crypto scammers phish with physical mail

crypto scammers phish with physical mail

🎙 John Hammond 👥 2.2M 📅 March 4, 2026 ⏱ 10 min 👁 15K 📄 news review 🧭 2026-08-16
Available in: English (current) Français

Keywords

phishingcryptocurrencyTrezorLedgerphysical mail

Summary

In this video, John Hammond discusses a novel phishing campaign targeting cryptocurrency hardware wallet users (Trezor and Ledger) through physical mail. The scam involves sending letters that instruct recipients to scan a QR code to complete an ‘authentication check’ before a deadline, threatening limited access to their wallets. The QR code leads to a fraudulent website designed to steal recovery phrases. Hammond analyzes the scam’s mechanics, noting that the website is now down but was previously active. He highlights the use of urgency and social engineering tactics. He also explores how scammers obtain physical addresses, referencing a BreachForums post selling Ledger customer data. Additionally, he discusses a blog post by Jeremy that details how the phishing website exfiltrated data to a Telegram bot, and how the bot was disrupted. The video emphasizes the importance of never sharing recovery phrases and staying vigilant against such attacks.

145 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into a real-world phishing campaign, demonstrating the evolution of social engineering tactics. The argumentation is solid, supported by multiple sources and a technical breakdown of the scam’s infrastructure. Hammond effectively explains the attack chain, from physical mail to data exfiltration, and offers practical advice for users. The inclusion of a technical analysis by Jeremy adds depth, showing how the scam was disrupted. The video is well-structured and informative, though it relies on unverified forum posts for some claims.

92 words

Title / Content Match

The title accurately reflects the content, which focuses on a phishing scam delivered through physical mail.

Quality & Reliability

8/10

The video provides a detailed analysis of a real-world phishing campaign targeting cryptocurrency hardware wallet users via physical mail. It references multiple credible sources, including BleepingComputer and a technical blog by Jeremy, and demonstrates hands-on investigation techniques. The information is current and well-contextualized, though some claims rely on unverified forum posts.

Key Moments

Cited Sources

Concurring Sources

  • Scammers targeting crypto users via mail — Confirms the existence of the physical mail phishing campaign.
  • Snail-mail letters target Trezor and Ledger users in crypto theft attacks — Independent coverage of the same campaign.

External References

Contribution & Novelties

This video brings attention to a novel phishing vector: physical mail. It provides a detailed case study of how scammers combine traditional mail with digital phishing techniques to target cryptocurrency users. The analysis includes a technical breakdown of the scam’s infrastructure, including the use of Telegram bots for data exfiltration, and demonstrates how such operations can be disrupted. The video also highlights the importance of threat intelligence platforms like Flare in monitoring cybercrime activities.

Pour aller plus loin :

  • Phishing — Overview of phishing techniques.
  • Social engineering (security) — Explanation of social engineering tactics.
  • Telegram Bot API — Official documentation on Telegram bots, relevant to the exfiltration method.

108 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a well-researched and accessible video for a broad audience.

Reliability 8/10

💬 No comments were provided for analysis.