Worked example · 2023-20
Fake hardware-wallet firmware-update / recovery-app phishing cohort — Ledger / Trezor user base — 2023 onward (multi-year cohort)
Summary
Ledger and Trezor are the two market-dominant hardware-wallet vendors. Both have a public-facing brand-trust position built on years of marketing, security advisory publication, and user-base familiarity. Both have official communication channels (email newsletters, in-app notifications, official social-media accounts, official customer-support pages) that legitimate users routinely interact with. Both have publicly committed in writing — through user-onboarding documentation, customer-support pages, and recurring security advisories — that legitimate vendor communications never request the user's BIP39 seed phrase under any circumstances.
In December 2020, Ledger SAS publicly disclosed a customer-data breach: a marketing-database compromise had leaked the email addresses, physical addresses, phone numbers, and order history of approximately 273,000 Ledger customers. The leaked database was published on a hacking forum. The leak provided phishing operators with a high-quality target list — known Ledger customers, with verified purchase history, contactable via multiple channels (email, physical mail, phone). The 2020 Ledger leak is the operational substrate for the broader 2023–2026 fake-firmware-update / recovery-app phishing cohort.
The cohort consists of multiple parallel sub-campaigns sharing the structural pattern:
Sub-campaign (a) — Email phishing from "Ledger" / "Trezor" support, 2020 onward, accelerating 2022–2023. The user receives an email impersonating Ledger / Trezor official communications. The lure typically references one of: (i) "your Ledger has been compromised in a data breach; verify your recovery phrase to confirm your account is secure"; (ii) "firmware update required; download Ledger Live v[fake-version] and re-enter your recovery phrase"; (iii) "your Ledger has been disabled by the security team; complete the verification process to reactivate." The email links to an attacker-controlled phishing website that mimics the legitimate Ledger Live / Trezor Suite UI and prompts the user for their 24-word seed phrase. Per Kaspersky's spring 2023 cohort tabulation, over 85,000 scam emails were detected and thwarted by Kaspersky's solutions during a single quarter targeting both hot and cold wallets.
Sub-campaign (b) — Physical-mail-letter campaign impersonating Ledger / Trezor, active 2025–2026. Scammers mail printed letters to known Ledger / Trezor customers (using addresses from the 2020 Ledger leak and adjacent data sources). The letters use realistic branding, letterheads, and urgent language. Trezor-themed letters warn users to complete a "verification process" by a deadline (one cohort cited a February 15, 2026 deadline). Ledger-themed letters request scanning a QR code for a "critical security update." The QR codes lead to fake domains (per Trezor / Ledger advisories: trezor.authentication-check.io, ledger.setuptransactioncheck.com, and rotating variants) that prompt the user for the 24-word seed phrase. The physical-mail vector exploits the user's higher trust in physical mail relative to email — a recurring social-engineering observation.
Sub-campaign (c) — Trojanised companion-app cohort, 2023 onward. Per Kaspersky's 2023 disclosure: infostealers (commodity malware: Atomic Stealer / AMOS for macOS, Lumma / Vidar / RedLine for Windows, multiple Android stealers) detect the presence of legitimate Ledger Live / Trezor Suite installations on the infected machine and swap out fragments of the companion-app code with trojanised code. The trojanised app fakes an error during a routine wallet operation and initiates a "recovery process" that prompts the user for their 24-word seed phrase. The user, expecting that legitimate wallet-recovery flows may legitimately require the seed phrase, enters it; the trojanised app exfiltrates it and the wallet is drained. This sub-campaign is structurally distinct from the email / physical-mail sub-campaigns because the lure is delivered through the legitimate companion-app's own UI, leveraging the user's prior trust in the (now-modified) app.
Sub-campaign (d) — Mailed-fake-hardware-wallet replacement cohort, 2021 onward. Per Bitcoin Magazine June 2021 / Cointelegraph reporting: scammers mail counterfeit hardware wallets to victims of the 2020 Ledger data breach with a cover letter claiming the user's existing Ledger has been "compromised" and the replacement device should be used immediately. The replacement is a counterfeit unit with attacker-known seed material; if the user transfers funds to the counterfeit, the attacker drains them. This sub-campaign overlaps with the counterfeit-hardware cohort at examples/2025-01-counterfeit-ledger-nano-s-plus-cohort.md but is distinguished by the delivery channel (unsolicited mail leveraging the 2020 leak) and the brand-impersonation lure (claiming the user's existing device is compromised).
