Hardware wallet users are facing a phishing tactic that moves beyond email and fake apps. Scammers are sending physical letters disguised as official notices to Ledger and Trezor customers, using QR codes to direct recipients to spoofed websites that ask for wallet recovery phrases and lead to stolen funds.
Fake verification letters made to look official
Security researcher Dmitry Smilyanets reported on February 13 that he received a physical letter posing as an official Trezor notice. The document told the recipient to complete an “Authentication Check” by February 15 or face device restrictions. It was designed to appear credible, complete with a hologram sticker and a QR code. One obvious mistake gave it away: the letter incorrectly identified Trezor CEO Matěj Žák as the “Ledger CEO,” showing that the scam reused branding elements across companies.
Scan the code, enter the phrase, lose the wallet
The attack flow is simple. After scanning the QR code, users land on a fake Ledger or Trezor setup page that asks for a 12-, 20-, or 24-word recovery phrase, claiming it is needed to verify ownership of the device. Once entered, the phrase is sent through a backend API to the attackers in real time, allowing them to import the wallet and drain assets.
No legitimate hardware wallet provider will ask for a recovery phrase through a website, email, or mailed letter. That remains the core rule users need to remember. If the phrase is exposed, control of the wallet is effectively gone.
Bear market conditions make social engineering easier
Deddy Lavid, CEO of cybersecurity firm Cyvers, said crypto scams do not shrink in a bear market. They adapt. He noted that users are more anxious during weak market conditions and are more likely to react quickly to fear-driven messages such as compliance alerts or wallet warnings. Physical mail works well in this setting because it borrows the appearance of an official notice and adds a deadline, pushing recipients to act before they stop to verify.
Past data breaches gave scammers a target list
The campaign is possible in part because of earlier customer data leaks tied to hardware wallet brands. Trezor disclosed a breach in January 2024 that affected nearly 66,000 customers. Ledger and its partners have also suffered major leaks that exposed customer mailing addresses. In 2021, scammers mailed fake Ledger Nano devices to victims of the 2020 Ledger breach. In April 2025, physical phishing letters with QR codes began targeting Ledger users, and in May 2025, a fake Ledger Live application was used to steal recovery phrases. Ledger had already warned users about letter-based phishing on its support site in October last year.
Three basic rules for users
The letters are built around trust and time pressure. The practical defenses are plain: do not scan QR codes from unexpected mail, do not enter a recovery phrase on any website, and do not respond to notices demanding verification before a deadline. If a message appears suspicious, users should verify it directly through the official sites, trezor.io or ledger.com.

