Owners of hardware wallets from Ledger and Trezor are being targeted in a new wave of offline phishing attacks, according to security researchers. Unlike traditionalOwners of hardware wallets from Ledger and Trezor are being targeted in a new wave of offline phishing attacks, according to security researchers. Unlike traditional

Ledger and Trezor Users Targeted in New Offline Phishing Campaign

2026/02/16 22:24
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Owners of hardware wallets from Ledger and Trezor are being targeted in a new wave of offline phishing attacks, according to security researchers.

Unlike traditional email or SMS scams, this campaign uses physical mail to reach victims, marking a shift from digital-only attacks to real-world correspondence. The letters impersonate official support teams and attempt to trick users into revealing their recovery seed phrases, which grant full control over crypto funds.

Security firms including SlowMist and Chainalysis have identified the structure of the scam and warned users to remain vigilant.

How the Physical Phishing Scam Works

Researchers have outlined several key stages:

1. Data Sourcing

Fraudsters are believed to use data from historical third-party breaches, including the 2020 Ledger marketing database leak, to obtain physical addresses of wallet owners.

2. The “Official” Letter

Victims receive professionally printed letters featuring authentic-looking Ledger or Trezor logos.
The letters often claim:

  • The device is “vulnerable”
  • The account has been “restricted”
  • Immediate action is required due to “new regulations”
  • Ledger

3. The Urgent Call to Action

The letter includes a URL or QR code directing users to a fake “Support Portal.”

4. The Seed Phrase Trap

Once on the fraudulent website, users are prompted to enter their 24-word recovery seed phrase to “authenticate” or “upgrade” their device.

Entering the seed phrase instantly compromises the wallet.

Why This Tactic Is Dangerous

Physical mail carries a level of perceived legitimacy.

By bypassing spam filters, phishing detection tools, and email security systems, scammers are reaching victims directly in their homes. The psychological impact of an official-looking printed document increases the likelihood of trust and compliance.

This represents a strategic evolution in phishing methods.

Strategy Reveals Why It Can Survive an 88% Bitcoin Crash

The Golden Rule of Hardware Wallets

Never, under any circumstances, enter your recovery seed phrase into a computer, phone, or website.

Your seed phrase should only ever be entered directly into your hardware wallet device during a legitimate recovery process.

If any website asks for it, it is a scam.

Critical Safety Checklist

FeatureOfficial SupportScammer Tactics
CommunicationOfficial ticket systems or verified emailPhysical letters, unsolicited calls, SMS
Seed Phrase RequestNever asks for seed phraseEventually requests seed phrase
Device ReplacementOfficial RMA processSends unsolicited “free” replacement devices
ToneProfessional and informationalFear-based urgency (“Funds will be lost”)

What to Do If You Receive a Letter

  • Do not visit the URL – do not scan QR codes or type the link manually.
  • Verify via official apps – open Ledger Live or Trezor Suite. Legitimate security alerts will appear there.
  • Report the letter – send a photo to official support channels at support.ledger.com or trezor.io/support.

Hardware wallets remain secure when used correctly. The vulnerability lies not in the device, but in social engineering attempts designed to trick users into surrendering their private keys.

The post Ledger and Trezor Users Targeted in New Offline Phishing Campaign appeared first on ETHNews.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.