Fake Ledger data breach emails used to trick victims into giving up recovery phrases
- New phishing email scam impersonating Ledger spotted
- The emails claim the user’s Ledger wallet seed phrase was compromised, and asks for confirmation
- Users that provide the seed phrase lose all their money
Criminals are trying to steal cryptocurrency by impersonating hardware wallet firm Ledger and sending phishing emails.
Victims have reported receiving emails pretending to be from Ledger, and claiming that their seed phrase (also known as recovery phrase, or mnemonic seed) is compromised. To protect their digital belongings, the victims are invited to “verify the security” of the recovery phrase through the “secure verification tool”.
The email comes with a “Verify my recovery phrase” button which leads people through an AWS website, to a domain “ledger-recovery[.]info”. There, users can enter their recovery phrase, which is then saved on a server and relayed to the attackers.
Providing the right data
A recovery phrase is used to load the contents of a cryptocurrency wallet into a new device, or new software wallet. It usually comes as a series or either 12, or 24 random words. Whoever has access to this phrase, also has access to the funds, so it is absolutely pivotal that these remain offline, hidden, and not shared with anyone.
To make sure they’re getting the real deal, the scammers added several safeguards to the phishing page. The site is limited to 2048 valid words that can be entered as part of the mnemonic seed phrase. Furthermore, whatever the user enters, they will get the response that the seed phrase is wrong – most likely to allow the victims to double down on their entries and thus confirm they have provided the right information.
Phishing emails often used to have poor grammar and spelling and could typically be identified by clumsy, amateurish wording. However, with the introduction of generative AI, that is no longer the case. In this case, though, the clue was in the email address, since it came from the SendGrid email marketing platform. Furthermore, the link redirects through an Amazon AWS website, which should also be a red flag.
It is impossible to know how many people (if any) fell for the trick, but those that did lost their money permanently.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via BleepingComputer
You might also like
New phishing email scam impersonating Ledger spotted The emails claim the user’s Ledger wallet seed phrase was compromised, and asks for confirmation Users that provide the seed phrase lose all their money Criminals are trying to steal cryptocurrency by impersonating hardware wallet firm Ledger and sending phishing emails. Victims have…
Recent Posts
- Google Wallet ID passes will be available in select EU states this summer
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- Nomad Goods Promo Codes: Get 25% Off in June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023