Sunday, May 25, 2025

Business exec sounds alarm on Ledger phishing letter delivered by USPS

Scammers posing as Ledger, a {hardware} pockets producer, are sending bodily letters to crypto customers instructing them to “validate” their wallets or threat dropping entry to funds, within the newest phishing assault to influence the trade.

BitGo CEO Mike Belshe shared an image of the rip-off letter, which featured a QR code, presumably linked to a malicious phishing web site. The letter was despatched by the USA Postal Service (USPS), in keeping with the chief.

“These are all scams don’t fall for any of those,” Troy Lindsey wrote after receiving a replica of the phishing letter.

Phishing, Crimes, Scams
A duplicate of the rip-off Phishing letter. Supply: Mike Belshe

Cointelegraph reached out to Ledger for remark however was unable to acquire a response by the point of publication.

This phishing try highlights the ever-evolving complexity and ways of social engineering scams designed to steal crypto non-public keys, consumer funds, and different delicate information from unsuspecting victims.

Associated: Hackers utilizing faux Ledger Stay app to steal seed phrases and drain crypto

Coinbase and crypto customers hit arduous by phishing assaults in 2025

In April 2025, $330 million in Bitcoin (BTC) was stolen from an aged particular person by a phishing assault, onchain detective ZackXBT confirmed in an April 30 X put up.

“Two suspects within the $330 million heist embody ‘Nina/Mo’ — a Somalian who operates a name rip-off heart in Camden, UK — and an confederate ‘W0rk,’ who assisted with the location and name,” the onchain safety analyst stated in an replace.

On Might 15, crypto alternate Coinbase introduced it was the goal of a ransom try after customer support contractors, who have been later fired by the corporate, leaked consumer information to risk actors.

The scammers demanded a $20 million ransom, which Coinbase refused to pay, and the stolen information included names, addresses, contact data, and a restricted quantity of different delicate account information belonging to a small subset of Coinbase clients.

No non-public keys, login credentials, or accesses to Coinbase Prime accounts have been compromised in the course of the leak, in keeping with the alternate.

TechCrunch founder Michael Arrington was extremely vital of the alternate for the safety failure, arguing that it’s going to result in bodily violence towards clients uncovered within the hack.

Journal: Crypto-Sec: Phishing scammer goes after Hedera customers, deal with poisoner will get $70K