This morning, 10 July 2026, I was caught by a very convincing physical-mail phishing scam targeting Ledger users.
I received a professional-looking letter claiming to be from Ledger. It contained my full name, postal address, the exact Ledger device I own, Ledger branding and an individual reference number.
The letter claimed that I urgently needed to complete a “Post-Quantum Cryptography Security Update” before 31 July 2026. It instructed me to scan a QR code.
I scanned the QR code and was taken to a website that appeared to be Ledger. It asked me to enter my 24-word Secret Recovery Phrase. Believing the letter and website were genuine, I entered it. I also followed what appeared to be a Ledger update prompt on my computer.
I NEVER CONNECTED OR PLUGGED IN MY LEDGER DEVICE.
That did not protect me.
Shortly afterwards, an unauthorised transaction emptied 0.00969157 BTC from my wallet. The transaction has now been confirmed and cannot be cancelled.
The important part I did not understand is that the 24 words are not merely a password or recovery code. They are effectively a complete backup of the wallet’s private keys. Anyone with those words can recreate the same wallet on another device and spend the funds without possessing the original Ledger or knowing its PIN.
A normal Ledger wallet is not two-factor security where both the physical device and the 24 words are required. The physical device protects the keys during normal use, but the recovery phrase can regenerate those keys somewhere else.
This is the point that needs to be made brutally clear during hardware-wallet setup:
THE 24 WORDS ALONE ARE EFFECTIVELY THE WALLET.
Do not:
- Scan QR codes from letters claiming to be Ledger.
- Enter your 24 words into any website, phone or computer.
- Trust a letter merely because it knows your name, address or device model.
- Believe claims about urgent verification, security upgrades, account suspension or “post-quantum” protection.
- Assume the physical Ledger must be connected before someone can take the funds.
Ledger now has an official support article called “Physical Mail Phishing Scam” describing this exact method and stating that it will never ask users to enter their recovery phrase online.
I am posting redacted photographs of the letter so other people can recognise the wording and layout. I have covered the QR code so nobody accidentally scans it.
I have reported this to ReportCyber and Western Australia Police. I understand that entering the recovery phrase was the critical mistake. I am posting this because the scam was specifically targeted, professionally produced and knew exactly which Ledger device I owned.
I do not currently know how the criminals obtained my name, address and device information, and I am not claiming that Ledger itself sent the letter.