...
+61 2 9188 7896 (24 / 7) お問い合わせ

共有する

台帳レター詐欺:高度な暗号通貨ウォレットフィッシング攻撃

クイック概要

製品概要

A new phishing scam targets Ledger wallet users using physical letters sent to their home addresses. These letters, designed to appear official, urge recipients to perform a fake security update by scanning a QR code. Victims are then led to a convincing phishing site that prompts them to enter their recovery phrase, compromising their cryptocurrency wallets.

キーポイント

  • Physical letters mimic official Ledger correspondence.
  • Scam letters direct recipients to scan a QR code for a fake update.
  • The linked phishing site asks for sensitive wallet information.
  • Site avoids search engine indexing to remain undetected.
  • Victims' funds are stolen upon entering their recovery phrase.
  • Quick response may help freeze stolen funds on exchanges.

FAQ

How does the Ledger letter phishing scam operate?
Victims receive a fake letter urging a security update. Scanning the QR code leads to a phishing site that asks for wallet details and the recovery phrase.
What happens if I enter my recovery phrase on the phishing site?
Your wallet is compromised, and your crypto holdings can be stolen immediately.
盗まれた暗号通貨は回復できますか?
It may be possible to freeze the funds if action is taken quickly, but recovery is complex and not guaranteed.
台帳レター詐欺:高度な暗号通貨ウォレットフィッシング攻撃

The Ledger Letter Phishing Scam

Our crypto investigators recently heard from an Australian scam victim who lost his entire crypto portfolio to a very sophisticated Ledger phishing scam.

For years we’ve been told to be careful of phishing SMS messages, calls and emails, but what if the phishing scam arrived in your mailbox? And we mean your actual physical mailbox, at your house, addressed to your full name and home address, delivered through Australia Post.

This incredibly sophisticated shift away from online digital phishing and back to an old-school approach is something victims simply don’t see coming.

手紙

The letter claims to be from Ledger and is printed with the official Ledger logo on what appears to be the genuine company’s letterhead. To make it look even more believable, the letter is signed off by Charles Guillemet, the actual Chief Technology Officer (CTO) of Ledger.

The phishing letter aims to convince the victim that an urgent security update is required, claiming it is a Post-Quantum Cryptography Security Update. The letter even lists a link to learn more about Post-Quantum Cryptography on the official Ledger website.

ledger.com/blog-quantum-computing-threat-to-blockchain

The link genuinely directs users to a resource on the real Ledger website, providing even more authenticity to the elaborate crypto phishing scam.

The letter encourages the victim to scan a QR code to ensure access is maintained to their Ledger wallet.

Ledger phishing scam letter

So how Does the Scam Work?

When the individual scans the QR code, it sends them to what we describe as one of the smoothest-looking phishing sites we’ve ever seen. The website the victim is sent to is:

secure.entry-ledger.com

The Ledger letter phishing scam

Our scam investigators conducted an initial open-source investigation of the website, where no current publications warning against the site were found. It also appears the scammers have deliberately prevented the website from being indexed by search engines, further reducing its exposure. This scam is highly targeted. Unlike many phishing scams which rely on volume, this scam is extremely targeted.

When visited, the website states that a Post-Quantum Cryptography Security Update is Required, followed by the Ledger logo and the words “The most secure cryptocurrency & NFT wallet”, reinforcing the legitimacy of the genuine Ledger wallet.

Once the user clicks 「はじめに」, a pop-up appears asking whether they approve sending data to help improve the user experience, which appears to be a genuine analytics request that many legitimate companies display.

Once past this pop-up, the site displays images of Ledger devices, asking the user to select their device. Once selected, the user is very politely warned about what is needed to conduct the security update. After a PIN is created, and the user is warned several times about best security practices and ensuring they are careful with their personal details, the victim is finally prompted to enter their 24-word recovery phrase (seed phrase).

What to do if Your Crypto has Been Stolen

The instant the seed phrase is provided to the website, your wallet is compromised and your crypto holdings can be stolen.

It is important to contact our scam investigators as soon as possible. If investigators can respond to a hack or stolen crypto quickly, there is a chance of attempting to freeze the funds at an exchange before the scammers can cash out.

However, there are many factors which influence whether freezing is possible. It is certainly not guaranteed, and recovering funds from a sophisticated phishing scam is a complex process. The first step towards justice, though, is investigating the offence and identifying the scammers responsible.

At Cybertrace, we investigate cryptocurrency fraud and assist victims of sophisticated scams involving fake websites, impersonation scams, phishing attacks and cryptocurrency theft.

Using blockchain intelligence software, open-source intelligence (OSINT) and specialised investigative techniques, our investigators trace stolen cryptocurrency in an effort to identify the offenders responsible.

If you’ve been the victim of this new type of Ledger phishing scam, 弊社のチームにお問い合わせ today for a confidential discussion.

Feel free to tell us your story in the comments section below if you have been a victim of the Ledger letter phishing scam.

コメント送信

あなたのメールアドレスは公開されません。 必須項目は、マークされています *

お問い合わせ

お問い合わせ

フレンドリーなスタッフまでお問い合わせください。 Cybertrace オーストラリアでは、あなたの事件を内密に評価します。専門家に相談してください。

今すぐお問い合わせ