Scammers are targeting Ledger users with fake letters urging them to scan a QR code and provide their 24-word recovery phrase under the guise of a “security update”.
The phishing scheme exploits data from Ledger's 2020 breach, exposing personal details of over 270,000 users, including home addresses.
Ledger reiterated that it never asks for seed phrases and warned users to ignore such requests, regardless of how legitimate they may appear.
Despite closely mimicking Ledger's branding, the fake letters aim to steal recovery phrases, prompting Ledger to caution users against engaging with any such solicitations.