FA code or a verification code that you did NOT request, ignore the message. It's a sign that someone is trying to access your account. Do not click on any link attached to that message.
Use Bit2Me Verify for source confirmation: If a representative, partner, or external source claims to be Bit2Me, you can and should verify their authenticity:
KEY STEP: Confirm the authenticity of the source in question by using Bit2Me Verify at https://bit2me.com/es/verificacion
Important: Make sure it is an authorized Bit2Me representative. Avoid interacting with unauthorized or unverified sources, and do not share your account details with them.
Official contact channels only: Always use only the secure and verified channels to access and contact Bit2Me:
OFFICIAL: Always use the official website ([www.bit2me.com](https://www.bit2me.com)) and the official Bit2Me mobile application.
OFFICIAL: If you need further assistance, do not hesitate to contact the Bit2Me support team via the support chat available on our website or app, or through our official WhatsApp.
What should you do if you click on a suspicious link?
Immediate actions you can take:
- Change your password: If you have the slightest suspicion of having entered your data on a fake site, change your password immediately from the official website.
- Activate 2FA: Make sure you have Two-Factor Authentication (2FA) active on your account. It is the most important security layer.
- Report Phishing: If you receive a suspicious email or SMS, forward it to support@bit2me.com so our security team can investigate it and block the attacker.
Your account's security is a shared responsibility. |
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article