The vendor-side response is a continuous-update threat-intelligence surface. Ledger maintains a public "Ongoing phishing campaigns" page tracking active sub-campaigns. Trezor publishes parallel security advisories. Both vendors have publicly committed that legitimate vendor communications never request the user's seed phrase under any circumstances; the vendor-side commitment is the structural defender-side primitive that the user is supposed to enforce.
For OAK's purposes the cohort is the canonical worked example for brand-trust-leveraged phishing for seed-phrase exfiltration in the v0.1 corpus. The cohort complements the LastPass cohort (cold-storage-at-rest), the iCloud-MetaMask cohort (implicit-cloud-custody), and the counterfeit-hardware cohort (hardware supply-chain) in establishing the breadth of the seed-phrase-exfiltration threat surface across at-rest storage, implicit-cloud-custody, hardware supply-chain, and active-phishing sub-classes.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2020-07 | Ledger announces a data breach exposing customer data; the database (~273,000 customer email addresses + physical addresses + phone numbers + order history) is later publicly leaked on a hacking forum | (operational substrate for the broader cohort) |
| 2020-12 onward | First wave of Ledger-data-leak-driven phishing emails begins targeting known Ledger customers | T11.x phishing-driven seed-phrase exfiltration sub-cohort begins |
| 2021-06 | Bitcoin Magazine reports: scammers mailing counterfeit hardware wallets to victims of the 2020 Ledger data breach, claiming the user's existing device is compromised | (sub-campaign (d) — mailed-fake-hardware-wallet replacement) |
| 2022 to 2023 | Email phishing volume continues to scale; Kaspersky spring 2023 cohort tabulation reports 85,000+ scam emails detected in a single quarter | T11.x cohort acceleration (sub-campaign (a)) |
| 2023-05 | Kaspersky publishes counterfeit-Trezor-Model-T disclosure including the wait-for-balance-to-grow extraction pattern; parallel coverage of the broader cohort | (cohort attribution coverage) |
| 2023 onward | Trojanised companion-app sub-campaign (c) emerges; infostealers swap out fragments of legitimate Ledger Live / Trezor Suite code with trojanised "recovery process" prompts | T11.x trojanised-companion-app sub-cohort |
| 2025-2026 | Physical-mail-letter sub-campaign (b) accelerates; Trezor-themed and Ledger-themed letters with QR codes leading to fake domains; deadlines October 2025 to February 2026 | T11.x physical-mail sub-cohort |
| 2026-02 | Trezor / Ledger publicly confirm the physical-mail-letter campaign in updated security advisories; The Block, CCN, GnCrypto, Live Bitcoin News cover the cohort | (cohort attribution coverage continues) |
| Continuing | The cohort surface remains active at v0.1 reporting horizon (May 2026); the 2020 Ledger leak provides ongoing personalisation data; new sub-campaigns continue to emerge | (open cohort surface) |
What defenders observed
- The vendor-side commitment "we never ask for your seed phrase" is the structural defender-side primitive, but only if the user enforces it as an invariant. Both Ledger and Trezor have publicly committed in writing that legitimate vendor communications never request the user's seed phrase under any circumstances. The defender-side primitive is therefore vendor-side commitment + user-side enforcement of the invariant. The user's enforcement requires refusing to enter the seed phrase into any surface other than the legitimate device's own physical input mechanism — no email, no website, no in-app prompt, no chat-support exchange, no phone call, no physical-mail QR code, no firmware-update flow. The cohort exists because user-side enforcement of the invariant is imperfect; the defender / Mitigations-layer lesson is that user-education programmes targeting the invariant are the highest-leverage cohort-level mitigation.
