Ledger Scams and Phishing - Every Trick, and How to Spot It
The complete field guide to Ledger scams - fake support, fake Ledger Live updates, counterfeit devices in the post, drainer approvals and address-poisoning - with the tells that give each one away.
Almost nobody loses crypto to cryptography. They lose it to a well-written email at a bad moment. Since the 2020 breach put Ledger customers' names, emails and home addresses into public circulation, Ledger owners have been one of the most heavily targeted groups in consumer security - and the scams have got very good.
Here is the full catalogue, with the tells.
1. The fake "Ledger Live update" or "security update"#
How it looks: an email or SMS saying a critical vulnerability was found, your device is affected, and you must update or verify immediately. The link goes to a near-perfect clone of the Ledger site. The "updater" then asks you to enter your 24 words to "re-sync" or "migrate" your wallet.
The tell: a real firmware update happens through Ledger Live and is confirmed on the device screen with your PIN. Software never asks you to type a recovery phrase to update anything, ever.
What to do: never click. Open Ledger Live yourself, from your own machine. If there is a real update, it will be waiting there.
2. The fake data-breach notification#
How it looks: "Following a recent breach, your assets are at risk. Verify your wallet now." It exploits the fact that the 2020 breach was real and widely reported, so the email feels corroborated.
The tell: a genuine breach notice never includes a recovery-phrase step. And nobody legitimate creates urgency about your seed phrase, because urgency is the attacker's only real weapon.
3. Fake support - Discord, Telegram, X, Reddit, Google Ads#
How it looks: you post publicly that your Ledger will not connect. Within minutes a "support agent" DMs you. They are patient, competent, and walk you through a "wallet validation" on a support portal. Or you search "Ledger support" and the top result is a paid ad for a lookalike domain.
The tells:
- Nobody legitimate DMs you first. Ledger support does not slide into your DMs, ever.
- Real support tickets start from a URL you typed yourself.
- Any "validation", "sync", "migration" or "restore" step that involves typing 24 words is theft.
What to do: disable DMs from non-friends in crypto Discords. Never take help from someone who contacted you.
4. The counterfeit device in the post#
How it looks: an unsolicited package arrives, sometimes with a plausible letter on letterhead saying your old device was affected by the breach and here is a free replacement. The device inside is either tampered hardware or a genuine unit paired with a pre-filled recovery sheet. The instructions tell you to "restore your existing wallet" using words in the box, or to enter your own phrase into an included card reader.
This has genuinely happened to breach victims.
The tells: you did not order it. There are pre-written words in the box. Anything arriving unsolicited that touches your keys is an attack.
What to do: bin it, or keep it as a curiosity, but never plug it in. Wallets are ordered by you, from the vendor, and set up as a new device generating new words in front of you.
5. The wallet drainer - malicious approvals#
How it looks: a mint page, an airdrop claim, a "gas refund", a Uniswap lookalike. You connect your wallet and sign something. No 24 words involved - and yet the funds leave.
You signed a token approval (or a Permit / setApprovalForAll) granting a contract unlimited authority over your tokens or NFTs. The drainer sweeps at its convenience, sometimes weeks later.
The tells:
- The device asks you to enable blind signing to proceed - meaning it cannot show you what you are approving.
- The prompt says "unlimited" or shows a spending cap you did not choose.
- The site was reached from a DM, an ad, a QR code, or a reply-guy on X.
Defences:
- Never use your cold wallet for mints and claims. Use a throwaway hot wallet holding only gas.
- Keep blind signing off unless you specifically need it, and turn it off again after.
- A Flex or Stax shows readable contract details for supported contracts, which turns "approve this hash" into "approve unlimited USDC for this address" - a decision you can actually make.
- Periodically revoke old approvals through a reputable revoke tool.
6. Address poisoning#
How it looks: your transaction history shows a tiny incoming transfer from an address that looks like one you use - same first four and last four characters. Later you copy an address from your history and send to the impostor.
The tell: the amount is dust, and the address matches only at the ends.
Defence: never copy addresses from transaction history. Use saved contacts, verify the full string on the device screen, and send a small test first for large transfers.
7. Clipboard hijacking#
How it looks: malware watches your clipboard and swaps any copied crypto address for the attacker's. You paste, you see something that looks right, you send. It is gone.
Defence: this is exactly what the device screen exists for. Always compare the address shown in your wallet software against the address shown on the Ledger screen before confirming - the first and last six characters at minimum.
8. Fake apps in the app stores#
How it looks: a "Ledger Live" app with a plausible icon, reviews, and a developer name one character off. It asks you to import your existing wallet by entering your recovery phrase.
Defence: install only from links on the vendor's own site, check the publisher name, and remember that the real Ledger Live never asks for a recovery phrase.
