Over time, crypto wallet phishing campaigns have evolved from simple “fake login” pages to complex, multi-stage social engineering tactics and automated exploitation of infrastructure. The NJCCIC has noted an increase in phishing efforts aimed at stealing cryptocurrency seed phrases, including a campaign impersonating Ledger.

The messages use official Ledger branding and logos and appear to come from an official-looking email address. They claim a critical firmware update is available and include a URL pointing to a Ledger-themed domain. The link leads to a polished clone of the vendor’s site that requests the 24-word seed phrase, claiming it is required to complete the update. Once shared, these seed phrases grant attackers full control of victims’ cryptocurrency wallets. Other Ledger-related phishing attempts include physical mailers, claims of new multi-factor authentication (MFA) requirements, and legitimate support tickets followed by a prompt phone call from the threat actor.
Recommendations
- Avoid clicking links, opening attachments, responding to, or acting on unsolicited communications.
- Confirm messages from senders by verifying their contact information obtained from trusted and official sources before taking action, such as clicking on links or opening attachments.
- Always refrain from sharing your private key, seed phrase, or secret recovery phrase with anyone.
- Keep systems and apps up to date.
- Review the NJCCIC Cryptocurrency Scams webpage for additional information, recommendations, and resources.