- The 2020 Ledger data leak is an operational substrate that produces apparent legitimacy in subsequent phishing. The leaked database (~273,000 customer email addresses + physical addresses + phone numbers + order history) provides phishing operators with the personalisation data — name, address, phone number, purchase history — that produces apparent legitimacy in subsequent phishing emails / letters / calls. The defender / contributor lesson is that historical breach data is an operational substrate that compounds over time: the 2020 leak continues to provide actionable phishing data at v0.1 reporting horizon (May 2026), six years after the initial leak. Contributors writing future cohort worked examples should preserve the historical-breach-data dimension explicitly.
- The physical-mail vector exploits the user's higher trust in physical mail relative to email. Physical mail is operationally more expensive to send than email, requires physical-address data (which the 2020 Ledger leak provides for the cohort), and arrives in a channel that the user's spam-filter does not cover. The user's mental model of "physical mail = legitimate" is a recurring social-engineering surface; the defender lesson is that brand-impersonation phishing operates across all communication channels the legitimate vendor uses, not only email. Defender practice for any user with non-trivial holdings should treat unsolicited physical mail purporting to be from a hardware-wallet vendor as suspicious by default and should verify any such communication through the vendor's official customer-support channel before acting.
- The trojanised-companion-app sub-pattern leverages the user's prior trust in the legitimate app's UI. The infostealer-driven sub-campaign (c) does not deliver the lure through email or physical mail; it delivers the lure through the legitimate Ledger Live / Trezor Suite app's own UI after swapping out fragments of the app's code. The user, expecting that legitimate wallet-recovery flows may legitimately require the seed phrase, enters it. The defender lesson is that infostealer presence on the user's machine collapses the user-side trust in the companion app's UI; defender practice for any user with non-trivial holdings should treat the user's host-machine security posture (anti-infostealer protections, OS / browser update discipline) as a first-class T11 mitigation surface.
- Continuous-update threat-intelligence surfaces from the legitimate vendors are the operational defender-side resource. Ledger's "Ongoing phishing campaigns" page and Trezor's parallel advisories track active sub-campaigns continuously. Defender practice for any user with non-trivial holdings should subscribe to these threat-intelligence surfaces and should treat any unsolicited communication purporting to be from the vendor as a candidate phishing attempt pending verification against the active-campaign list.
What this example tells contributors writing future Technique pages
- The proposed T11.x sub-Technique covering hardware-wallet supply-chain / physical-access compromise should include a phishing-driven sub-pattern. The cohort at this worked example anchors the active-phishing-driven seed-phrase exfiltration impersonating hardware-wallet vendor sub-pattern, distinct from the counterfeit-hardware sub-pattern at
examples/2025-01-counterfeit-ledger-nano-s-plus-cohort.mdand from the cold-storage-at-rest sub-pattern atexamples/2022-12-lastpass-vault-cohort.md. Contributors writing the proposed sub-Technique page should preserve the multi-sub-pattern structure explicitly and should articulate the relationships between sub-patterns. - Historical-breach data as operational substrate is a recurring T-series dimension. The 2020 Ledger leak provides ongoing personalisation data at v0.1 reporting horizon (May 2026) — six years after the initial leak. Contributors writing future T-series worked examples should preserve the historical-breach-data dimension explicitly and should not treat breach data as having a bounded operational lifetime. Adjacent examples in the v0.1 corpus include the LastPass cohort (where the 2022 vault exfiltration provides an unbounded brute-force window) and the SIM-swap-driven cohort (where leaked phone-number data provides ongoing actionable phishing-target data).
- The vendor-side commitment + user-side enforcement primitive is a load-bearing T11 Mitigations-layer pattern. Contributors writing the OAK Mitigations layer should pre-position the vendor-side commitment that legitimate channels never request the seed phrase + user-side enforcement of the invariant primitive as a first-class user-side T11 control. The vendor-side half of the primitive is well-deployed (Ledger / Trezor advisories); the user-side enforcement half is the gap that the cohort exploits, and user-education programmes targeting the invariant are the highest-leverage cohort-level mitigation.
- The multi-channel brand-impersonation dimension generalises across the broader phishing threat surface. The cohort covers email, physical mail, in-app prompts (via trojanised companion apps), and unsolicited mailed-hardware-replacement letters. Contributors writing future phishing-related worked examples should preserve the multi-channel dimension explicitly and should not over-anchor on email-only phishing as the dominant brand-impersonation surface.
