Scammers target Trezor and Ledger users with fake mail letters

Threat actors are mailing physical letters impersonating Trezor and Ledger to trick cryptocurrency hardware wallet users into revealing recovery phrases. The letters create urgency by claiming mandatory checks are required to avoid losing wallet access. Victims scanning included QR codes are directed to phishing sites that steal their wallet information.

Cybercriminals have launched a phishing campaign using snail mail to target users of Trezor and Ledger hardware wallets. The letters, printed on fake official letterhead, pretend to come from the companies' security and compliance teams. They warn recipients of upcoming mandatory procedures, such as an "Authentication Check" for Trezor or a "Transaction Check" for Ledger, with deadlines of February 15, 2026, and October 15, 2025, respectively.

One such letter mimicking Trezor, received by cybersecurity expert Dmitry Smilyanets, states: "To avoid any disruption to your Trezor Suite access, please scan the QR code with your mobile device and follow the instructions on our website to enable Authentication Check by February 15th, 2026." It adds that even if users have already enabled the feature on their device, further action is needed for full synchronization.

A similar Ledger letter, shared on X, urges users to complete the check to prevent disruptions. The QR codes link to fraudulent websites, including trezor.authentication-check[.]io and ledger.setuptransactioncheck[.]com. These sites replicate official setup pages and pressure users to enter their 12-, 20-, or 24-word recovery phrases under the guise of verifying device ownership.

Once submitted, the phrases are sent to an attacker-controlled API at trezor.authentication-check[.]io/black/api/send.php, allowing thieves to access and drain victims' wallets. At the time of reporting, the Ledger site was offline, while the Trezor one was flagged by Cloudflare as phishing.

The targeting may stem from past data breaches at both companies, which exposed customer contact details. Trezor and Ledger emphasize that they never request recovery phrases via email, website, or mail. Recovery phrases, which represent private keys, grant full wallet control and should only be entered on the hardware device itself.

This physical phishing tactic is uncommon but echoes earlier incidents, including modified Ledger devices mailed in 2021 and a similar campaign against Ledger users in April.

Relaterade artiklar

Illustration depicting hackers hijacking Linux Snap Store apps to steal cryptocurrency recovery phrases, featuring a compromised Ubuntu laptop and digital seed phrase theft.
Bild genererad av AI

Angripare kapar Linux Snap Store-appar för att stjäla kryptovalutafraser

Rapporterad av AI Bild genererad av AI

Cyberbrottslingar har komprometterat betrodda Linux-applikationer på Snap Store genom att ta över utgångna domäner, vilket låter dem distribuera skadlig kod som stjäl kryptovalutagenereringsfraser. Säkerhetsexperter från SlowMist och Ubuntu-bidragsgivare Alan Pope belyste attacken, som riktar sig mot etablerade utgivarKonton för att sprida skadliga uppdateringar som utger sig för populära plånböcker. Canonical har tagit bort de påverkade snapparna, men krav på starkare skyddsåtgärder kvarstår.

A cryptocurrency investor lost over $282 million in Bitcoin and Litecoin after scammers impersonated Trezor support to steal a recovery seed phrase. The theft, revealed on January 16, 2026, by investigator ZachXBT, involved 1,459 Bitcoin and 2.05 million Litecoin stolen on January 10. The attacker laundered funds through Thorchain and converted them to Monero, causing the privacy coin's price to surge 36%.

Rapporterad av AI

Sydkoreanska myndigheter avslöjade av misstag återställningsfrasen för en kryptoplånbok i ett pressmeddelande, vilket ledde till stöld av nästan 5 miljoner dollar i beslagtagna tillgångar. Nationala skattetjänsten utfärdade en ursäkt och inledde en utredning om brottet. Händelsen belyser pågående utmaningar med att säkra digitala valutor för rättsväsendet.

Following the 2022 LastPass data breach, blockchain firm TRM Labs has tied over $35 million in stolen cryptocurrency to Russian cybercriminals, detailing sophisticated laundering via mixers and exchanges persisting into late 2025.

Rapporterad av AI

The cryptocurrency industry experienced a significant reduction in hack-related losses last December, totaling $76 million, according to blockchain security firm PeckShield. This marks a 60% decrease from November's $194.2 million in damages. Despite the improvement, 26 major exploits still occurred, highlighting ongoing vulnerabilities.

Välbärgade kryptovalutainvesterare, som tidigare var kända för att skryta med sina förmögenheter, prioriterar nu integritet som svar på riktade utpressningsförsök kallade wrench attacks. Bloomberg-journalisten Olivia Solon undersöker denna förändring i den senaste Tech In Depth-nyhetsbrevet. Dessa attacker har alltmer fokuserat på kryptohållare på senare tid.

Rapporterad av AI

Authorities in Scottsdale, Arizona, have arrested two teenagers accused of attempting to steal $66 million in cryptocurrency from a local home, a plot they say was orchestrated through extortion. The suspects, who traveled from California, posed as delivery drivers before entering the residence and restraining occupants. The case draws parallels to a 'Black Mirror' episode involving coerced crimes.

 

 

 

Denna webbplats använder cookies

Vi använder cookies för analys för att förbättra vår webbplats. Läs vår integritetspolicy för mer information.
Avböj