Crypto Fraud Goes Postal: Ledger Customers Hit By Seed Phrase Scam

Source Bitcoinist

Thieves have opened a new front against cryptocurrency users with fake letters delivered by regular postal mail targeting owners of Ledger hardware wallets.

The letters misleadingly tell recipients they need to confirm their private seed phrases for a “critical security update,” according to reports posted on social media site X on April 29.

Physical Letters Impersonate Official Communications

Tech pundit Jacob Canfield uncovered the scam when he received such a letter to his home address. The scammers use Ledger’s official logo and business address, and also a reference number to make it look legitimate. It tells the recipients to scan a QR code and input their wallet’s private recovery phrase, stating that this will authenticate their device.

The letter uses pressure measures, threatening that “failure to complete this required validation process may lead to limited access to your wallet and funds.”

Security professionals caution that anyone who does this would be essentially surrendering total control of their cryptocurrency assets to cybercriminals.

Recovery Phrases: Keys To Crypto Kingdoms

A seed phrase or recovery phrase is a list of up to 24 words that is the master key to a cryptocurrency wallet. Whoever comes into possession of this phrase has complete control of the corresponding wallet and is able to send all the funds to other wallets. These phrases are incredibly valuable for a target of scammers because of it.

The hardware wallet firm also confirmed the letters were fake. Ledger issued the following statement after Canfield’s post:

“Ledger will never call, DM [direct message], or request your 24-word recovery phrase. If it happens, it’s a scam.”

The firm also warned customers against interacting with accounts purporting to be Ledger staff or anyone that provides assistance with fund recovery.

Possible Connection To Previous Data Breach

The mail scam can be linked to a significant security hack that occurred close to five years back. Hackers in July 2020 compromised Ledger’s database and revealed the personal details of over 270,000 clients.

This is not the first time physical mail has been used by criminals to target users of cryptocurrency. In a 2021 Bleeping Computer report, several Ledger users reported receiving fake Ledger devices in the mail. Those fake devices were programmed to drop malware when plugged into a computer.

The stolen data comprised names, phone numbers, and residence addresses – data through which this mail scam would be feasible.

Canfield made this link in his social media announcement, pointing out that scammers seem to be targeting Ledger users whose information was hacked in that breach.

The most recent mail scam is a development in strategy, a mix of conventional mail fraud with cryptocurrency theft strategies.

Security researchers recommend that the owners of hardware wallets keep in mind that any legitimate firm will never request recovery phrases under any circumstances, even if a message appears to be official.

Featured image from Joint Base San Antonio, chart from TradingView

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Natural Gas sinks to pivotal level as China’s demand slumpsNatural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
Author  FXStreet
Jul 01, 2024
Natural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
placeholder
Analysts Highlight 4 Reasons Why ETH Price Could Rebound Strongly in MayEthereum (ETH) has declined for five consecutive months. However, it enters May with rising optimism.
Author  Beincrypto
May 07, Wed
Ethereum (ETH) has declined for five consecutive months. However, it enters May with rising optimism.
placeholder
Avalanche Price Forecast: AVAX set to extend losses as Open Interest drops to one-month lowAvalanche (AVAX) trades in the green by almost 1% at press time on Wednesday, as it tests a crucial support floor that has held for over two months.
Author  FXStreet
Jun 18, Wed
Avalanche (AVAX) trades in the green by almost 1% at press time on Wednesday, as it tests a crucial support floor that has held for over two months.
placeholder
Gold price bulls seem reluctant amid hawkish Fed-inspired USD strengthGold price (XAU/USD) attracts some dip-buying during the Asian session on Thursday and recovers a part of the previous day's losses to the $3,363-3,362 area, or the weekly trough.
Author  FXStreet
Yesterday 03: 59
Gold price (XAU/USD) attracts some dip-buying during the Asian session on Thursday and recovers a part of the previous day's losses to the $3,363-3,362 area, or the weekly trough.
placeholder
Bitcoin Price Forecast: BTC on the verge of a breakdown amid possible US strike on IranBitcoin (BTC) price edges slightly higher, trading near $104,700 at the time of writing on Thursday, after stabilizing above a key level, the 50-day Exponential Moving Average (EMA) at $103,100.
Author  FXStreet
18 hours ago
Bitcoin (BTC) price edges slightly higher, trading near $104,700 at the time of writing on Thursday, after stabilizing above a key level, the 50-day Exponential Moving Average (EMA) at $103,100.
goTop
quote