‘Convincing’ Phishing Attack Targets Ledger Hardware Wallet Users

27 October 2020

Customers of Ledger, the hardware cryptocurrency wallet, are being targeted by a phishing attack posing as an email from Ledger support. 

On Sunday a Reddit user posted in the r/ethfinance subreddit, alerting the group to the existence of the attack. 

The fake email ostensibly informs users their Ledger assets may be compromised. It states, “Our forensics team has found several of the Ledger Live administrative servers to be infected with malware.” This claim is false; while the email form looks professional, it is a phishing attempt to steal customers data. 

See also: Crypto Wallet Maker Ledger Loses 1M Email Addresses in Data Theft

The email is so convincing that even wary users might be fooled. Ledger confirmed that, for the last week, a phishing attack has been targeting Ledger cryptocurrency wallet customers. 

“I received the same email and for once I got really confused. Everything checks out,” said one Reddit user in reply to the original post. “However, there you can see that the url is incorrect (notice the dot on the second ‘e’ => ledgėr). What triggered my doubt was that I received the email twice within a couple of minutes. … It’s probably related to the previous hack where a hacker managed to get our email addresses.”

Another user replied, “Wow this looked really legit, so much so I used Contact Us form to ask Ledger if it was real. I am normally pretty good at sniffing things like this out – this was by far the most convincing attempt I have ever seen.”

See also: YouTube’s Whac-a-Mole Approach to Crypto Scam Ads Remains a Problem

Roots of a phishing attack

In July, the Ledger team discovered an API key related to their e-commerce and marketing database was exploited, and the database accessed by an unauthorized third party. The database details (mostly email addresses) were used to send order confirmations and promotional emails. 

In a blog post revealing the hack, the Ledger team emphasized that users’ payment information and crypto funds are safe.

CoinDesk independently reviewed one of these phishing emails, which was sent from “support@legder.com.” A key clue in any phishing email is a slight misspelling of a real address or URL; in this instance, “ledger.com” is misspelled. 

Pro tip: Bookmark verified sites where you normally would input sensitive information and only access them through that bookmarked link.

Phishing attacks are common and attackers are increasingly sophisticated, creating emails that resemble official company correspondence. They rely on a person making a mistake and clicking on a link that could compromise his or her security. 

See also: Social Engineering: A Plague on Crypto and Twitter, Unlikely to Stop

In a statement, a Ledger spokesperson said an internal task force has been deployed to investigate the latest phishing attack. 

“The investigation is ongoing and at this time we cannot give any additional information but one thing is for certain: Ledger will never ask you for your 24-word recovery phrase, which is a blatant sign of a phishing scam,” said the spokesperson. “Ledger encourages customers to exercise caution as phishing attacks become more sophisticated and to alert Ledger’s customer support team and consult Ledger.com for more information on the detection of scams.”

The leader in blockchain news, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups.