Beware of Fake Letters

Fake QR letters steal recovery phrases and drain crypto wallets.

Beware of Fake Letters

The issue of fraudulent messages targeting hardware wallet users has already been discussed several times on Otokrypto. In recent weeks, the problem has resurfaced with greater intensity, as criminals have introduced yet another method to steal sensitive data.

Cybercriminals are now sending physical letters to users of Trezor and Ledger devices, impersonating the manufacturers. The letters encourage recipients to scan a QR code that leads to carefully crafted phishing websites.

The attackers claim that users must complete a mandatory “Authentication Check” or “Transaction Check.” In the case of Trezor users, a deadline is often set for the end of the month to create a sense of urgency. The letters appear official and warn that failure to act may result in limited device functionality or issues accessing Trezor Suite.

The fake websites then prompt users to enter their 24-, 20-, or 12-word recovery phrase. Under the pretense of verifying device ownership, this sensitive information is handed directly to criminals. Once the recovery phrase is entered, attackers gain full control of the wallet and can quickly drain all funds stored on it.

Both Trezor and Ledger have experienced data breaches in recent years that exposed customers’ contact information. This may have made it easier for criminals to prepare and execute these targeted mail campaigns.

Security experts emphasize that hardware wallet manufacturers will never ask users to provide, scan, or submit their recovery phrase. It should only ever be entered directly on the device itself when restoring a wallet — never on a website or in an application.

Anyone who has access to a recovery phrase effectively has full control over the wallet and its funds. For this reason, users should exercise extreme caution toward any correspondence urging immediate action.

Share