Phishing Scam Targets Crypto Wallet Owners via Postal Letters
A new wave of phishing attacks has been reported in Switzerland by the Federal Office for Cybersecurity BACS, targeting crypto wallet owners via postal letters. The scam involves a letter claiming to be an urgent security update from a wallet manufacturer, complete with a QR code that, when scanned, directs the user to enter their recovery phrase on a phishing website.
The attackers are using address lists obtained from data breaches at wallet retailers or shipping service providers. This approach is more expensive than traditional email-based phishing, but it increases the likelihood of a successful attack due to the higher perceived legitimacy of physical mail.
According to BACS, the scam is attempting to exploit the concept of quantum resistance, which has been discussed in the crypto community for years. However, a legitimate update to a wallet's protocol or device software would never require users to enter their recovery phrase on a website.
The phishing letters are addressed to various crypto wallets and not limited to one specific brand. This is a change from previous waves of this type of attack, which targeted specific brands such as Ledger.