Scams Targeting Crypto Holders
This article provides information on common phishing and scam tactics targeting Ledger™ users. Attackers often impersonate Ledger, attempting to steal your 24-word Secret Recovery Phrase or crypto assets.
If you’re asked to share your 24-word Secret Recovery Phrase in any way, it's a scam.
Security Best Practices
- Reminder: Anyone with access to your 24-word Secret Recovery Phrase can take your assets.
- Never enter your 24-word Secret Recovery Phrase anywhere else than on your Ledger device upon setup or restore.
- Ledger Wallet™ (formerly Ledger Live) will never request you to enter your 24-word Secret Recovery Phrase.
- Ledger Support will never ask you for your 24-word Secret Recovery Phrase.
- Do your own research, and only use our official chatbot on support.ledger.com. Take a moment to review its resources along with our Academy.
Types of Scams and Phishing Tactics
📞 Phone Scams
Scam Tactic: If you receive a phone call from anyone claiming to be a Ledger employee, they're not. Ledger employees never make unsolicited phone calls.
A common variation of this scam involves fake police officers calling you using a real police phone number, claiming your ID was stolen and that someone is attempting to access your accounts through Ledger Recover. They then tell you a Coincover employee will follow up. A fake Coincover agent then calls and instructs you to transfer your funds while they claim to be securing your account. Coincover and Ledger will never ask you to move your funds.
How to Detect: Any unsolicited phone call claiming to be from Ledger, Coincover, or law enforcement asking about your crypto accounts is a scam.
What to Do: Hang up immediately. Never transfer funds or disclose your 24-word Secret Recovery Phrase as a result of any phone call. Ledger, Coincover, and law enforcement will never call you to ask about your crypto accounts or request that you move your funds.
Learn More📥 Fake Ledger Wallet
Scam Tactic: Scammers create counterfeit Ledger Wallet websites or apps to deceive users into entering their Secret Recovery Phrases.
How to Detect: Any source other than the official website is fraudulent. If Ledger Wallet asks for your 24-word Secret Recovery Phrase, it's fake.
What to Do: Delete the fake app immediately. Download the legitimate version from the official Ledger website. If you've disclosed your 24-word Secret Recovery Phrase, learn how to reset your Ledger device and create a new 24-word Secret Recovery Phrase here.
Learn More🎁 NFT Scams
Scam Tactic: Scammers send unsolicited NFTs, promising rewards to lure you into malicious sites.
How to Detect: Watch out for unknown or suspicious NFTs or airdrops in your accounts. These often come with QR codes or prompts encouraging you to visit a website or take action.
What to Do: Do not engage with unsolicited NFTs without verifying their authenticity. Never share your 24-word Secret Recovery Phrase.
For more information:
📋 Clipboard Hijacks
Scam Tactic: Malware alters clipboard data to redirect crypto transactions to scammers' addresses.
How to Detect: Watch for any differences between the copied address and the one you’re about to paste.
What to Do: Always double-check the address when copying and pasting during transactions. Use updated antivirus or anti-malware software and manually verify all addresses.
Learn More✔️ Token Approvals
Scam Tactic: Scammers trick users into approving tokens on malicious contracts that drain funds.
How to Detect: Check for any approvals that seem unfamiliar or that you don’t remember authorizing. Be wary of DApps requesting extensive access to your tokens.
What to Do: Revoke unnecessary token approvals using trusted tools and verify every contract before approval.
For more information:
📢 Social Media
Scam Tactic: Impersonators on social media offer fake giveaways or support to steal your data.
How to Detect: Always verify the authenticity of accounts; official accounts are typically verified. Be cautious of offers that sound too good to be true—they usually are.
What to Do: Only interact with verified official accounts and directly verify any offers through official channels.
Learn More📧 Phishing Emails
Scam Tactic: Attackers send fake emails pretending to be Ledger support or another trusted service, urging users to click malicious links.
How to Detect: Phishing emails often include urgent messages, grammatical errors, or ask you to enter sensitive information. Always check the sender's email address.
