Ledger and Trezor Users Targeted by Physical Mail Phishing for Recovery Phrases

Ledger and Trezor Users Targeted by Physical Mail Phishing for Recovery Phrases

N
News Editor 01
2026-07-24 10:25:16
Scammers are mailing fake official letters to Ledger and Trezor users, using QR codes and cloned setup pages to steal wallet recovery phrases. Security experts warn that no legitimate hardware wallet company will ever ask for a seed phrase.
LedgerTrezorrecovery phrasephishinghardware wallet

Hardware wallet users are facing a phishing tactic that moves beyond email and fake apps. Scammers are sending physical letters disguised as official notices to Ledger and Trezor customers, using QR codes to direct recipients to spoofed websites that ask for wallet recovery phrases and lead to stolen funds.

Fake verification letters made to look official

Security researcher Dmitry Smilyanets reported on February 13 that he received a physical letter posing as an official Trezor notice. The document told the recipient to complete an “Authentication Check” by February 15 or face device restrictions. It was designed to appear credible, complete with a hologram sticker and a QR code. One obvious mistake gave it away: the letter incorrectly identified Trezor CEO Matěj Žák as the “Ledger CEO,” showing that the scam reused branding elements across companies.

Scan the code, enter the phrase, lose the wallet

The attack flow is simple. After scanning the QR code, users land on a fake Ledger or Trezor setup page that asks for a 12-, 20-, or 24-word recovery phrase, claiming it is needed to verify ownership of the device. Once entered, the phrase is sent through a backend API to the attackers in real time, allowing them to import the wallet and drain assets.

No legitimate hardware wallet provider will ask for a recovery phrase through a website, email, or mailed letter. That remains the core rule users need to remember. If the phrase is exposed, control of the wallet is effectively gone.

Bear market conditions make social engineering easier

Deddy Lavid, CEO of cybersecurity firm Cyvers, said crypto scams do not shrink in a bear market. They adapt. He noted that users are more anxious during weak market conditions and are more likely to react quickly to fear-driven messages such as compliance alerts or wallet warnings. Physical mail works well in this setting because it borrows the appearance of an official notice and adds a deadline, pushing recipients to act before they stop to verify.

Past data breaches gave scammers a target list

The campaign is possible in part because of earlier customer data leaks tied to hardware wallet brands. Trezor disclosed a breach in January 2024 that affected nearly 66,000 customers. Ledger and its partners have also suffered major leaks that exposed customer mailing addresses. In 2021, scammers mailed fake Ledger Nano devices to victims of the 2020 Ledger breach. In April 2025, physical phishing letters with QR codes began targeting Ledger users, and in May 2025, a fake Ledger Live application was used to steal recovery phrases. Ledger had already warned users about letter-based phishing on its support site in October last year.

Three basic rules for users

The letters are built around trust and time pressure. The practical defenses are plain: do not scan QR codes from unexpected mail, do not enter a recovery phrase on any website, and do not respond to notices demanding verification before a deadline. If a message appears suspicious, users should verify it directly through the official sites, trezor.io or ledger.com.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.