9. Recovery and "fund recovery" services#
How it looks: you posted that you lost access. Someone offers to recover your wallet for a fee, or a slick site advertises seed recovery. Some ask for the phrase; some ask for an up-front payment; the sophisticated ones do both.
The tell: there is no such thing. If you have the words, you need no service. If you do not, nobody can help. Every "crypto recovery expert" contacting a person who just announced a loss is a second attack on the same victim.
10. Impersonated giveaways and "official" airdrops#
How it looks: a verified-looking account announces a Ledger-themed airdrop or a compensation programme for breach victims. Connect your wallet to claim.
The tell: claims that require connecting to an unknown contract, plus artificial deadlines. Legitimate airdrops do not need you to approve unlimited spending.
The quick triage table#
| Signal | Meaning |
|---|---|
| Asks for 24 words, in any form | Theft. Stop immediately. |
| Contacted you first (DM, call, email, post) | Assume hostile |
| Creates urgency or a deadline | Assume hostile |
| Arrived as an unsolicited package | Assume hostile |
| Asks you to enable blind signing | Slow down and verify the contract |
| Address matches only at the start and end | Address poisoning |
| Found through a search ad | Close it; type the URL yourself |
If you already entered your phrase#
Move fast. Anyone with your words can drain you at any moment, from anywhere.
- Set up a new wallet with new words on a device you trust.
- Verify the new backup, then move everything - all chains, all tokens, NFTs, staked positions, layer-2 balances.
- Prioritise by value; you may be racing an automated sweeper.
- Treat the old phrase as public forever. Never reuse it.
If you signed a malicious approval but did not expose your seed, revoke the approval, move remaining assets to a fresh address, and keep the old address only for dust.
Habits that make you a hard target#
- One rule, absolute: the 24 words never get typed into anything with a network connection.
- Bookmark the real URLs. Never search for them.
- Use a unique email alias for wallet purchases so you can see which leak caused which spam.
- Never announce holdings, gains, or that you own a hardware wallet.
- Keep a hot wallet for the fun, degenerate stuff and a cold wallet that signs five times a year.
- Verify every receive address on the device.
FAQ#
Will Ledger ever email me asking for my recovery phrase?#
No. No wallet manufacturer, exchange, support agent, or firmware update will ever legitimately need your recovery phrase. Any message that asks - however official it looks - is an attempt to steal your funds.
I got an email about a Ledger data breach. Is it real?#
There was a genuine breach in 2020, which is exactly why fake follow-ups work so well. Whether or not any specific email is real, the response is identical: do not click the link, do not enter anything. Open Ledger Live yourself if you want to check something.
Someone sent me a free Ledger in the post. Should I use it?#
No. Unsolicited hardware wallets are an established attack, most notoriously against 2020 breach victims. Do not connect it, and never restore a wallet from words that came in a box.
Can I get my crypto back after a scam?#
Almost never. Blockchain transactions are final and irreversible. Report it to your national fraud body and the chain analytics services, but treat "recovery experts" who contact you afterwards as a second scam targeting the same wound.
How do drainers steal funds without my recovery phrase?#
By getting you to sign a token approval that grants a contract permission to move your assets. Your key is never exposed - you authorised the theft yourself, usually while blind signing. Revoking approvals and refusing to blind-sign closes this hole.
Disclosure. Some links on this site may be affiliate links. If you buy through them we may earn a commission at no extra cost to you. It never changes our verdict — we say when a product is a bad fit. Vaultwise is an independent publication. We are not affiliated with, endorsed by, or sponsored by Ledger SAS, Trezor/SatoshiLabs, or any wallet manufacturer. Product names and trademarks belong to their respective owners.
Keep reading
Is Ledger Safe in 2026? The Breach, Ledger Recover and the Real Risks
An honest risk assessment of Ledger - what the 2020 data leak and the 2023 Connect Kit attack actually exposed, whether Ledger Recover changes the trust model, and where the genuine danger sits.
Targets: is ledger safe
Ledger Hardware Wallet Review 2026 - Is It Still Worth Buying?
A full, independent review of the Ledger hardware wallet range - how the secure element actually protects you, what the 2020 breach and Ledger Recover really changed, and who should buy which model.
Targets: ledger hardware wallet review
Ledger Recovery Phrase - The Complete Guide to Your 24 Words
What the 24-word recovery phrase is, how to back it up so fire and burglary cannot take it, when the 25th-word passphrase helps, and exactly what to do if you think yours is compromised.
Targets: ledger recovery phrase
Get the self-custody checklist
One email a month: new scam patterns, firmware notes worth reading, and the mistakes that actually cost people money. No token shilling, ever.
Replace the form action with your own Formspree / ConvertKit / Buttondown endpoint in src/layout.mjs.