18/08/2026
🎣 PHISHING HAS ARRIVED — BY POSTAL MAIL
An important real-world case shared by our Network, demonstrates how cybercriminals are combining leaked personal data, traditional postal services, QR codes and professional-looking websites to steal cryptocurrency.
A person received a letter at his home address bearing a French postal mark. The letter was printed on high-quality paper, reproduced Ledger’s visual identity, included his full name and contained a QR code leading to a highly convincing imitation website.
It looked professional. It appeared personal. It created urgency.
And it was phishing.
The letter claimed that the recipient urgently needed to activate supposed “Quantum Resistance” protection. It imposed a short deadline and warned that access to the recipient’s funds could be restricted if the alleged security update was not completed.
After scanning the QR code, the victim was directed to a website designed to closely imitate Ledger. The process guided the user through several apparently legitimate steps: selecting a hardware wallet, reading an explanation about supposed quantum protection and finally entering the wallet’s recovery words - also known as the seed phrase.
That is where the deception ends and the theft of cryptocurrency begins.
The fraudulent domain was pulsematrixledger[.]com—not ledger.com.
A legitimate hardware-wallet manufacturer will never ask users to disclose their seed phrase through a website, QR code, email, telephone call, text message or postal letter.
How did the criminals obtain the victim’s physical address?
The Ledger device had been purchased directly from the manufacturer in 2020, which remains the recommended way to purchase a hardware wallet. However, Ledger’s e-commerce and marketing database was compromised in 2020. Information relating to approximately 272,000 customers - including names, telephone numbers and postal addresses - was subsequently published online.
The stolen information did not become harmless simply because several years had passed.
Once personal data has been leaked, copied and distributed, criminals may retain it indefinitely, combine it with information from other sources and reuse it in future fraud campaigns. A historical data breach can therefore create a long-term security risk for affected individuals.
This case also highlights an important misconception: phishing is intended to steal electronic information, but the delivery channel does not have to be electronic.
The bait may arrive through:
• Email
• SMS or messaging applications
• Social-media platforms
• Telephone calls
• QR codes
• Physical documents delivered by post
This attack can therefore be described as a combination of physical phishing, QR-code phishing - or “quishing” - brand impersonation and targeted social engineering.
The reference to “quantum resistance” was another layer of manipulation. Quantum-resistant security cannot be activated by scanning a QR code and entering a seed phrase. It depends on the cryptographic algorithms, protocols and address or output types used by the relevant blockchain network.
With Bitcoin P2WPKH addresses, the public key remains concealed behind a cryptographic hash until the UTXO is spent. This does not provide complete quantum resistance, but it offers an additional layer of protection while the public key remains undisclosed. With Taproot/P2TR outputs, by comparison, the public key is visible when the output is created.
Quantum computers may eventually pose a more serious threat to today’s public-key cryptography than to cryptographic hash functions. However, no legitimate “quantum security update” requires users to disclose their seed phrase.
🔐 The fundamental rule remains unchanged:
Never enter your seed phrase into a website.
It should only be entered directly into the appropriate hardware wallet—and only when genuinely necessary, such as during a legitimate wallet-recovery process initiated by the owner.
Before taking any action:
• Do not scan QR codes simply because they appear in a professional document.
• Examine the domain character by character.
• Do not trust a message merely because it contains your correct personal information.
• Independently open the manufacturer’s official application or manually type the verified website address.
• Confirm security announcements through official channels.
• Never disclose recovery words, private keys or authentication credentials.
• Treat artificial urgency, threats and short deadlines as major warning signs.
Professional presentation is not proof of authenticity. Correct personal information is not proof of legitimacy. A physical letter is not automatically safer than an email.
Cybercriminals understand that people often lower their guard when communication arrives through a traditional and seemingly trustworthy channel. That is precisely why this attack is so effective.
The most important lesson is simple:
Your seed phrase is the key to your assets. Anyone who obtains it can control the wallet—and blockchain transactions are generally irreversible.
Credit and thanks to our Network for documenting and sharing this highly relevant case and raising public awareness of an evolving cybercrime technique.