What to Do: Never click on links in suspicious emails. Always go directly to the official website by typing the URL yourself. If unsure, contact Ledger support through official channels.
Learn More💨 Dusting Attacks
Scam Tactic: Small amounts of cryptocurrency (dust) are sent to many wallet addresses to track transactions and de-anonymize users.
How to Detect: Unexpected tiny deposits from unknown addresses in your wallet history. Scammers may later send phishing messages pretending to be from Ledger or another service.
What to Do: Do not interact with the dust transaction. Use a new wallet address for transactions if privacy is a concern. Be cautious of unsolicited messages referencing these small deposits.
Learn More🔀 Address Poisoning
Scam Tactic: Scammers send small transactions to your wallet with addresses that look similar to ones you've transacted with before, hoping you’ll accidentally send funds to their address.
How to Detect: Check the full wallet address carefully before sending any transaction. Do not rely on just the first and last few characters.
What to Do: Always copy and paste the correct recipient address from a trusted source. Verify transaction details thoroughly before confirming.
Learn More♻️ Pre-Seed device Scam
Scam Tactic: Scammers send Ledger devices with a pre-written 24-word Secret Recovery Phrase, claiming they're ready to use.
How to Detect: Watch for devices that include a 24-word Secret Recovery Phrase in the box or instruct you to use an existing 24-word Secret Recovery Phrase instead of generating one.
What to Do: Don’t use the 24-word Secret Recovery Phrase or send funds—it's compromised. Contact official Ledger support and only buy from trusted sources.
🔄 Phishing transactions on the TON Network
Scam Tactic: Scammers send phishing transactions with comments containing links to fake websites, often right after you deposit TON.
How to Detect: Look for unexpected send/receive transactions with messages directing you to visit a website, especially if you didn’t initiate the activity.
What to Do: Do not click any links or enter sensitive information. Simply ignore the transaction—your funds remain safe if you don’t interact.
📨 Physical Mail Phishing Scam
Scam Tactic: If you receive a physical letter claiming to be from Ledger and asking you to verify your account or enter your 24-word Secret Recovery Phrase, it's a scam. Scammers use urgent language and may include fake QR codes or links to trick you into revealing your 24-word Secret Recovery Phrase.
How to Detect: Any physical mail asking for your 24-word Secret Recovery Phrase in any form, is a phishing scam.
What to Do: Do not scan any codes or visit any links. Never share your 24-word Secret Recovery Phrase. Report the letter to Ledger Support and discard it immediately.
🗒️ Recovery Sheet Scam
Scam Tactic: Scammers send counterfeit recovery sheets to Ledger customers or swap the recovery sheet inside a second-hand Ledger device for one with a pre-filled 24-word Secret Recovery Phrase (SRP). If you set up your Ledger device using the pre-filled 24-word Secret Recovery Phrase instead of generating a new one, the scammer who created that phrase gains full access to your funds.
How to Detect: Your recovery sheet should always be blank when you first receive your Ledger device. If your box contains a sheet with words already filled in, or if you receive an unsolicited recovery sheet in the mail, it is a scam. To verify what your recovery sheet should look like, refer to our article on recovery sheet versions by Ledger device.
What to Do: Never use a pre-filled recovery sheet. Only record the 24-word Secret Recovery Phrase generated directly on your Ledger device during setup. If you suspect your recovery sheet has been tampered with, contact Ledger Support immediately and do not send any funds.
Learn moreImportant Note
If you think you have received a fake communication from a third party impersonating Ledger (phone call, email, or other), report it in detail to our dedicated phishing address: phishing@ledger.fr
You can find our dedicated phishing website here for more information on ongoing phishing campaigns. Learn more about protecting yourself here.
I Got Scammed - What Do I Do?
If you’ve lost funds, we recommend reviewing our Loss of Funds article for guidance on the next steps.
To better protect yourself in the future, take a moment to learn about our Clear Signing initiative and how it enhances transaction security. Additionally, understanding Blind Signing and its risks can help you make more informed decisions while navigating the crypto space.