Quick Summary
The Securityish Brief
Threat actors are targeting users of Trezor and Ledger, two prominent cryptocurrency hardware wallet manufacturers, with physical letters that impersonate official communications. These phishing letters create a false sense of urgency, claiming that users must complete an ‘Authentication Check’ or ‘Transaction Check’ by specific deadlines to maintain access to their wallets. For instance, a letter received by cybersecurity expert Dmitry Smilyanets warned Trezor users to complete the process by February 15, 2026, or risk losing functionality.
The letters instruct users to scan QR codes that lead to malicious websites. For Trezor, the phishing site is still live and claims that users must complete the authentication check by the specified date. A similar letter for Ledger warned users to enable a ‘Transaction Check’ by October 15, 2025, to avoid disruptions.
These phishing sites mimic official Trezor and Ledger pages, tricking users into entering their wallet recovery phrases, which are critical for accessing their cryptocurrency. Once entered, this sensitive information is sent to the attackers, allowing them to steal funds from the victims’ wallets.
Both Trezor and Ledger have previously experienced data breaches that exposed customer contact information, raising concerns about how these threat actors are selecting their targets. The phishing campaign highlights a growing trend of physical mail phishing, which remains relatively rare compared to email phishing.
Users must be vigilant, as these scams exploit the trust associated with established brands like Trezor and Ledger. The urgency created by these letters can lead to hasty decisions, increasing the risk of falling victim to such scams.
Why This Matters for Your Security
Understanding the tactics used in these phishing attacks is crucial for everyday users and organizations. The impersonation of trusted brands can make it challenging to discern legitimate communications from fraudulent ones. Users should remember that hardware wallet manufacturers will never ask for recovery phrases through email or physical mail.
As these scams evolve, users should be cautious of any unsolicited communications requesting sensitive information. Regularly monitoring accounts and being aware of the latest scams can help mitigate the risks associated with these types of attacks.
Key Takeaways
- Be cautious of any physical letters requesting sensitive information, especially from Trezor or Ledger.
- Never share your recovery phrase; it should only be entered directly on your hardware wallet.
- Verify any urgent requests by contacting the company directly through official channels.
- Regularly monitor your cryptocurrency accounts for any unauthorized transactions.
- Stay informed about the latest phishing tactics targeting cryptocurrency users.
Key Terms & Concepts
- Phishing: In this article, phishing refers to fraudulent attempts to obtain sensitive information by impersonating trusted entities.
- Recovery Phrase: A recovery phrase is a series of words used to restore access to a cryptocurrency wallet.
- Trezor: Trezor is a brand of hardware wallet used for securely storing cryptocurrencies.
- Ledger: Ledger is a manufacturer of hardware wallets designed to keep cryptocurrencies safe from theft.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.