Beware of Cold Wallets! Trezor and Ledger users are receiving physical letters containing phishing QR codes in succession.

ChainNewsAbmedia

Cryptocurrency scam techniques are once again evolving. Recently, multiple hardware wallet users, including those of Trezor and Ledger, have reported receiving physical letters disguised as official notices. The letters instruct recipients to scan a QR code for mandatory verification, but in reality, they are designed to trick users into entering their seed phrases, allowing attackers to steal assets. Such attacks are not new and highlight the ongoing risks of personal data leaks and social engineering scams.

Physical letters disguised as official notices demand “identity verification” within a deadline

Cybersecurity team Dmitry Smilyanets pointed out that several users received paper letters signed by Trezor or Ledger, claiming that they need to complete an “Authentication Check” or “Transaction Check” within a certain timeframe, or their devices may be restricted.

Reports indicate that the letters are meticulously crafted, featuring forged signatures, brand logos, anti-counterfeit stickers, and include a verification QR code. In some cases, the letters even bear the signature of Trezor CEO Matěj Žák.

Scanning the QR code directs to a fake website, prompting users to input their seed phrases

Dmitry Smilyanets reported that the QR codes in the letters lead recipients to malicious websites that mimic official pages, requesting users to enter their wallet seed phrases to complete a so-called “security verification.” Once the seed phrase is entered, the data is transmitted via backend APIs to the attackers, allowing them to import the wallet on other devices and transfer assets.

Both Trezor and Ledger emphasize that they never, and will never, ask users for seed phrases via websites, emails, or physical letters. Once seed phrases are leaked, control of the wallet is effectively lost.

Origin of the attack: Ledger’s past data breaches as a targeting list

The precision of these physical scam letters is linked to data breaches over the past years. In 2020, Ledger experienced a security incident involving its e-commerce partner Shopify, which exposed the names and physical addresses of hundreds of thousands of customers. In 2023, Ledger Connect Kit also suffered a supply chain attack. Early 2024, Trezor reported that contact information for 66,000 users was inadvertently leaked.

Just last month, Ledger was hacked through a third-party payment provider, Global-e, resulting in the exposure of user names and contact details. Although the company stated that private keys and payment information were not compromised, this data could still be used for phishing attacks. Even if the hardware wallet itself remains secure, leaked user data can be exploited repeatedly.

(Ledger’s third-party payment provider Global-e experiences data breach; official response: “Wallet hardware remains secure.”)

Evolving scam methods: from emails to physical social engineering

Recent attack trends show that phishing tactics are shifting from emails and fake customer service messages to counterfeit apps, fake hardware devices, and even physical letters. Physical mail reduces user suspicion, especially when designed to look highly authentic, making it easier to deceive recipients. These continuous attacks reflect the risks associated with data protection and reliance on third-party services within the crypto industry.

Dmitry Smilyanets warns that the most crucial defense for users remains a fundamental principle: “Never disclose your seed phrase to anyone under any circumstances.” Amid ongoing cybersecurity incidents, enhancing user awareness and securing supply chains will continue to be key challenges for the industry.

This article originally appeared on Chain News ABMedia: “Beware of Cold Wallets! Trezor and Ledger Users Receive Phishing QR Code Physical Letters.”

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

FBI:AI 深度伪造技术加剧政府冒充类诈骗,2024 年损失超 4 亿美元

随着人工智能技术的普及,政府冒充类诈骗案件上升,诈骗者利用深度伪造视频和语音合成手段增信。2024年,一起AI伪造会议的诈骗案导致损失约2亿港元。FBI报告显示,2024年相关投诉超1.7万起,损失逾4亿美元,公众需提高警惕。

GateNews5h ago

Charlie Lee cảnh báo nguy cơ lượng Bitcoin của Satoshi bị tấn công lượng tử

Charlie Lee warns that Satoshi Nakamoto's estimated 1.1 million BTC could be at risk from future quantum computing attacks. He highlights vulnerabilities in early Bitcoin wallets and urges the crypto community to adopt long-term security measures.

TapChiBitcoin6h ago

DOJ Disrupts SocksEscort Network Linked to Crypto Fraud

U.S. authorities disrupted SocksEscort, a major proxy network exploiting infected routers for cybercrime, leading to significant losses for victims. The operation emphasized international cooperation in tackling cybercrime infrastructure.

TodayqNews16h ago

Ethereum Poisoning Attacks: How to Protect Yourself From Scammers - U.Today

Address poisoning attacks on Ethereum users are increasingly automated, deceiving victims into sending money to fake wallets. Recent data reveals significant losses and highlights the economic incentives driving these attacks, emphasizing the need for caution among users.

UToday20h ago

China's State Network Information Center Releases OpenClaw Security Risk Warning, with Approximately 23,000 Active Assets in the Domestic Market

Data from China's National Internet and Information Security Notification Center shows that there are over 200,000 active OpenClaw internet assets worldwide, with about 23,000 located within China, primarily concentrated in areas with dense network resources. These assets are exposed to security risks, and the behavior of agents is difficult to control, which could result in serious consequences such as data deletion and information theft.

GateNews22h ago

Ethereum Fees Drop Triggers Surge in Scams? Address Poisoning Attacks Skyrocket, USDT Micro Transactions Spike 612%

As Ethereum transaction costs decline, address poisoning attacks are becoming increasingly frequent. Attackers create counterfeit similar addresses and conduct small-value transfers to trick users into sending funds to the wrong address. After the Fusaka upgrade, small-value transactions surged, causing massive losses. Although the success rate of attacks is low, attackers continue to carry out these schemes due to low costs. Users need to carefully verify addresses and remain vigilant against such risks.

GateNews03-13 07:14
Comment
0/400
No comments