Trezor and Ledger Users Targeted by Fraudulent Physical Mail Scams

TheNewsCryptoPublicado em 2026-02-16Última atualização em 2026-02-16

Security researchers observed attackers mailing fraudulent letters to owners of Trezor and Ledger devices. The mailed letters appear to reference the recipient’s crypto wallet and urge action related to their seed phrase. Attackers designed the letters to look legitimate with custom details inside printed envelopes. Recipients often receive the mail after recent hardware purchases or online order tracking visibility.

The scam text instructs users to visit a malicious domain for “security updates” or hardware redemption offers. On the fraudulent site, visitors see prompts to enter their private seed words to “verify ownership” or “unlock assets.” Threat actors use the stolen seed phrases to transfer digital assets out of targeted wallets. Social engineering through physical mail increases victims’ trust in the scam’s authenticity.

Researchers highlighted that this tactic leverages data scraped from public records, retailer databases, or shipment notifications. Attackers can customize letters with names, partial wallet model details, and purported support contacts. This customization, therefore, makes physical mail scams more convincing than generic email or SMS phishing attempts. The mailed letters often warn of “urgent security notices” or “account closures” to pressure quick responses.

Security firms cautioned that hardware wallets protect only against remote hacks, not user-shared secrets. If users reveal their mnemonic seed phrases or private keys, attackers can bypass hardware protections entirely. Additionally, scammers may include QR codes that link directly to malicious seed collection forms. Users have reported receiving these letters weeks after their hardware wallet orders ship.

The refund or upgrade claims in the letters often entice users to take immediate action. Researchers said many victims misinterpret legitimate branding elements included in the scam envelopes. In some cases, attackers emulate official Ledger or Trezor support documentation. Physical mail allows scammers to bypass email spam filters and SMS fraud blocks.

How Users Can Protect Against Mail-Based Scams

Security experts urge hardware wallet users to treat unsolicited mail with suspicion. Users should verify any claim requiring seed phrase entry with official support channels. Legitimate wallet providers never ask for seed phrases, private keys, or recovery words for “verification.” If a mail notice appears urgent or threatening, recipients should cross-check order records and official support pages.

Users should also ensure that their shipment tracking notifications come from authorized retailer domains. Any third-party unsolicited offer relating to crypto assets should be avoided entirely. Criminal referrals increase for scam campaigns that combine personalized mail with fraudulent online forms. Reporting suspicious letters to law enforcement may help future investigations. Community forums also share examples of fraudulent mail to educate new hardware wallet buyers.

Highlighted Crypto News:

Upbit Lists Bittensor (TAO) with KRW, BTC, and USDT Trading Pairs

TagsCryptocurrencyLedgerScamScammersTrezor

Perguntas relacionadas

QWhat is the main tactic used by attackers to target Trezor and Ledger users according to the article?

AAttackers are mailing fraudulent physical letters that appear legitimate and reference the recipient's crypto wallet, urging action related to their seed phrase.

QHow do the scammers make the physical mail scams more convincing than generic phishing attempts?

AThey customize the letters with details like names, partial wallet model information, and purported support contacts, leveraging data scraped from public records, retailer databases, or shipment notifications.

QWhat is the primary risk if a user enters their seed phrase on the malicious website mentioned in the scam?

AThreat actors can use the stolen seed phrases to transfer digital assets out of the targeted wallets, bypassing hardware protections entirely.

QWhat should hardware wallet users do if they receive unsolicited mail that appears urgent or threatening?

AThey should treat it with suspicion, verify any claims through official support channels, and cross-check order records and official support pages, as legitimate providers never ask for seed phrases.

QWhy are physical mail scams able to bypass some common security measures according to the article?

APhysical mail allows scammers to bypass email spam filters and SMS fraud blocks, increasing the perceived authenticity and reach of the scam.

Leituras Relacionadas

Trade.xyz's Rebase Refusal Sparks Controversy, On-Chain Pre-IPO Market Faces Major Pricing Test

The debate surrounding Trade.xyz's refusal to adjust its SPCX (SpaceX pre-IPO) perpetual contract pricing amid updated share count revelations highlights a key challenge for on-chain pre-IPO markets. While several centralized exchanges (CEXs) paused and repriced their contracts after SpaceX's filing showed a ~10% increase in total shares, Trade.xyz maintained its market-driven pricing logic, which tracks expected per-share price sentiment rather than fundamental valuation metrics like market cap. This discrepancy triggered cross-platform arbitrage and caused leveraged long positions on Trade.xyz to suffer significant losses, as the platform's HIP-3 architecture lacks a native "Rebase" mechanism to neutrally adjust all user positions following such corporate actions. The incident underscores the difficulty for decentralized perpetual exchanges (Perp DEXs) to implement Rebase—a process CEXs handle by centrally pausing markets and adjusting ledger data. On-chain, this requires complex smart contract modifications, increasing gas costs, complexity, and potential attack surfaces. While some DEXs have managed similar adjustments, Trade.xyz's current design does not natively support it, though the team is reportedly exploring solutions for future events like stock splits. Ultimately, the controversy serves as a critical case study for the nascent on-chain pre-IPO sector, raising questions about price discovery reliability, transparent rule disclosure, and the readiness of DeFi infrastructures to handle traditional corporate actions as real-world assets (RWAs) gain traction.

