Coin Market Solution logo Coin Market Solution logo
crypto.news 2025-04-30 07:39:31

Ledger hardware wallet’s users targeted by mail, reportedly exploiting data leaked in 2020 breach

Scammers are sending physical letters to Ledger hardware wallet users, impersonating the company in an effort to steal wallet seed phrases — a phishing scheme that may be linked to Ledger’s 2020 data breach. In a recent post on X, Jacob Canfield shared a photo of one such fraudulent letter. The letter, which arrived by mail, was made to look official with Ledger branding, business address, and a unique reference number. It asked the recipient to scan a QR code and input their wallet’s 24-word recovery phrase, claiming it was required for a “critical security update.” It also stated that failure to complete the “mandatory validation process” could lead to restricted access to the user’s crypto funds. Breaking: New scam meta launched. Now they’re sending physical letters to the @Ledger addresses database leak requesting an ‘upgrade’ due to a security risk. Be very cautious and warn any friends or family that you know is in crypto and is not that savvy. pic.twitter.com/XoUAGQBJXt — Jacob Canfield (@JacobCanfield) April 28, 2025 Responding to Canfield’s post, Ledger reminded users that “Ledger will never ask for your 24-word recovery phrase. If someone does, it’s a scam.” You might also like: News Trezor Safe devices still vulnerable to physical supply chain attacks, Ledger says Canfield speculated that this scam letter may be tied to Ledger’s notorious data breach from July 2020. In that incident , a hacker exploited an inactive API key to access portions of Ledger ’s e-commerce and marketing database. The breach resulted in the exposure of approximately one million customer email addresses, along with other personal details such as names, phone numbers, shipping addresses, and information about purchased products. While it’s unknown whether Canfield’s letter is tied to the 2020 Ledger breach, cybersecurity outlet BleepingComputer previously reported that data from the breach had been used in various crypto phishing campaigns involving fake emails, counterfeit hardware wallets, and scam websites. You might also like: Crypto Hardware Wallet Company Ledger Suffers Data Breach, 1M Customer Details Exposed

Loe lahtiütlusest : Kogu meie veebisaidi, hüperlingitud saitide, seotud rakenduste, foorumite, ajaveebide, sotsiaalmeediakontode ja muude platvormide ("Sait") siin esitatud sisu on mõeldud ainult teie üldiseks teabeks, mis on hangitud kolmandate isikute allikatest. Me ei anna meie sisu osas mingeid garantiisid, sealhulgas täpsust ja ajakohastust, kuid mitte ainult. Ükski meie poolt pakutava sisu osa ei kujuta endast finantsnõustamist, õigusnõustamist ega muud nõustamist, mis on mõeldud teie konkreetseks toetumiseks mis tahes eesmärgil. Mis tahes kasutamine või sõltuvus meie sisust on ainuüksi omal vastutusel ja omal äranägemisel. Enne nende kasutamist peate oma teadustööd läbi viima, analüüsima ja kontrollima oma sisu. Kauplemine on väga riskantne tegevus, mis võib põhjustada suuri kahjusid, palun konsulteerige enne oma otsuse langetamist oma finantsnõustajaga. Meie saidi sisu ei tohi olla pakkumine ega pakkumine