• Source:JND

Hackers continue to go after cryptocurrency users in possibly new and unusual attacks. Rather than emails or messages, the bad actors are now mailing 'direct' letters to customers of crypto wallet security companies in an attempt to steal their recovery phrases. These scams are the latest amid an increase in more advanced frauds, such as fake Zoom meetings and hijacked Telegram accounts, recent reports have suggested. Cryptocurrency scams are getting more sophisticated and harder to spot than ever before in recent years.

Fake Letters Impersonate Crypto Wallet Security Companies

In a post on X, Recorded Future Senior Director of Product Management Dmitry Smilyanets said the hackers sent faux physical letters to Trezor customers. The letters impersonate the company and contain a hologram and a QR code that links users to a fraudulent website.

To make things more believable, the fake letters are reported to have Matěj Žák’s signature himself as Trezor CEO.

ALSO READ: Google Android XR OS Leaks Reveal Clean UI, AI Focus, And Galaxy XR Headset

Trezor isn’t the only company that’s being imitated, another X user pointed out. Ledger, which is based in Paris, reportedly sent its customers similar letters. These counterfeit Ledger letters were printed on the company’s official letterhead and carried the signature of its Chief Technology Officer, Charles Guillemet.

Both letters carried nearly identical subject lines, claiming that the companies would “soon” make transaction authentication “mandatory” as a new security feature to “provide greater confidence” in transaction safety.

ALSO READ: Google Signals Early Android 17 Stable Release, Second Beta Confirmed For March

QR Codes Lead to Scam Websites

The letters asked recipients to scan a QR code and follow the steps on the screen in order to avoid being disconnected. According to Smilyanets, the created QR code sends people to a scam site that aims to steal wallet recovery phrases, giving criminals access to cryptocurrency funds.

Responding to the incident, Trezor confirmed that it “never” contacts customers first and strongly advised users to “never share” their wallet backups. The company urged customers to verify information through official channels before taking any action, adding, “Stay safe out there, everyone.”


Also In News