Scammers Mail Fake Ledger and Trezor Letters to Steal Seed Phrases

Scammers use fake postal letters and QR codes to trick Trezor and Ledger users into revealing wallet seed phrases.

Crypto phishing attacks are no longer limited to emails and fake ads. Criminals are now sending physical letters to hardware wallet users. Mail looks official and urges quick action, aiming to trick people into giving away their recovery phrases and steal their funds.

Trezor and Ledger Users Warned Over QR Code Phishing Letters

Threat actors are sending letters to users impersonating Trezor and Ledger, two major hardware wallet manufacturers. Letters claim users must complete a required “Authentication Check” or “Transaction Check.” They warn that failing to do so could cause wallet access problems. Each letter includes a QR code that leads recipients to phishing websites.

Reports show that letters look official and use the company’s logos and branding. Meanwhile, both companies suffered past data breaches that exposed customer contact details. Stolen mailing information may have enabled campaign reach.

Cybersecurity expert Dmitry Smilyanets shared one of these fake letters in an X post. In that case, scammers impersonated Trezor and told users to complete an authentication check by February 15, 2026. Non-compliance supposedly meant disrupted access to Trezor Suite.

Moreover, the letter told users to scan a QR code with their phone and follow instructions on a website. It added pressure by saying action was required, even if the feature was already activated. The scammers’ aim was to make people act quickly without thinking.

A similar letter was targeted at Ledger users. It claimed a mandatory “Transaction Check” was coming soon. With the deadline set for October 15, 2025, the message warned that ignoring it could cause transaction problems.

Scanning QR codes led to fake websites that looked like official Trezor or Ledger pages. The ledger-related site later went offline, while the fake Trezor site stayed online but was identified as phishing by Cloudflare.

The fake Trezor page displayed a warning banner, urging users to complete authentication by February 15, 2026. An exception for certain newer Trezor Safe models purchased after November 30, 2025, was added on the page. The claim suggested those devices were preconfigured.

Further, the final page asked users to enter their wallet recovery phrase. The form allowed 12, 20, or 24 words. To confirm ownership, the site required a phrase to activate authentication. In reality, entering it would give scammers full access to the wallet.

Seed Phrase Safety in Focus as Offline Crypto Scams Rise

Physical phishing remains less common than email scams. However, postal campaigns have appeared before. In 2021, criminals mailed modified Ledger devices designed to capture recovery phrases during setup. Another wave of postal phishing targeting Ledger users surfaced in April.

Hardware wallet providers repeatedly warn customers never to share recovery phrases. No legitimate update or security check requires entering a seed phrase online. Companies do not request such data by mail, email, or phone.

Meanwhile, the growing sophistication of scams signals ongoing risk for crypto holders. Offline tactics may appear more credible to some users as printed letters can feel official and urgent.

As such, users should verify any security notices directly through official websites. Typing known web addresses manually is safer than scanning unknown QR codes. Suspicious letters should be reported to wallet providers and cybersecurity authorities immediately.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Protect Your XRP: 6 New Phishing Tactics Identified by XRPL Contributor Wietse Wind - U.Today

Wietse Wind, developer of the Xaman wallet, warns of a February 2026 scam campaign targeting the XRP community through six methods, including fraudulent sign requests, malicious NFTs, impersonation accounts, phishing emails, fake wallets, and token giveaways. Wind emphasizes the importance of user verification and caution.

UToday10h ago

Multi-chain lending protocol ZeroLend will gradually cease operations. Users are advised to withdraw their funds as soon as possible.

ZeroLend announces it will gradually cease operations due to the protocol's current situation being unsustainable, with declining liquidity and increased malicious activities. The team is prioritizing ensuring users can safely withdraw their assets and recommends users withdraw their funds as soon as possible.

GateNewsBot12h ago

Korean police custody of 22 involved BTC confirmed to have leaked, internal circulation routes and personnel involvement are under investigation

Odaily Planet Daily reports that 22 Bitcoins held by the Gangnam Police Station in South Korea during an investigation have been confirmed to have leaked. At current prices, this amounts to approximately 2.1 billion Korean won. These Bitcoins were voluntarily submitted assets received by the police during a case investigation in 2021. The investigation shows that the cold wallet entity was not hacked, but internal assets were transferred out. Law enforcement agencies are investigating the internal flow and possible internal involvement. It is understood that this was discovered during a nationwide investigation following the disclosure of the 320 Bitcoins theft at Gwangju District Prosecutors Office. (Donga)

GateNewsBot13h ago

XRPL Validator: Privacy Upgrades for XRP-Issued Assets Could Boost Adoption - U.Today

XRP Ledger validator Vet signals an opportune moment for future adoption with privacy features for Multi-Purpose Tokens (MPTs), enabling compliance through confidential transfers. Developer Wietse Wind warns users about a surge in scams targeting XRPL, urging vigilance against deceptive practices.

UToday14h ago

OpenEden official website DNS suspected of being hijacked! The team emphasizes "do not click the link" assets remain secure

OpenEden Tokenization Platform has discovered that the DNS of the official website and portal may have been tampered with. Users are advised not to interact with the related domains for now to prevent asset theft. All on-chain reserve assets remain secure, and users can verify the underlying asset status through Chainlink. The team is investigating and will provide further updates.

動區BlockTempo16h ago

OpenEden official website and portal DNS may have been attacked; users are advised not to visit the related domains.

OpenEden issued a statement stating that the DNS of its official website and portal may have been tampered with, warning users not to interact with the related domains to prevent asset loss. The team confirmed that reserve assets are secure and is investigating the incident.

GateNewsBot17h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)