Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Exclusive Binance’s SB Seker on India's INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Exclusive: Binance’s SB Seker on India’s INR Stablecoin Case, the USD Premium & Rebuilding Regulator Trust
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Ledger and Trezor Users Are Being Tricked Into Giving Away Millions

Scammers use fake letters to trick users into scanning QR codes, aiming to steal wallet recovery phrases and put crypto funds at risk.

Written By Kenrodgers Fabian
Fact Checked by Dishita Malvania
Published 2026-02-16·Updated 6 months ago
Make The Crypto Times preferred on GoogleGoogle
Ledger and Trezor Users Are Being Tricked Into Giving Away Millions

Key Highlights

  • Scammers are sending fake Trezor and Ledger letters, tricking users into giving up recovery phrases and risking their crypto funds.
  • Mac users face phishing attacks with malware hidden in Word and PDF files, putting system credentials at risk.
  • Crypto Ponzi scams persist: PGI CEO stole $201M, showing the need for caution with promises of guaranteed returns.

Crypto wallet users are facing a new kind of scam that feels more personal and more dangerous than typical phishing attacks. Scammers are sending real-looking letters pretending to be from Trezor and Ledger. The letters tell people to do an “Authentication” or “Transaction Check” to keep their wallets working.

The letters are made to make people panic and act quickly, often asking them to scan QR codes that take them to fake websites. Experts say it’s a trick to steal wallet recovery phrases, giving scammers full access to your crypto.

People who received the letters say they look very official, with Trezor and Ledger letterheads. Some even include deadlines, like February 15, 2026, for Trezor users or October 15, 2025, for Ledger users. Scammers are using old data breaches to make sure the letters get to real customers.

For instance, cybersecurity expert Dmitry Smilyanets received a letter stating, “To avoid any disruption to your Trezor Suite access, please scan the QR code with your mobile device and follow the instructions on our website to enable Authentication Check by February 15th, 2026.”

A new scam affecting @Trezor customers:
– a physical mail ✅
– a hologram ✅
– a QR code leading to the scam website ✅
– a signature of @Ledger CEO 😂😂😂
– mailed from 🇺🇸 PA pic.twitter.com/ou60qtsVmK

— 𝕯𝖒𝖎𝖙𝖗𝖞 𝕾𝖒𝖎𝖑𝖞𝖆𝖓𝖊𝖙𝖘 (@ddd1ms) February 12, 2026

How the scam works

When users scan the QR codes, they’re taken to fake websites that look just like Trezor or Ledger’s official setup pages. The Trezor site tells users to complete an authentication check unless they bought their device after November 30, 2025. 

It then shows scary warnings about wallet errors or limited access. Finally, it asks users to enter their 12-, 20-, or 24-word recovery phrase. Once entered, scammers can take control of the wallet and steal all the funds.

Phishing emails like this happen a lot, but receiving fake letters in the mail is still rare. In the past, scammers even sent modified Ledger devices through the mail to steal recovery phrases during setup. That’s why hardware wallet users must stay alert. Never type your recovery phrase on a website, phone, or computer. Trezor and Ledger both warn that recovery phrases should only ever be used directly on the hardware wallet.

Mac users also at risk

Apart from the hardware wallet scams, macOS users are under the threat of advanced phishing attacks that target system credentials. Blockchain security company SlowMist found that the attackers used emails that appeared to be compliance notifications or audit results. 

The emails contained Word or PDF documents that carried AppleScript malware. When the documents were opened, it enabled the attackers to steal information from the users’ memories.

Ponzi scams persist

Moreover, crypto scams are also ongoing worldwide. Recently, Ramil Ventura Palafox, the CEO of Praetorian Group International (PGI), was given a 20-year prison sentence. He scammed more than 90,000 investors out of over $201 million, including $171 million in bitcoin. Palafox promised his investors a daily return of 0.5% to 3%, as he claimed that PGI traded bitcoin on a large scale. 

However, his actual business was using payments from new investors to fund his purchases of luxury cars, houses, and designer items, with some victims losing more than $62 million.

These scams show just how careful crypto users need to be. Always double-check messages, don’t scan QR codes from strangers, and never share your wallet recovery phrase.

Also Read: Binance Co-CEO Teng Slams ‘Misleading’ Sanctions Violations Report

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

'Your Keys, Your Coins' Justin Sun Escalates Trump-Linked WLFI Battle
‘Your Keys, Your Coins’: Justin Sun Escalates Trump-Linked WLFI Battle
Cathie Wood's ARK Invest Buys SpaceX, Securitize & Solana ETF, Continues Palantir Sales
Cathie Wood’s ARK Invest Buys SpaceX, Securitize & Solana ETF, Continues Palantir Sales
No Safety Net, High Taxes Why Edelweiss CEO Radhika Gupta Says No to Crypto in India
No Safety Net, High Taxes: Why Edelweiss CEO Radhika Gupta Says No to Crypto in India
Sandbox SAND Hacked Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage
Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage
Bofur Capital Drained of $2M Minutes After Compound Withdrawal
Bofur Capital Drained of $2M Minutes After Compound Withdrawal

Find Us on Socials

You may also like

Crypto Alert Fake IRS “Digital Asset Compliance Portal” Letters Arrive in Mail

Crypto Alert: Fake IRS “Digital Asset Compliance Portal” Letters Arrive in Mail

₹113 Crore MTC Crypto Scam India’s ED Finally Moves After 8 Years

₹113 Crore MTC Crypto Scam: India’s ED Finally Moves After 8 Years

Rapid7 Exposes Fake Trezor App Used to Steal Crypto Seed Phrases

Rapid7 Exposes Fake Trezor App Used to Steal Crypto Seed Phrases

ZachXBT Challenges Waka Flocka Flame After Fomo Criticism

ZachXBT Challenges Waka Flocka Flame After Fomo Criticism

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information