Original language : English
Date : Thu 10 Sep 2026 05:48:36
Project : Trezor
Author : Anonymous
Risk : Danger
Category : software wallet
Physical phishing: scammers are mailing out fake paper letters in Trezor's name

Scammers have stepped out of the digital realm and moved on to good old-fashioned paper mail. On the r/CryptoCurrency forum, user _TheWolfOfWalmart_ sounded the alarm, warning the community about a new scam scheme. People have started receiving physical letters through regular mail that look like official mailings from hardware wallet maker Trezor.

According to _TheWolfOfWalmart_, the letter looks quite solid, but checking the QR code reveals that it leads to a phishing site rather than the official Trezor domain. Yet the scammer's biggest — and most comical — failure was plain carelessness. In the first version of the letter, they forgot to proofread the text and signed it: "Matej Zak, Ledger CEO". In other words, the scammers simply mixed up their competitor's brands.

Trezor

However, the fraudsters quickly learned from their mistakes. According to user Dusted7, in subsequent batches of letters the signature was corrected to "Trezor CEO". Users virtuzoso and Manitcor confirmed that the scammers even started sticking holographic stickers bearing the Trezor logo onto the letters to give them maximum credibility. User Sweet-Article559 also received one of these mailings with a hologram and noted that the barcode smears easily, even though the letter looks frighteningly plausible at first glance.

The comments also covered why these addresses surfaced. User noviwu97 rightly pointed out that the Trezor customer database did in fact leak online, although the crypto community more often brings up the high-profile Ledger breach. The post's author, _TheWolfOfWalmart_, clarified an important detail: the data leak doesn't make Trezor hardware wallets themselves vulnerable — only customer's mailing addresses have been compromised. User Justanotherlunatic, meanwhile, received a letter despite never having bought a Trezor device. In his view, data traders on the black market simply buy up merged databases of everyone who has ever purchased crypto hardware.

There was room in the thread for practical advice, too. According to user According-Regret-311, mailing out fake letters is genuine mail fraud, and it carries real penalties. He urged everyone who received such a letter to take the trouble and file a complaint with the United States Postal Service.

If you happen to find a message from Trezor in your mailbox, just throw it away — and whatever you do, don't scan the QR codes.

url

domain explore registered registrar abuse email score average
trezor.authentication-info.io Jan. 6, 2026 Global Domain Group LLC [email protected] 2/100 2.0
Blacklist: NoCoin Hexxium QuidsUp URLhaus FadeMind MetaMask Phishunt Badd-Boyz BlackBook CoinMiner OpenPhish ThreatFox TweetFeed PhishRadar Scam Block Abuse Block Phishing DB ScamSniffer PhishDestroy Malware Block Phishing Army Toxic Domains Filters Heroes GlobalAntiScam Phishing Block Pi-hole Trojan Scam Blocklist Fraud Blocklist Pi-hole Malware Crypto Blocklist Pi-hole Phishing Ransomware Block CyberHost Malware Pi-hole Malicious Pi-hole C2 Servers Thread Intelligence PhishDestroy Community
authentication-info.io Jan. 6, 2026 Global Domain Group LLC [email protected] 2/100 2.0
Blacklist: NoCoin Hexxium QuidsUp URLhaus FadeMind MetaMask Phishunt Badd-Boyz BlackBook CoinMiner OpenPhish ThreatFox TweetFeed PhishRadar Scam Block Abuse Block Phishing DB ScamSniffer PhishDestroy Malware Block Phishing Army Toxic Domains Filters Heroes GlobalAntiScam Phishing Block Pi-hole Trojan Scam Blocklist Fraud Blocklist Pi-hole Malware Crypto Blocklist Pi-hole Phishing Ransomware Block CyberHost Malware Pi-hole Malicious Pi-hole C2 Servers Thread Intelligence PhishDestroy Community

source

https://www.reddit.com/r/CryptoCurrency/comments/1r8lic8/psa_fake_scam_letters_being_sent_out_claiming_to/

Trust Rating

2
98
Scam Credential Harvesting Phishing Reply