- Continuous-update threat-intelligence surfaces from legitimate vendors are first-class OAK Mitigations-layer resources. Ledger's "Ongoing phishing campaigns" page and Trezor's parallel advisories should be treated as first-class OAK Data-Sources entries. Contributors writing the OAK Data Sources axis should pre-position vendor-side continuous-update threat-intelligence surfaces as a distinct data-source class alongside on-chain telemetry, mempool / pre-block telemetry, and forensic-provider feeds.
- The infostealer-driven trojanised-companion-app sub-pattern bridges T11 and T4 / T5. The host-machine infostealer infection (T4 / T5 infostealer family — see also OAK-S series Atomic Stealer / Lumma / Vidar / RedLine entries) plus the trojanised-companion-app delivery (T11.002-adjacent at the modification of installed app layer) plus the seed-phrase exfiltration (T11.x phishing-driven sub-pattern) chain together into a multi-Technique attack chain. Contributors writing future worked examples involving infostealer-driven cohort attacks should preserve the multi-Technique chain dimension explicitly.
Public references
[ledgerphishingcampaignspage]— Ledger official, "Ongoing phishing campaigns" page (ledger.com/phishing-campaigns-status); primary continuous-update vendor-side threat-intelligence resource.[ccnseedphrasephishing2026]— CCN, "Ledger and Trezor Users Security Alert: Seed Phrase Phishing Attempts Sent by Mail"; primary press-coverage of the 2025–2026 physical-mail sub-cohort.[theblockledgerphysicalmail2026]— The Block, "Ledger confirms physical scam letters requesting seed phrase in fake security upgrade"; primary press-coverage source.[gncryptotrezorledgerphysical2026]— GnCrypto, "Scam letters target Trezor and Ledger users with QR code traps"; primary press-coverage source.[livebitcoinnewsphysical2026]— Live Bitcoin News, "Scammers Mail Fake Ledger and Trezor Letters to Steal Seed Phrases"; primary press-coverage source.[bleepingledgerdatabreachemail]— BleepingComputer, "New fake Ledger data breach emails try to steal crypto wallets"; primary press-coverage of the email-phishing sub-cohort.[kasperskycryptophishing2023]— Kaspersky, "Kaspersky uncovers phishing activity targeting cryptocurrency users worldwide" (July 2023); primary cohort-attribution source for the 85,000-scam-emails-quarterly tabulation.[kasperskytrezorfake2023]— Kaspersky, "Review and analysis of fake Trezor cryptowallet" (May 2023); parallel-cohort source for the wait-for-balance-to-grow extraction pattern and the trojanised-companion-app sub-cohort.[cointelegraphmailedfakeledger2021]— Cointelegraph, "Scammers mail out fake hardware wallets to victims of Ledger data breach" (June 2021); primary press-coverage of the mailed-fake-hardware-replacement sub-cohort.[bitcoinmagazineledgerfakehw2021]— Bitcoin Magazine, "Inside The Scam: Victims Of Ledger Hack Are Receiving Fake Hardware Wallets" (June 2021); secondary coverage of the mailed-fake-hardware-replacement sub-cohort.[trezorforumphishingcommonthreats]— Trezor official, "Common Security Threats" learning resource; primary vendor-side threat-intelligence reference.
Citations
Existing citation keys reused: [kasperskytrezorfake2023] (also cited in the counterfeit-Ledger-Nano-S-Plus 2025 worked example) and [bitcoinmagazineledgerfakehw2021] (also cited in the counterfeit-Ledger-Nano-S-Plus worked example).
Proposed new BibTeX entries (added to citations.bib as part of this batch):
[ledgerphishingcampaignspage]— Ledger official continuous-update phishing-tracking page.[ccnseedphrasephishing2026]— CCN primary press source.[theblockledgerphysicalmail2026]— The Block primary press source.[gncryptotrezorledgerphysical2026]— GnCrypto primary press source.[livebitcoinnewsphysical2026]— Live Bitcoin News primary press source.[bleepingledgerdatabreachemail]— BleepingComputer primary press source for email sub-cohort.[kasperskycryptophishing2023]— Kaspersky 2023 phishing-cohort tabulation source.[cointelegraphmailedfakeledger2021]— Cointelegraph 2021 mailed-fake-hardware-replacement source.[trezorforumphishingcommonthreats]— Trezor official threat-intelligence reference.
