Malicious QR Codes Lead to Wallet Drains
-

The letters reportedly direct victims to scan a QR code leading to a fake setup page mimicking official Ledger or Trezor websites. Once users enter their seed recovery phrases, the information is transmitted to attackers, allowing them to import the wallet and steal funds.Both Ledger and Trezor have repeatedly warned customers that they will never request recovery phrases via email, website forms, phone calls, or physical mail.
These scams exploit prior data breaches that exposed customer contact details, including physical addresses — enabling attackers to conduct more convincing offline phishing campaigns.