A new type of attack targeting innocent users has emerged in the cryptocurrency market. Here are the details. Continue Reading: Beware: A New Threat Targeting A new type of attack targeting innocent users has emerged in the cryptocurrency market. Here are the details. Continue Reading: Beware: A New Threat Targeting

Beware: A New Threat Targeting Cryptocurrency Users Has Emerged

2026/02/17 00:54
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

A new scam targeting cryptocurrency hardware wallet users has emerged.

Scammers are sending physical letters that appear to be from Trezor and Ledger, directing users to fake websites and aiming to obtain their seed phrases.

The letters sent as part of the campaign are designed to mimic official company letterhead. They state that users must complete a mandatory process called “Identity Verification” or “Transaction Verification” to avoid losing access to their wallets.

Scammers are giving specific deadlines to pressure users into hurrying and asking them to scan the QR code in the letter. These QR codes, in turn, redirect users to phishing sites that mimic the official Trezor and Ledger installation pages.

A fake Trezor email sent to cybersecurity expert Dmitry Smilyanets claimed that device functionality could be restricted if authentication verification wasn’t completed by February 15, 2026. Similarly, a Ledger-themed email shared on social media platform X asserted that a “Transaction Verification” process needed to be completed by October 15, 2025.

While the fake Ledger domain name linked via QR codes has been taken down, it was reported that the Trezor-themed site remained active for a while before being flagged as a phishing site.

Related News: Watch Out: Large Token Unlocking Events in 27 Altcoins This Week - Here's the Day-by-Day, Hour-by-Hour List

The fake Trezor page asks users to enter a 12, 20, or 24-word recovery phrase. The site claims this information is necessary to verify device ownership and activate the feature. However, the entered data is transmitted directly to the attackers via an API in the background.

This information allows attackers to transfer the victim’s wallet to their own devices and steal the crypto assets inside.

It’s unclear what criteria were used to send the letters. However, both Trezor and Ledger have experienced data breaches in recent years that exposed customer contact information. This strengthens the possibility that physical addresses may have fallen into the wrong hands.

Phishing attacks via physical mail are rare, but not entirely new. In 2021, attackers mailed modified Ledger devices designed to steal recovery emotes during setup. A similar campaign targeting Ledger users was also reported in April.

Seed phrases used in hardware wallets can be defined as the text equivalent of private keys and provide full access to the assets in the wallet. Anyone who possesses this phrase can control all the funds in the wallet.

Manufacturers like Trezor and Ledger never ask users to enter recovery phrases into a website, scan a QR code, or share them online. Recovery phrases should only be entered on the hardware device itself, in an environment not connected to the internet.

*This is not investment advice.

Continue Reading: Beware: A New Threat Targeting Cryptocurrency Users Has Emerged

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags: