As Ledger investigates more than $86 million in suspected losses tied to its Southeast Asian reseller CryptoBilis, fraudsters are exploiting the fear. Security researcher Cyber Scrilla flagged on October 10 that a fake Ledger website and application were appearing prominently in Google Search results, designed to trick users into surrendering their 24-word recovery phrases, Bitcoin News reported.

The impersonation campaign reportedly displayed a claim of more than one million visits over 30 days. That figure deserves skepticism: as crypto.news notes, no verified count of visits to the malicious domain exists, and a September investigation by Zscaler ThreatLabz found that a similar "1M+ monthly visits" badge shown on a malicious Google advertisement actually referred to Google itself — making the ad look more trustworthy without saying anything about the phishing destination.

A Documented Playbook

Zscaler's September 25 analysis documented how these campaigns against Ledger users operate:

  • Malicious Google ads ran through a verified advertiser account, targeting Ledger-related searches in the U.S., Europe and parts of Asia.
  • Clicks were redirected through Google Cloud Storage and Vercel — with redirect addresses rotating roughly every 15 to 20 minutes to defeat blocking — before landing on a fake Ledger page built on Google Sites.
  • The page offered downloads for Windows, macOS, Linux and mobile, then showed misleading connection and firmware-update messages before asking users to "verify" device ownership by entering their recovery phrase.
  • The form auto-completed suggestions from the list of 2,048 recognized recovery words. After submission, it displayed an error claiming the phrase was invalid and asked the user to enter it again — sending both copies to the attacker.

Zscaler found no evidence the page performed any legitimate verification. There is also no established connection between this phishing infrastructure and the CryptoBilis losses: the reseller incident concerns devices from a specific distribution channel, while researchers have not demonstrated that the phishing site caused any of those drains.

The Broader Pattern

The campaign is part of a persistent wave of recovery-phrase theft against hardware wallet users. In February 2026, a phishing operation targeted Ledger and Trezor users with physical letters carrying QR codes that led to fraudulent verification pages. In August, a user reported losing life savings through a fake Trezor Google advertisement. In the current climate, users searching for Ledger support or setup help are the primary target — and a top-ranked fraudulent result can reach them before the official site does.

Ledger's guidance is unchanged: never type a recovery phrase into any website, downloaded application or online verification form, obtain wallet software only from the official site, and remember that no legitimate support channel will ever ask for the 24 words. Anyone who has exposed a phrase should move remaining assets to a wallet generated from a new one.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.