1 min read
Add as a preferred source on Google

Fake Ledger Site Targets Recovery Phrases Amid $92.9M Theft Probe

The phishing campaign appeared in Google results as Ledger investigates losses tied to reseller CryptoBilis across three Southeast Asian markets.

Mentioned assets
Hardware wallet beside a smartphone on a dim apartment table / TokenPost.ai
Hardware wallet beside a smartphone on a dim apartment table / TokenPost.ai

A fake Ledger-branded website and application are targeting users’ 24-word wallet recovery phrases as Ledger investigates reported losses linked to reseller CryptoBilis, with estimated theft reaching $92.9 million.

The phishing pages appeared in Google search results and redirected users through cloud-hosting services before sending submitted recovery phrases to attacker-controlled infrastructure. The pages also used the 2,048-word BIP-39 English word list to suggest words as users typed.

Ledger said Oct. 9 that it was investigating reported losses involving CryptoBilis customers in Indonesia, Malaysia and the Philippines. The company asked the reseller to suspend sales and shipments.

The losses were estimated at $92.9 million from 311 wallets across five networks as of 12:45 p.m. ET (16:45 UTC) on Oct. 9. Tether froze $10 million in USDT. Ledger has not confirmed the final amount or number of affected wallets.

The search-based phishing campaign has not been linked to the CryptoBilis-related thefts. A recovery phrase can restore a cryptocurrency wallet, and anyone who obtains it may be able to move its assets without the physical device.

“Never enter your 24 words – there is no good reason to type your recovery phrase into a computer,” Ledger said. Users who already set up a device should consider moving assets to a new Ledger signer with a new seed.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…