Crypto Phishing by Postal Mail: when the QR code lurks in your mailbox

Phishing by postal mail

Phishing usually arrives by email or text message, but recently the scammers have started using a channel that most people don’t even have on their radar: good old-fashioned postal mail. The BACS recently warned about fake letters containing a QR code, supposedly from a crypto wallet provider, with the letter urging recipients to scan the QR code in order to perform an “urgent update” for their wallet.

Sounds absurd, but it works anyway because physical letters carry a certain authority that an email simply cannot match (when was the last time you threw away a letter without reading it?).

How the attack works

The letter looks professional and claims the crypto wallet needs to be updated for security reasons, with a QR code in the letter leading to a phishing website that closely resembles the genuine wallet provider’s site.

There you are asked to enter your recovery phrase – the 12 or 24 words that can restore your wallet – and anyone who does this faces a serious problem, because with the recovery phrase the attackers can seize complete control of the wallet, after which all cryptocurrency gets transferred to other wallets within minutes. The insidious part is that no technical vulnerability is being exploited; rather, the user enters their credentials voluntarily, or at least believes they are doing so.

Not the first QR code scam

The trick with fake QR codes in the physical world is by no means new, since back in June 2026 the BACS warned about forged Swiss Post pickup notices where scammers placed yellow “Avis de passage” cards in mailboxes with a QR code leading to a fake Post website. Personal data and credit card information were collected there, disguised as a small delivery fee of about 2 to 4 francs.

At the time, this was mainly confined to western Switzerland, but the crypto variant is now apearing nationwide.

Why physical mail

Email phishing is getting detected better and better, spam filters catch a large portion of malicious messages and people have (hopefully) become more careful, which means a physical letter bypasses all of these protective mechanisms completely: no spam filter, no “suspicious” warning in the inbox, no link to hover over and check the URL before clicking.

On top of that, whoever receives a letter tends to take it more seriously than an email, which is psychologically understandable but also precisely what the attackers exploit…

Protection

No legitimate wallet provider sends letters asking you to enter your recovery phrase, because the recovery phrase belongs exclusively to the owner and should never, under any circumstances, be entered anywhere online (with the sole exception being the initial setup of the wallet on a new device).

If you receive such a letter, simply throw it away, and if you are unsure whether a letter might be genuine, navigate to the provider’s official website directly in your browser – not through the QR code.

If you want to test your organization against these kinds of social engineering attacks: that is exactly what we are here for.

Details on the warning from the BACS.

And whether the next phishing letter will arrive by registered mail…