Snail Mail Phishing Campaign Targets Trezor and Ledger Crypto Wallet Users

Related

Multiple US Healthcare Data Breaches Expose Millions of Patient Records

What happened Several major healthcare data breaches have been added...

Grafana Labs Refuses to Pay Ransom After Codebase Theft

What happened Grafana Labs confirmed over the weekend that an...

UK Water Company Fined After Hackers Lurked Undetected for Nearly Two Years

What happened The UK's Information Commissioner's Office fined South Staffordshire...

Škoda Online Shop Security Incident Exposes Customer Data

What happened Škoda Auto has disclosed a security incident affecting...

Share

What happened

Threat actors have launched a phishing campaign using physical mail to impersonate communications from hardware wallet providers Trezor and Ledger, attempting to steal cryptocurrency recovery phrases. The letters, printed on fake company letterhead, instruct recipients to complete an urgent “Authentication Check” or “Transaction Check” by scanning a QR code and visiting a fraudulent website. 

The phishing pages mimic legitimate wallet setup portals and prompt users to enter their recovery phrase under the pretense of verifying device ownership. Once entered, the recovery phrase is transmitted to attacker-controlled infrastructure, allowing threat actors to import the wallet and steal cryptocurrency funds. 

The targeting source is unclear, though both Trezor and Ledger have experienced past data breaches that exposed customer contact information. 

Who is affected

Customers of Trezor and Ledger hardware wallets who receive and interact with the phishing letters are affected, as submitting recovery phrases allows attackers to gain full control of cryptocurrency wallets.

Why CISOs should care

The campaign demonstrates how attackers are expanding phishing techniques beyond digital channels by using physical mail and trusted brand impersonation to obtain sensitive authentication credentials.

3 practical actions

  • Warn users about recovery phrase security. Ensure users understand recovery phrases must never be entered into websites or shared externally.
  • Monitor for phishing domain access. Detect connections to known fraudulent domains impersonating Trezor or Ledger services.
  • Review exposure from prior data breaches. Assess whether customer contact data may have been exposed and used for targeted phishing campaigns.
IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.