Skip to blog content

    Quality Crypto Reporting · Primary Sources Researched

    CryptoWorkPro

    Market context

    Powered by CoinStats APIUpdated 8:22 PM

    BTC-0.51%
    $84,385
    ETH-1.25%
    $2,669
    XRP-1.91%
    $1.47
    SOL-0.31%
    $118.01
    BNB-0.38%
    $766.15
    HBAR-3.45%
    $0.0997
    QNT-10.93%
    $229.3
    TRX-0.35%
    $0.3346
    LINK-5.82%
    $13.63
    XLM-3.38%
    $0.2115
    Back to Blog
    Wallets & Security

    Don't Scan the QR Code on That Ledger Letter. It Wants Your 24 Words.

    Published September 27, 2026

    Ledger's May 13, 2026 page says fake postal letters tell you to scan a QR code and type your recovery phrase. Ledger almost never mails customers.

    Don't Scan the QR Code on That Ledger Letter. It Wants Your 24 Words.

    A letter arrives with Ledger branding. It talks about a security notice, a verification process, or a "transaction check." A QR code sits on the page. People photograph these envelopes and ask on X, YouTube, Instagram, and Reddit whether they should scan them.

    Ledger's own pages describe that pattern as phishing. The target is the 24-word Secret Recovery Phrase, the list that can recreate the wallet. Do not scan the code. Do not type those words into a website.

    What Ledger's pages say about the letter

    Ledger Support's article Physical Mail Phishing Scam, last updated May 13, 2026, says scammers send fraudulent postal letters that pose as official Ledger communications. The letters often claim there is an urgent verification process or security notice. They pressure the reader to enter the Secret Recovery Phrase on a website or to scan a QR code that leads to a phishing site.

    Ledger says it almost never sends physical mail to customers. It says it will never ask anyone to enter the Secret Recovery Phrase online or by phone. It also says it will never request a QR scan or a visit to an external website in order to input that phrase.

    One example on that page is a "Transaction Check Notice." The letter claims that activating transaction check requires scanning a QR code. Ledger says the destination is a fraudulent site built to collect the recovery phrase.

    Ledger's ongoing phishing campaigns page documents the same postal method. The letters vary in format and subject. They prompt a QR scan, a visit to a printed website, or both, and then ask for the 24 words. Ledger's line on that page is direct: there is never a good reason to type the recovery phrase into a computer. Anyone who has the phrase has full access to accounts created from it.

    Another letter variant on that page claims Ledger opened vault addresses for specific users. It implies, without stating it outright, that the reader should send funds to those addresses. Ledger says that claim is not true. Do not send cryptocurrency to an address from the letter.

    The same page says to treat a so-called Ledger message that arrives by text, WhatsApp, Telegram, phone call, or postal letter as a phishing attempt. Ledger says it will never contact users by text or phone. Official domains listed there include ledger.com, ledger.fr, ledgerwallet.com, and ledger.zendesk.com. Look-alike spellings exist. Report a fake letter to phishing@ledger.fr. Download Ledger Wallet, formerly Ledger Live, only from ledger.com/ledger-live.

    Ledger documents phone impersonation as a separate campaign. This article covers the letter.

    How the QR code is used

    A QR code is a square barcode. A phone camera can read it and open a website. That convenience is the trap when the code arrives in unexpected mail.

    The FBI's Internet Crime Complaint Center, in PSA220118, says criminals use malicious QR codes to send people to sites that steal login and financial information. After a scan, check the URL. Do not download an app from a QR code. Use the phone's official app store. The FBI notes that law enforcement cannot guarantee recovery after funds move.

    The FTC's December 6, 2023 alert, Scammers hide harmful links in QR codes to steal your information, says not to scan an unexpected QR code, especially one that urges immediate action. If the message might be real, contact the company through a website or phone number you already know.

    Ledger's mail pages and the FBI and FTC alerts describe different pieces of the same reader problem. Ledger describes letters that use a QR code to collect a recovery phrase. The federal alerts describe why an unexpected code is a poor way to reach a real company.

    What to do if the letter is already in your house

    Do not scan the code. Do not visit a URL printed on the letter. Do not enter the 24 words. Do not send crypto to any address in the letter.

    Contact Ledger only through support.ledger.com, typed yourself. Report the mailing to phishing@ledger.fr. In the United States, you can also report it at reportfraud.ftc.gov and the FBI's Internet Crime Complaint Center.

    If you scanned the code but entered nothing, close the site. Do not install software from it. Ledger's documented theft method for this campaign is the recovery phrase. The FBI and FTC also warn that a QR destination can be a fake login page or a malware download, so treat that site as untrusted.

    If you typed the 24 words anywhere, treat that phrase as compromised. Ledger's guide How to change your recovery phrase and create new accounts, last updated August 28, 2026, says to move remaining assets first to accounts that come from a different phrase, then reset the device and set it up as new so it generates a new phrase. Changing the PIN is not enough. Do not reuse the old words.

    What remains unknown

    CryptoWorkPro has not inspected a specific letter, QR destination, or customer account. The Ledger pages cited here do not say how mailing addresses were obtained, how many letters were sent, or a confirmed loss total. Those facts stay unknown.

    Sources

    Disclosure: This article summarizes Ledger's May 13, 2026 physical-mail phishing page, Ledger's phishing-campaigns status page, Ledger's August 28, 2026 recovery-phrase reset guide, and FBI and FTC QR-code alerts. It does not inspect a specific letter, QR destination, or customer wallet. The featured image is a generated editorial illustration, not a photograph of a real letter. This article is not financial, legal, or investment advice. AI-assisted research and writing. Cited sources, not AI alone, support the claims.