marsbitHá 8m

Trade.xyz's Rebase Refusal Sparks Controversy, On-Chain Pre-IPO Market Faces Major Pricing Test

marsbitHá 8m

The 'Middle Eastern Prince' Swindles a Wealthy Woman: Renting Planes and Rolls-Royces, Scamming 120 Million Over Three Years

Two brothers who posed as "Middle Eastern princes" have been sentenced in the United States to 24 and 23 years in prison, respectively, and ordered to pay over $21.2 million in restitution and back taxes. Over three years, they fraudulently obtained approximately $21 million, primarily by promoting fictitious investment projects, including a non-existent cryptocurrency mining operation in a former General Electric industrial park in East Cleveland. The brothers, aged 42 and 33, created elaborate personas: one claimed to be a wealthy royal family heir and the city's "International Economic Advisor," while the other posed as a hedge fund manager with expertise from watching the TV show *Billions*. They bolstered their image by renting luxury cars and private jets and cultivating a relationship with a local mayor's chief of staff, who provided official-looking documents and government event access. A significant portion of the victims' funds, about $18 million, came from a single Chinese investor, a woman from Sichuan with experience in Bitcoin mining. The brothers also defrauded several women, including one former girlfriend. Their scheme unraveled when the primary investor discovered her $6 million worth of mining equipment had been sold off. The case highlights a trend of impostors using fabricated "Middle Eastern royal" identities to target wealthy individuals. Similar incidents include a "Dubai prince" who recently promoted a $500 million family office in Hong Kong and a Colombian man who impersonated a Saudi prince for decades in the US before being caught and sentenced in 2019.

marsbitHá 23m

The 'Middle Eastern Prince' Swindles a Wealthy Woman: Renting Planes and Rolls-Royces, Scamming 120 Million Over Three Years

marsbitHá 23m

a16z Partner: Being in the Flow of Capital Is the True Moat

A16z Partner: Standing in the Cash Flow is the True Moat Historically, many of the strongest companies built their moats by positioning themselves within "cash flows"—facilitating value creation and transfer in a network and taking a cut. The more value flows, the larger they grow. Crypto is the first modern technology natively built for this. With open ledgers, programmable settlement, and stablecoins enabling internet-speed global value transfer, it allows startups to inherit network effects from day one. Well-designed tokens align users, developers, and the protocol towards network growth, distributing value to contributors. This model isn't new (e.g., railroads, Visa, Google, AWS) but Crypto democratizes it. It lets entrepreneurs target areas with high inefficiency and profit extraction—like traditional finance's payments, custody, FX, and settlement—to compress costs, increase speed, and redistribute value by standing in the new flow. The opportunity extends beyond finance to emerging markets like GPU/compute, AI training data, energy, and space, where new, programmable infrastructure can be built without legacy constraints. Key questions for founders: Are you already in the cash flow? Does your revenue scale 10x with network activity? Where is profit extraction highest relative to value created in your market? The strategy is clear: compress the old cost structure, position yourself in the new value stream, and let the network compound.

marsbitHá 50m

a16z Partner: Being in the Flow of Capital Is the True Moat

marsbitHá 50m

Capturing 15 Top-Tier Zero-Day Vulnerabilities: A Consensus Protocol Debug Agent Framework Built by 0G Lab in Collaboration with Teams from NUS, PKU, and BUPT

"Agents Capture 15 Critical Zero-Day Bugs: 0G Lab's Multi-Agent Framework Automates Debugging in Consensus Protocols" Distributed consensus protocols are notoriously difficult to debug due to complex, intertwined states. A novel framework, Agora, developed by 0G Labs with researchers from NUS, Peking University, and Beijing University of Posts and Telecommunications, tackles this by fusing deep domain expertise with a collaborative multi-agent LLM architecture. Agora moves beyond the limitations of single LLMs and traditional testing like fuzzing. It employs three specialized agents: an Orchestrator for global state, a Strategy agent for generating attack scenarios using distributed systems knowledge, and a TestGen agent that creates executable tests. A core innovation is its efficient "Succinct Memory & Communication" mechanism and a dynamic test harness. This allows the system to translate abstract hypotheses into concrete tests across languages like Go and Rust, run them, capture failures, and refine the approach in a closed loop—all with minimal token overhead. In rigorous evaluations on production-level protocols including Raft, EPaxos, and components from etcd and Sui, Agora discovered 15 previously unknown deep logic bugs (e.g., execution divergence, liveness violations). In stark contrast, powerful standalone LLMs like GPT-5.2 and Claude 4.5 found zero such bugs. Agora achieved this with a high precision of 73.9% and at an average cost of only about $40 per bug found. The framework demonstrates high generalizability. Its decoupled design allows the "Multi-Agent + Hypothesis-Driven Testing" paradigm to be applied to other complex domains like database concurrency control, OS kernels, and Web3 smart contract auditing. By enabling efficient, automated detection of deep logic flaws, Agora points the way for AI-powered security in critical infrastructure, aligning with the growing trends of agentic systems and automated quality control.

marsbitHá 54m

Capturing 15 Top-Tier Zero-Day Vulnerabilities: A Consensus Protocol Debug Agent Framework Built by 0G Lab in Collaboration with Teams from NUS, PKU, and BUPT

marsbitHá 54m

Trading

Spot
Futuros
活动图片