Crypto Wallet Phishing by Letter: Scammers Use QR Codes to Steal Private Keys
Crypto wallet phishing by letter has become a new threat in the crypto space. The Federal Office for Cybersecurity BACS reported on August 18, 2026, that it had received various reports about letters arriving at people's postboxes urging an urgent security update for their crypto wallets and supplying a QR code for it.
No legitimate process exists where you type your recovery phrase into a website, and manufacturers and exchanges do not announce wallet updates by post. The letters are phishing attempts that aim to steal users' private keys by getting them to enter their recovery phrases on a fake website.
The attackers use a QR code in the letter to defeat three layers of protection: spam filters don't see letters, browser warnings often fail to apply because freshly registered domains aren't yet on any list, and you can't hover over a link to read its destination with a QR code.
These letters are likely sent in batches using address lists obtained from data breaches at wallet retailers. The Ledger company received printed letters in April 2026, and BACS reported that the current wave affects various crypto wallets, not just one specific brand.