Ledger and Trezor Letters Are Draining Wallets. Here's the Scam.

By Alexandr Kerya · · 4 min read

TL;DR - A physical letter with a fake wallet "authentication deadline" and a QR code is now how attackers steal Ledger and Trezor seed phrases, not phishing email.

Ledger's 2020 data breach didn't hand anyone a seed phrase. The letter now landing in hardware-wallet owners' mailboxes six years later is built to finish that job.

The campaign works because it skips every filter a reader has learned to trust. No spam folder, no suspicious sender address, no browser warning. Just an envelope with a real name and a real street address on it, both stolen years ago and both still worth using.

The Anatomy of the Scam Letter

The letter arrives printed on convincing letterhead, carrying a holographic-looking seal and a forged signature from a company executive. It claims a mandatory "Authentication Check" or "Transaction Check" must be completed by a set deadline, or the wallet will lose functionality. Real campaigns tracked by security researchers used October 15, 2025 for Ledger recipients and February 15, 2026 for Trezor recipients.

A QR code sits below the warning. Scanning it doesn't go to ledger.com or trezor.io. It routes to a lookalike domain, seen in the wild as ledger.setuptransactioncheck.com and trezor.authentication-check.io, styled to match the real onboarding flow pixel for pixel.

Neither company sends this kind of notice by mail. Never has.

Flow diagram of the Ledger and Trezor mail phishing scam in six steps: a 2020/2026 data breach leaks the victim's mailing address, a fake letter arrives with an authentication deadline, the victim scans the QR code, a lookalike site asks for the seed phrase, the attacker imports the seed phrase, and the wallet is swept with funds fanning out.
Six steps turn a years-old mailing-address leak into a drained wallet, starting with paper mail instead of email.

How Do You Know If a Letter Is Fake?

Ledger and Trezor have both confirmed, publicly, that they never request a recovery phrase by mail, email, or phone, and firmware or account changes only happen through the official app connected directly to the physical device. Any letter asking you to scan a code and then type or photograph a 12-, 20-, or 24-word phrase is the scam, full stop, regardless of how official the paper looks.

The tell isn't the branding. It's the request itself.

What Happens the Instant You Scan the QR Code?

The fake site asks for the recovery phrase under the guise of "verifying" the wallet. The moment those words are typed in, the attacker has everything needed to reconstruct the wallet's private keys on their own device, no signature or approval from the owner required. Assets typically move within minutes of the phrase being entered, often split across several new addresses before the owner even closes the browser tab.

This isn't a hack of the hardware device. The device was never touched.

What Should You Do If You Already Typed In Your Seed Phrase?

Treat that recovery phrase as burned, permanently, even if the wallet still shows a balance right now. Generate a brand-new seed on a hardware device, offline, and move any remaining funds there immediately, because the attacker can sweep the rest at any time. Never reuse the compromised phrase for anything, ever again.

Anyone can look up the destination address on a block explorer and watch, one transaction at a time, where the stolen funds move next. Screening that address with Plastron does the same check in seconds, surfacing sanctions, mixer, and stolen-funds exposure across Ethereum and six other chains in one pass instead of a manual, hop-by-hop lookup.

Where the Stolen Funds Usually Go

Drainer payouts rarely sit still. They tend to fan out across a handful of intermediate wallets, then bridge to another chain or route through a swap before landing somewhere the owner can cash out. A drainer's payout address often ends up inside Plastron's own dataset of 3,901 labeled addresses, most tagged scam or hack and exploit, cross-checked against the full 780-address OFAC SDN list. Once one address in a drainer's cluster gets labeled, every wallet downstream of it inherits the same flag.

That's the same pattern behind the Coldcard hardware-wallet hack, just triggered by a mailed letter instead of a firmware bug.

FAQ

Do Ledger or Trezor ever contact customers by physical mail about security?

No. Both companies have confirmed all legitimate security and firmware notices happen inside the official app, never through a letter, a QR code, or an unsolicited phone call.

Is my hardware device itself compromised if I received one of these letters?

No, the physical device isn't affected just by receiving mail. The wallet is only at risk if the recovery phrase was actually typed into the fake site the QR code leads to.

Can stolen crypto from this scam ever be recovered?

Rarely, and only if the funds land at an identifiable exchange deposit address before moving further, in which case a report to that exchange and law enforcement is worth filing. Funds that pass through a swap or a mixer first are effectively gone.

Why do these attackers have my real name and mailing address?

Most likely from a past data breach. Ledger's July 2020 breach exposed roughly 272,000 customers' physical addresses alongside their names, and a separate incident in January 2026 exposed customer contact data through a third-party payment processor. Either dataset is enough to print a convincing letter.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

The Coldcard Hack Drained $116M. Here's Where It's Hiding.How to Check and Revoke Risky Token Approvals on Your WalletHow to Audit Your Wallet for Tornado Cash Residue Before Sending to CEXCustodial vs Non-Custodial Wallets: Who Gets AML Screened?