Trezor and Ledger Users Targeted by Fraudulent Physical Mail Scams

TheNewsCryptoPublicado a 2026-02-16Actualizado a 2026-02-16

Security researchers observed attackers mailing fraudulent letters to owners of Trezor and Ledger devices. The mailed letters appear to reference the recipient’s crypto wallet and urge action related to their seed phrase. Attackers designed the letters to look legitimate with custom details inside printed envelopes. Recipients often receive the mail after recent hardware purchases or online order tracking visibility.

The scam text instructs users to visit a malicious domain for “security updates” or hardware redemption offers. On the fraudulent site, visitors see prompts to enter their private seed words to “verify ownership” or “unlock assets.” Threat actors use the stolen seed phrases to transfer digital assets out of targeted wallets. Social engineering through physical mail increases victims’ trust in the scam’s authenticity.

Researchers highlighted that this tactic leverages data scraped from public records, retailer databases, or shipment notifications. Attackers can customize letters with names, partial wallet model details, and purported support contacts. This customization, therefore, makes physical mail scams more convincing than generic email or SMS phishing attempts. The mailed letters often warn of “urgent security notices” or “account closures” to pressure quick responses.

Security firms cautioned that hardware wallets protect only against remote hacks, not user-shared secrets. If users reveal their mnemonic seed phrases or private keys, attackers can bypass hardware protections entirely. Additionally, scammers may include QR codes that link directly to malicious seed collection forms. Users have reported receiving these letters weeks after their hardware wallet orders ship.

The refund or upgrade claims in the letters often entice users to take immediate action. Researchers said many victims misinterpret legitimate branding elements included in the scam envelopes. In some cases, attackers emulate official Ledger or Trezor support documentation. Physical mail allows scammers to bypass email spam filters and SMS fraud blocks.

How Users Can Protect Against Mail-Based Scams

Security experts urge hardware wallet users to treat unsolicited mail with suspicion. Users should verify any claim requiring seed phrase entry with official support channels. Legitimate wallet providers never ask for seed phrases, private keys, or recovery words for “verification.” If a mail notice appears urgent or threatening, recipients should cross-check order records and official support pages.

Users should also ensure that their shipment tracking notifications come from authorized retailer domains. Any third-party unsolicited offer relating to crypto assets should be avoided entirely. Criminal referrals increase for scam campaigns that combine personalized mail with fraudulent online forms. Reporting suspicious letters to law enforcement may help future investigations. Community forums also share examples of fraudulent mail to educate new hardware wallet buyers.

Highlighted Crypto News:

Upbit Lists Bittensor (TAO) with KRW, BTC, and USDT Trading Pairs

TagsCryptocurrencyLedgerScamScammersTrezor

Preguntas relacionadas

QWhat is the main tactic used by attackers to target Trezor and Ledger users according to the article?

AAttackers are mailing fraudulent physical letters that appear legitimate and reference the recipient's crypto wallet, urging action related to their seed phrase.

QHow do the scammers make the physical mail scams more convincing than generic phishing attempts?

AThey customize the letters with details like names, partial wallet model information, and purported support contacts, leveraging data scraped from public records, retailer databases, or shipment notifications.

QWhat is the primary risk if a user enters their seed phrase on the malicious website mentioned in the scam?

AThreat actors can use the stolen seed phrases to transfer digital assets out of the targeted wallets, bypassing hardware protections entirely.

QWhat should hardware wallet users do if they receive unsolicited mail that appears urgent or threatening?

AThey should treat it with suspicion, verify any claims through official support channels, and cross-check order records and official support pages, as legitimate providers never ask for seed phrases.

QWhy are physical mail scams able to bypass some common security measures according to the article?

APhysical mail allows scammers to bypass email spam filters and SMS fraud blocks, increasing the perceived authenticity and reach of the scam.

Lecturas Relacionadas

US Stocks Hit Record Highs: Why Isn't the Market Afraid of the Flames of War?

U.S. stocks hit a record high on April 15, with the S&P 500 closing at 7,022.95, just 77 days after its previous peak. This rebound occurred in only 11 trading days—far faster than recoveries following past crises like the COVID-19 pandemic (103 days) or the 2011 debt crisis (106 days). The market's rapid recovery is attributed to "ceasefire expectations" rather than deteriorating economic fundamentals. During the sell-off triggered by the U.S.-Israel military action against Iran in late February, the S&P 500 fell nearly 10%. However, the market rallied twice on ceasefire rumors—first on March 24 and again on April 8—even before any permanent peace deal was signed. Notably, the VIX fear index fell below pre-war levels, indicating that the market had repriced the conflict from an uncertainty to a calculable risk. Major financial institutions like JPMorgan reported record trading revenues of $11.6 billion in Q1 2026, largely driven by volatility in commodities and emerging markets. Hedge funds turned net long for the first time since late 2025, while margin debt hit a record $1.28 trillion. This reflects a financial system that commercializes volatility, treating geopolitical shocks as tradable opportunities rather than systemic threats. However, the current optimism relies on assumptions of a sustained ceasefire and stable oil prices, leaving the market vulnerable if these conditions change.

marsbitHace 26 min(s)

US Stocks Hit Record Highs: Why Isn't the Market Afraid of the Flames of War?

marsbitHace 26 min(s)

Is the Rebound an Illusion? The Bond Market Has Already Given the Answer

Is the stock market's rapid rebound to pre-war levels a sign of recovery or a misleading rally driven by momentum rather than fundamentals? While the S&P 500 has fully recovered its losses from the U.S.-Iran conflict and nears all-time highs, bond and oil markets tell a different story. Key data reveals contradictions: 10-year Treasury yields have risen 30 basis points, signaling persistent inflation concerns and constrained Fed policy space. WTI crude is up 37%, indicating that geopolitical risks are not priced to resolve soon. The 2-year Treasury yield, a sensitive gauge of rate expectations, has increased nearly 40 bps, challenging the narrative of imminent Fed rate cuts. The equity market appears to be pricing in a "perfect scenario": subdued oil impact on consumption, Fed rate cuts despite hot inflation, stable corporate margins, and near-term conflict resolution. However, bonds and oil reflect a reality of sticky inflation, limited Fed flexibility, and ongoing geopolitical tension. This divergence suggests the rally may be momentum-driven rather than fundamentally justified. If upcoming CPI data exceeds expectations (e.g., above 3.5%), the 2026 rate-cut narrative could collapse. Investors chasing the rally are betting on an ideal outcome—swift conflict resolution, controlled inflation, Fed easing, and resilient earnings—while ignoring signals from more cautious asset classes. The gap will likely close either through a fundamental improvement validating stocks or a market correction aligning with bond and oil realities.

marsbitHace 34 min(s)

Is the Rebound an Illusion? The Bond Market Has Already Given the Answer

marsbitHace 34 min(s)

Trading

Spot
Futuros
活动图片