Scammers Mail Fake Ledger and Trezor Letters to Steal Seed Phrases

Scammers use fake postal letters and QR codes to trick Trezor and Ledger users into revealing wallet seed phrases.

Crypto phishing attacks are no longer limited to emails and fake ads. Criminals are now sending physical letters to hardware wallet users. Mail looks official and urges quick action, aiming to trick people into giving away their recovery phrases and steal their funds.

Trezor and Ledger Users Warned Over QR Code Phishing Letters

Threat actors are sending letters to users impersonating Trezor and Ledger, two major hardware wallet manufacturers. Letters claim users must complete a required “Authentication Check” or “Transaction Check.” They warn that failing to do so could cause wallet access problems. Each letter includes a QR code that leads recipients to phishing websites.

Reports show that letters look official and use the company’s logos and branding. Meanwhile, both companies suffered past data breaches that exposed customer contact details. Stolen mailing information may have enabled campaign reach.

Cybersecurity expert Dmitry Smilyanets shared one of these fake letters in an X post. In that case, scammers impersonated Trezor and told users to complete an authentication check by February 15, 2026. Non-compliance supposedly meant disrupted access to Trezor Suite.

Moreover, the letter told users to scan a QR code with their phone and follow instructions on a website. It added pressure by saying action was required, even if the feature was already activated. The scammers’ aim was to make people act quickly without thinking.

A similar letter was targeted at Ledger users. It claimed a mandatory “Transaction Check” was coming soon. With the deadline set for October 15, 2025, the message warned that ignoring it could cause transaction problems.

Scanning QR codes led to fake websites that looked like official Trezor or Ledger pages. The ledger-related site later went offline, while the fake Trezor site stayed online but was identified as phishing by Cloudflare.

The fake Trezor page displayed a warning banner, urging users to complete authentication by February 15, 2026. An exception for certain newer Trezor Safe models purchased after November 30, 2025, was added on the page. The claim suggested those devices were preconfigured.

Further, the final page asked users to enter their wallet recovery phrase. The form allowed 12, 20, or 24 words. To confirm ownership, the site required a phrase to activate authentication. In reality, entering it would give scammers full access to the wallet.

Seed Phrase Safety in Focus as Offline Crypto Scams Rise

Physical phishing remains less common than email scams. However, postal campaigns have appeared before. In 2021, criminals mailed modified Ledger devices designed to capture recovery phrases during setup. Another wave of postal phishing targeting Ledger users surfaced in April.

Hardware wallet providers repeatedly warn customers never to share recovery phrases. No legitimate update or security check requires entering a seed phrase online. Companies do not request such data by mail, email, or phone.

Meanwhile, the growing sophistication of scams signals ongoing risk for crypto holders. Offline tactics may appear more credible to some users as printed letters can feel official and urgent.

As such, users should verify any security notices directly through official websites. Typing known web addresses manually is safer than scanning unknown QR codes. Suspicious letters should be reported to wallet providers and cybersecurity authorities immediately.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

OpenAI Launches "EVMbench": Testing AI's Ability to "Ensure Smart Contract Security"

As the security risks in cryptocurrency continue to rise, OpenAI is officially entering the blockchain security field. Led by CEO Sam Altman, OpenAI announced the launch of a new testing framework called "EVMbench," aimed at evaluating whether artificial intelligence has the practical ability to "understand, detect, and even repair" vulnerabilities in cryptocurrency smart contracts. OpenAI stated that EVMbench will focus on the security issues of smart contracts on Ethereum and Ethereum Virtual Machine (EVM) compatible chains. The ultimate goal is to establish a quantifiable and comparable evaluation standard for AI systems in the field of blockchain security. The so-called "smart contracts" refer to self-executing code deployed on the blockchain, widely supporting decentralized exchanges (DEX), lending protocols, derivatives protocols, and various on-chain financial applications. However, once these contracts are deployed, they are vulnerable to...

区块客1h ago

Data: The total trading volume of stablecoins in 2025 exceeds $35 trillion, with illegal activities accounting for less than 0.5%.

TRM Labs report shows that by 2025, stablecoin trading volume is expected to reach $35 trillion, with illegal activities accounting for 0.4%. Despite illegal transactions increasing to $141 billion, mainly focused on sanctions evasion and money laundering, legitimate use is growing rapidly. Stablecoins have become a core infrastructure, with the illegal usage rate of mainstream stablecoins being extremely low.

GateNewsBot2h ago

An address poisoning scam resulted in one victim losing $599,000 USDT.

PANews February 19 News, according to Cointelegraph citing @web3_antvirus, a poisoning scam involving an address led to a victim losing $599,000 USDT. The victim sent funds to a fake address copied from transaction records. The attacker embedded the fake address through a small transfer, mixing it with legitimate transaction records. The victim then copied the address and sent the funds to the attacker.

GateNewsBot3h ago

Korean prosecutors recover $21.4 million worth of stolen Bitcoin

Odaily Planet Daily reports that the Gwangju District Prosecutors Office in South Korea has recovered approximately $21.4 million worth of Bitcoin stolen from its custody last year. The assets were originally seized from a gambling platform and were stolen in August last year after investigators accidentally accessed a phishing website that exposed the seed phrase. Due to the prosecution blocking transactions on the related wallets, making it difficult to liquidate the assets, the hacker returned 320.8 Bitcoins to the official wallet on Tuesday. Currently, the South Korean prosecutors have transferred the recovered Bitcoin to a local exchange for safekeeping, and the hacker's identity remains unknown.

GateNewsBot4h ago

OpenEden: DNS hijacking issue has been resolved; smart contracts and reserve assets remain unaffected

The OpenEden platform has regained DNS control of the official website domain. Previously, due to unauthorized record modifications, the domain was hijacked. An investigation confirmed that there was no impact on smart contracts and asset security. Security measures will be strengthened.

GateNewsBot6h ago

Moonwell: Submitted recovery plan on governance forum and initiated partial compensation

DeFi lending protocol Moonwell incurred $1.78 million in bad debt due to an oracle configuration error. A recovery plan has been announced, including integrating the MFAM community into the WELL ecosystem, initiating partial compensation, and continuing compensation through protocol revenue. MFAM holders and stkWELL stakers will receive compensation at a ratio of 1:1.5.

GateNewsBot11h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)