A phishing campaign targeting Ledger and Trezor users is circulating as of May 2026, using forged physical letters with authentic-looking branding, holographic seals, and forged executive signatures. The letters request recipients scan a QR code for a mandatory “Authentication Check” or “Transaction Check” by a specified deadline, claiming wallet functionality will be lost otherwise. The QR codes redirect to fake domains (e.g., trezor.authentication-check.io, ledger.setuptransactioncheck.com) and request the recipient’s 24-, 20-, or 12-word recovery phrase; entering it allows attackers to drain all wallet assets. The campaign uses personalized recipient names and addresses sourced from prior Ledger and Trezor data breaches, increasing effectiveness through social engineering.
Your wallet is not compromised unless you scan the QR code or enter your recovery phrase. Legitimate Ledger and Trezor communications only occur through the device itself (Ledger Live, Trezor Suite) or official URLs (ledger.com, trezor.io). Report the phishing domain via ledger.com/security/report-an-issue or trezor.io/learn/a/report-phishing-attack. Never share your recovery phrase with anyone under any circumstances.
Related News