Owners of hardware wallets from Ledger and Trezor are being targeted in a new wave of offline phishing attacks, according to security researchers.
Unlike traditional email or SMS scams, this campaign uses physical mail to reach victims, marking a shift from digital-only attacks to real-world correspondence. The letters impersonate official support teams and attempt to trick users into revealing their recovery seed phrases, which grant full control over crypto funds.
Security firms including SlowMist and Chainalysis have identified the structure of the scam and warned users to remain vigilant.
Researchers have outlined several key stages:
Fraudsters are believed to use data from historical third-party breaches, including the 2020 Ledger marketing database leak, to obtain physical addresses of wallet owners.
Victims receive professionally printed letters featuring authentic-looking Ledger or Trezor logos.
The letters often claim:

The letter includes a URL or QR code directing users to a fake “Support Portal.”
Once on the fraudulent website, users are prompted to enter their 24-word recovery seed phrase to “authenticate” or “upgrade” their device.
Entering the seed phrase instantly compromises the wallet.
Physical mail carries a level of perceived legitimacy.
By bypassing spam filters, phishing detection tools, and email security systems, scammers are reaching victims directly in their homes. The psychological impact of an official-looking printed document increases the likelihood of trust and compliance.
This represents a strategic evolution in phishing methods.
Never, under any circumstances, enter your recovery seed phrase into a computer, phone, or website.
Your seed phrase should only ever be entered directly into your hardware wallet device during a legitimate recovery process.
If any website asks for it, it is a scam.
| Feature | Official Support | Scammer Tactics |
| Communication | Official ticket systems or verified email | Physical letters, unsolicited calls, SMS |
| Seed Phrase Request | Never asks for seed phrase | Eventually requests seed phrase |
| Device Replacement | Official RMA process | Sends unsolicited “free” replacement devices |
| Tone | Professional and informational | Fear-based urgency (“Funds will be lost”) |
Hardware wallets remain secure when used correctly. The vulnerability lies not in the device, but in social engineering attempts designed to trick users into surrendering their private keys.
The post Ledger and Trezor Users Targeted in New Offline Phishing Campaign appeared first on ETHNews.