Discussion
The fake hardware-wallet firmware-update / recovery-app phishing cohort (multi-year cohort 2023–2026, with operational lineage extending back to the 2020 Ledger data breach) is OAK's canonical v0.1 worked example for brand-trust-leveraged phishing for seed-phrase exfiltration within the proposed T11.x hardware-wallet-supply-chain / physical-access compromise sub-class. The case anchors the active-phishing-driven sub-pattern alongside the counterfeit-hardware sub-pattern (at examples/2025-01-counterfeit-ledger-nano-s-plus-cohort.md) and the cold-storage-at-rest sub-patterns (at examples/2022-12-lastpass-vault-cohort.md and examples/2022-04-icloud-metamask-seed-phrase-cohort.md).
The structural significance for the broader T11 framework is the empirical demonstration that brand-trust-leveraged phishing is a first-class T11 surface that the v0.1 framework does not currently cover at the seed-phrase-exfiltration layer. T4 covers phishing-driven on-chain authority grants (Permit2 misuse, allowance-approve drainers, setapprovalforall NFT drainers); the 2023–2026 fake-firmware-update cohort sits at the phishing-driven seed-phrase exfiltration layer, which is structurally distinct because (a) the substrate-of-extraction is the seed phrase itself rather than an on-chain authority grant, (b) the realised loss is bounded by the entire wallet's value rather than by per-token allowance limits, and (c) the user-side mental model defended is the seed-never-asked-for-by-vendor invariant rather than the check-the-signature-prompt heuristic. The defender / Mitigations-layer lesson is that the seed-never-asked-for-by-vendor invariant is a first-class user-side T11 control independently of the on-chain-authority-grant signing-prompt-verification mitigations that dominate the T4 family.
The case is operationally instructive in five distinct dimensions: (a) the multi-sub-campaign structure (email phishing, physical-mail-letter campaign, trojanised companion-app cohort, mailed-fake-hardware-wallet replacement) demonstrates the breadth of brand-impersonation surfaces across communication channels; (b) the historical-breach-data dimension (the 2020 Ledger leak provides ongoing personalisation data at v0.1 reporting horizon, six years after the initial leak) demonstrates that breach data has unbounded operational lifetime; (c) the vendor-side-commitment + user-side-enforcement primitive is the structural defender-side mitigation but the user-side enforcement gap is the cohort's exploitation surface; (d) the continuous-update threat-intelligence surface from legitimate vendors (Ledger's "Ongoing phishing campaigns" page, Trezor's parallel advisories) is a first-class operational defender-side resource that the OAK Data-Sources axis should pre-position; (e) the infostealer-driven trojanised-companion-app sub-pattern bridges T11 and the T4 / T5 infostealer family into a multi-Technique attack chain.
The cohort surface remains active at v0.1 reporting horizon (May 2026). The 2020 Ledger leak continues to provide actionable phishing-target data; new sub-campaigns continue to emerge; the user-side enforcement of the seed-never-asked-for-by-vendor invariant remains imperfect. Contributors maintaining this worked example post-v0.1 should treat the cohort as live and should report any further large-scale sub-campaign emergence (additional brand-impersonation surfaces, additional historical-breach data sources entering the operational substrate, additional infostealer-driven trojanised-companion-app variants) as they emerge.
For OAK's broader credibility, including the fake-firmware-update / recovery-app phishing cohort in v0.1 closes a structural gap: the v0.1 framework had no clean worked example of brand-trust-leveraged phishing for seed-phrase exfiltration despite the cohort having surfaced continuously since 2020. The case operationalises the active-phishing-driven seed-phrase-exfiltration dimension into a live empirical anchor, anchors the architectural distinction between phishing-driven on-chain-authority-grant attacks (T4 family) and phishing-driven seed-phrase-exfiltration attacks (the proposed T11.x sub-class), and provides contributors writing future T11.x worked examples with a tone-and-structure precedent for the active-phishing-cohort framing.