At the end of July, Switzerland’s BACS issued a warning about an attack method that feels almost retro: criminals sending physical letters through the post. Actual paper letters with a QR code, telling recipients to install a supposed security update for their crypto wallet. Anyone who follows those instructions loses their cryptocurrency. Every last coin.
Sounds like a niche problem? It really isn’t. This method has been making the rounds internationally for months – and frankly, it has implications that stretch well beyond the crypto world.
How it works
The letters look convincing. Company logo, correct mailing address, clean layout. They claim to come from manufacturers like Ledger or Trezor – the companies that make hardware wallets for cryptocurrency. The message: there’s an urgent security update, please install it via the enclosed QR code.
Scan the code and you land on a copycat website. There, you’re asked for your recovery phrase – that string of words granting full access to your wallet. Type it in, and the attackers have everything. The money is gone. Permanently. No support ticket in the world will get it back.
Not a Swiss one-off
BACS is responding to reports from within Switzerland, but the attack wave has been rolling internationally for considerably longer. In June 2026, Ledger itself warned about physical letters demanding a “Post-Quantum Cryptography Security Update” – complete with a deadline and the whole nine yards. Trezor users got similar fakes. And the letters were polished enough to make even seasoned crypto users hesitate.
Where do the attackers get the addresses? Security researchers point to the Global-e breach as the likely source. Global-e handled Ledger’s shipping logistics and had access to delivery addresses and order details. After the data leak in January 2026, localised letters started appearing across multiple countries. Classic case of one breach enabling a completely different kind of attack somewhere else.
The scale: CertiK puts crypto phishing losses for January 2026 alone at over $311 million. Full-year 2025 fraud losses hit $17 billion. That’s not niche territory anymore.
Why letters, of all things?
Because they work. It’s that simple.
Most people have learned to be sceptical of dodgy emails. But a letter? Completely different reaction. A printed document on official-looking stationery carries an authority that email simply never will. You think to yourself: who’d go through the effort of printing and posting this if it were fake? The perceived cost of postage acts as a trust signal. Pretty clever, actually.
Then there’s this: when you scan a QR code with your phone, there’s no spam filter, no warning banner, no red-flagged link. Most people just tap through without so much as glancing at the URL.
And – this is the crucial bit – the letters are targeted. Not mass-mailed to random addresses, but personalised post sent to confirmed wallet owners. That makes them far more believable.
What this has to do with SMEs
More than you’d think. Three scenarios:
Companies holding cryptocurrency themselves – whether as a payment method, a reserve, or just because a client paid that way – are direct targets. If there’s a hardware wallet sitting in the office, you need documented processes for managing it. We regularly see businesses during assessments where the recovery phrase is stuck on a Post-it note on someone’s monitor. Not joking.
Then there are employees who own crypto privately and open one of these letters at work. They might scan the QR code on a company phone. Even if the business itself has zero connection to crypto: a phishing page opened on a corporate device can become everyone’s problem.
And then there’s method transfer – which is the truly worrying part. Physical letters with QR codes don’t just work for crypto. The exact same tactic transfers seamlessly to banks, insurers, government agencies, or software vendors. In Switzerland, where QR invoices are part of daily life and practically nobody checks the URL before scanning, the barrier to success is especially low.
What to do
Most important rule first: no legitimate wallet manufacturer will ever ask for your recovery phrase by letter, email, or website. Ever. Under no circumstances. Internalise that and you’re protected against this specific attack.
But the principle extends further. QR codes in unsolicited mail deserve the same suspicion as links in unknown emails. Check the URL before scanning – or better yet, open the manufacturer’s website directly in your browser and look for updates there.
Companies with crypto assets need documented governance. Who has access to the wallet? Where’s the recovery phrase stored? How are transactions authorised? Hardware wallets belong in a safe, recovery phrases at a separate location. Sounds like basics – but we see time and again that exactly these fundamentals are missing.
And at the next awareness training? Put the physical letterbox on the agenda. Not just the inbox.
The bigger lesson
The physical letter with a QR code works as an attack because it exploits a medium we still trust. The lesson for businesses is straightforward: security awareness doesn’t stop at email. Any unsolicited request to enter credentials or install software deserves a pause and a cross-check – whether it arrives by email, phone, WhatsApp, or post.
Our social engineering assessments also cover physical attack vectors – manipulated letters, USB drops, on-site penetration tests. Sounds exotic, but it hits the mark with surprising regularity. If you want to know how your staff respond to these scenarios: get in touch.
Sources and further reading: BACS Current Incidents, CryptoTimes: Ledger warns of mail phishing, BleepingComputer: Snail Mail Crypto Attacks, Hackread: Ledger Seed Phrase Phishing