Loading prices…
🩸BEARISH

Fake Ledger Phishing Site Tops Google With 1M Visits

The campaign targets 24-word recovery phrases and follows earlier malicious Google ads that redirected Ledger users to fake verification pages.

Fake Ledger Phishing Site Tops Google With 1M Visits
Fake Ledger Phishing Site Tops Google With 1M Visits

Cybersecurity researcher Cyber Scrilla discovered a fraudulent Ledger website and application appearing at the top of Google Search and designed to capture users' 24-word recovery phrases. Google reportedly displayed more than 1 million visits to the site over the past 30 days.

Why it matters

The discovery comes amid investigations into an estimated $86 million in wallet thefts linked to Southeast Asian reseller CryptoBilis. It adds search visibility to the threat model for Ledger users, who may mistake a prominent result for an official wallet-verification page.

Market impact

The campaign follows a September investigation by cybersecurity firm Zscaler, which found malicious Google ads impersonating Ledger and redirecting users to fake verification pages. The activity highlights how compromised search placement can turn seed-phrase theft into a broader wallet-security risk.

Recovery phrases give control of self-custody wallets, making requests to submit all 24 words a critical phishing warning. Ledger users should verify that they are using official channels before entering any recovery information.

Frequently asked questions

  1. What is the fake Ledger site designed to steal?

    The fraudulent site and application are designed to trick users into submitting their 24-word wallet recovery phrases.

  2. How much traffic did Google reportedly show for the phishing site?

    Google reportedly displayed more than 1 million visits to the site over the previous 30 days.

  3. How is the campaign connected to CryptoBilis investigations?

    The alert comes amid investigations into an estimated $86 million in wallet thefts linked to Southeast Asian reseller CryptoBilis.

  4. What did Zscaler find in its September investigation?

    Zscaler uncovered malicious Google ads impersonating Ledger and redirecting users to fake wallet-verification pages.

  5. Why are search rankings significant in this Ledger phishing campaign?

    A prominent Google result can make a fraudulent wallet-verification page appear legitimate, increasing the risk that users submit their recovery phrases.

Source attribution
Aggregated from WuBlockchain · Verified · Last refreshed 1h ago
Open original →