Scammers target Trezor and Ledger users with fake mail letters

Threat actors are mailing physical letters impersonating Trezor and Ledger to trick cryptocurrency hardware wallet users into revealing recovery phrases. The letters create urgency by claiming mandatory checks are required to avoid losing wallet access. Victims scanning included QR codes are directed to phishing sites that steal their wallet information.

Cybercriminals have launched a phishing campaign using snail mail to target users of Trezor and Ledger hardware wallets. The letters, printed on fake official letterhead, pretend to come from the companies' security and compliance teams. They warn recipients of upcoming mandatory procedures, such as an "Authentication Check" for Trezor or a "Transaction Check" for Ledger, with deadlines of February 15, 2026, and October 15, 2025, respectively.

One such letter mimicking Trezor, received by cybersecurity expert Dmitry Smilyanets, states: "To avoid any disruption to your Trezor Suite access, please scan the QR code with your mobile device and follow the instructions on our website to enable Authentication Check by February 15th, 2026." It adds that even if users have already enabled the feature on their device, further action is needed for full synchronization.

A similar Ledger letter, shared on X, urges users to complete the check to prevent disruptions. The QR codes link to fraudulent websites, including trezor.authentication-check[.]io and ledger.setuptransactioncheck[.]com. These sites replicate official setup pages and pressure users to enter their 12-, 20-, or 24-word recovery phrases under the guise of verifying device ownership.

Once submitted, the phrases are sent to an attacker-controlled API at trezor.authentication-check[.]io/black/api/send.php, allowing thieves to access and drain victims' wallets. At the time of reporting, the Ledger site was offline, while the Trezor one was flagged by Cloudflare as phishing.

The targeting may stem from past data breaches at both companies, which exposed customer contact details. Trezor and Ledger emphasize that they never request recovery phrases via email, website, or mail. Recovery phrases, which represent private keys, grant full wallet control and should only be entered on the hardware device itself.

This physical phishing tactic is uncommon but echoes earlier incidents, including modified Ledger devices mailed in 2021 and a similar campaign against Ledger users in April.

Relaterte artikler

IT expert Supangat warns of Lebaran digital scams via WhatsApp and SMS in a press conference illustration.
Bilde generert av AI

IT expert warns of digital scams ahead of Lebaran

Rapportert av AI Bilde generert av AI

Ahead of Idul Fitri, IT expert from Untag Surabaya, Supangat, urges the public to heighten vigilance against scams via WhatsApp and SMS. Rising digital transactions are exploited by cybercriminals. Vida founder Niki Santo Luhur identifies two main methods: phishing and malware prevalent in Indonesia.

South Korean authorities accidentally revealed the recovery phrase for a cryptocurrency wallet in a press release, leading to the theft of nearly $5 million in seized assets. The National Tax Service issued an apology and launched an investigation into the breach. This incident highlights ongoing challenges in securing digital currencies by law enforcement.

Rapportert av AI

Scammers are sending emails that appear genuine to OpenAI users, designed to manipulate them into revealing critical data swiftly. These emails are followed by vishing calls that intensify the pressure on victims to disclose account details. The campaign highlights ongoing risks in AI platform security.

South Korean prosecutors in Gwangju have successfully recovered 320 bitcoin, valued at $22 million, that were lost due to a phishing scam. The incident occurred during an audit when staff used a fraudulent online wallet checking tool. Officials have identified the operator of the phishing site and blocked related transactions.

Rapportert av AI

Arizona Attorney General Kris Mayes has warned residents about a rise in cryptocurrency ATM scams, which cost victims more than $170 million last year. She launched a new fraud complaint form to help those affected report incidents quickly. The scams typically involve fraudsters directing people to deposit cash into bitcoin kiosks found at everyday locations like gas stations.

Dette nettstedet bruker informasjonskapsler

Vi bruker informasjonskapsler for analyse for å forbedre nettstedet vårt. Les vår personvernerklæring for mer informasjon.
Avvis