A Ledger transaction check letter does not arrive in your inbox. It arrives in your mailbox, printed on company letterhead, addressed to you by name, sometimes with a hologram in the corner and a signature at the bottom. It tells you a mandatory check is due by a date a week or two away, and it prints a QR code for you to scan. Everything about the presentation is designed to bypass the instinct you have built up about crypto scams, because you learned to distrust email and nobody ever taught you to distrust the post.
The letters are fake. Scanning that code and typing what the page asks for hands your wallet to somebody else, and the people running this have gone to more expense than any phishing email has ever justified.
What the Ledger transaction check letter asks for
Ledger owners started reporting these in October 2025, with letters demanding they complete a "Transaction Check" procedure. Scanning the code opens a domain built to look official, along the lines of ledger.setuptransactioncheck.com, which belongs to nobody at Ledger. From there the page asks for your recovery words in 24, 20 or 12-word form, claiming it needs them to verify device ownership, and whatever you type travels to the attackers through backend endpoints. Once they hold those words, they import your wallet on their own machine and empty every account it derives.
Notice what the letter never mentions. There is no request for a password, no login screen, no payment. The whole operation is built around one ask, dressed up as routine maintenance, because the recovery phrase is the only thing worth stealing and the only thing a hardware wallet company will never need from you.
The Trezor version, and the signature that gives it away
The same playbook ran against Trezor owners in February 2026. Security researcher Dmitry Smilyanets posted the letter he was sent, printed on impersonated letterhead and asking him to enable an "Authentication Check" by 15 February to avoid losing access to Trezor Suite. Naming a deadline days away is the entire mechanism here, because a reader who has time to think about it will not scan anything.
One detail is worth holding onto. Coverage of the campaign noted a forged signature attributing one letter to Matěj Žák, described as the CEO of Ledger, when Žák runs Trezor. The people who paid for holograms and letterhead did not check which company their own executive works for, and that class of mistake turns up in most of these letters if you slow down enough to look for it.
Why the envelope has your name and your address on it
This is the part that unsettles people, and the explanation is mundane. Your address is in a leaked file.
In June 2020, a website vulnerability at Ledger exposed customer contact details, and the following December an archive drawn from it was published on a hacker forum for anyone to download. The breach record at Have I Been Pwned lists more than a million email addresses along with names, phone numbers and postal addresses, and Ledger's chief executive addressed the leak publicly at the time, making a point that still holds: the leaked records have no connection to the funds sitting in anybody's wallet.
The list has been topped up since. On 5 January 2026, Ledger confirmed that a breach at its e-commerce partner Global-e had exposed names, postal addresses, email addresses, phone numbers and order details, including which products each customer had bought, while stressing that its own systems and devices were untouched. We covered that incident in Ledger's January 2026 data breach, and Trezor owners had their own exposure in the Trezor data breach.
So a stranger can know your name, your street, and the exact model sitting in your desk. Address records do not expire, which is why letters keep arriving years after the original leak, and why a wallet you bought in 2020 can still generate mail in 2026.
What to do when one arrives
- Do not scan the code. Photograph the letter, then set it aside somewhere you will not absent-mindedly return to it.
- Report it. Ledger and Trezor both take reports of these campaigns through their official support channels, reached by typing the company's address into your browser rather than following anything printed on the page in front of you.
- Tell the people around you, especially anyone in your household who might open your post. The attack works on whoever reads the envelope first.
- Check nothing on the device. There is no maintenance task, no deadline, and no functionality to lose.
- Take the reminder for what it is worth: if your address leaked, treat every unsolicited approach about your wallet, by post, phone or message, as hostile until proven otherwise.
The rule underneath all of this fits in one line: nobody legitimate will ever ask you for your recovery words, and that holds for the manufacturer, for a support agent, for a courier at your door, and for us.
The phrase is the weak point, and it does not have to be
Step back from this particular scam and look at what makes it viable. Somewhere in your home is a set of words that grants complete access to everything you own in crypto, and every attack of this kind is an attempt to talk you into reading them out. Phishing letters work because a single seed phrase is a single point of failure, and once it leaves your possession there is no revoking it, no freezing anything, and no support desk that can undo it.
Writing the words on paper is the weakest arrangement available. Stamping them into steel is the standard upgrade and survives fire and flood, though your whole position still rests on one object staying unread by everyone who ever comes near it. TapSafe Recovery takes the single point of failure out of the design: your Recovery Tag holds half of what is needed to restore the wallet, your paired phone holds the other half encrypted in your own iCloud or Google Drive, and optional Recovery Contacts hold a quarter each. Somebody who talks you out of one piece gets nothing, because no single component opens the wallet on its own. The seed phrase remains available on the device as a last resort under the BIP-39 standard, so you keep the escape hatch without carrying it around as your daily exposure.
A wallet built for a world where your address is public
Your data is out there and it is not coming back, so the sensible response is to hold your crypto in a way that survives somebody knowing exactly who you are and what you own.
The Ryder One generates keys inside an EAL6+ certified Infineon SLC38 secure element that they never leave, and every transaction renders in readable detail on the 1.6-inch AMOLED touchscreen before you approve it. Setup runs in about 60 seconds across three taps, with no words to copy out by hand and no slip of paper to hide, and the firmware was independently audited by Halborn with the full report published in the open. The Starter Combo is 149 USD, and the Super Safe Combo is 179 USD.
Bin the letter, and then ask how many places somebody would have to reach to assemble a complete copy of your recovery today. See the Ryder One.
Meta description: A Ledger transaction check letter in your mailbox is a phishing scam. Why it has your address, what the QR code does, and what to do when one arrives.




Share: