Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
Letters carrying a QR code urge a supposedly urgent wallet update on grounds of quantum resistance and lead to a page that asks for the recovery phrase. The Federal Office for Cybersecurity reported the ploy on August 18, 2026.

If a letter arrives in your postbox urging an urgent security update for your crypto wallet and supplying a QR code for it, that is phishing. No manufacturer and no exchange announces a wallet update by post, and there is no legitimate process in which you type your recovery phrase into a website. The Federal Office for Cybersecurity BACS reported on August 18, 2026, in its weekly review for week 33, that it had received various reports about precisely such letters.
What is new about this wave is the delivery route rather than the ploy. Phishing normally arrives by email or text message, because both cost nothing. A letter costs printing, enveloping and postage, and anyone going to that effort is counting on a hit rate that justifies it. That is exactly why the postal route became interesting to attackers only once they had address lists they knew belonged to crypto owners.
Crypto wallet phishing by letter: what BACS reported on August 18
The sequence the authority describes is short. A letter calls on the recipient to download an urgent update for various crypto wallets. A QR code is enclosed for that purpose. Anyone who scans it lands on a phishing website on which the recovery phrase is to be entered. Anyone typing it in there hands over complete control of the crypto wallet concerned, according to BACS.
BACS names no number of reports and no individual provider in whose name the letters were sent. It speaks of various reports and of various crypto wallets. If you read a more precise figure in an article, check where it comes from: it does not appear in the official notice.
The origin of the warning matters for placing it in context. BACS is the Swiss federal authority for cybersecurity and reports what is reported to it from Switzerland. For you as an investor in Germany, it is relevant all the same, for a substantive reason: the wallet brands are the same, the address stocks come from the same data breaches, and a letter knows no national border if the address list does not. No German official notice with the same wording exists so far. That does not mean nobody here is affected; it means only that there is no documented German figure on it.
A brief prehistory belongs here. As early as July 31, 2026, the same authority had published its own notice about letters with QR codes. The weekly review of August 18 is therefore no first finding, but confirmation that the wave was still running three weeks later.
Why "quantum resistance" works as a pretext right now
The letter justifies the supposed update with the introduction of so-called quantum resistance. What is meant is encryption that still holds once a sufficiently large quantum computer can break the methods in common use today. This is no invented piece of vocabulary. The debate about what quantum computers mean for Bitcoin and other cryptocurrencies has been running for years and is conducted by serious developers.
And that is precisely where the effect lies. A pretext works best when it is half true. Anyone who has heard the term before finds the letter plausible. Anyone who does not know it finds it technical enough not to ask questions. Both groups arrive at the same conclusion, namely that something important is happening here which had better not be ignored.
The difference between the real debate and the letter is banal and decisive all the same: a switch to quantum-resistant methods would be a change to the protocol and to the device software. Such a switch would never begin with users entering their recovery phrase somewhere. A phrase once typed into a web form is lost regardless of any encryption.
The recovery phrase explained: why those twelve or twenty-four words are everything
The recovery phrase, also called the seed phrase, is a sequence of usually twelve or twenty-four words from which all of a wallet's private keys can be calculated. This sequence of words is no supplement to login details and no second factor; it is the complete mathematical basis of your holdings.
Two things follow from that which are often confused in everyday use. First: whoever holds the phrase holds the balance, without your device, without your PIN and without you noticing anything. Second: you will not notice the theft immediately afterwards either, because the wallet on your device continues to look normal. An attacker who has copied down the phrase can wait weeks.
Why a device never asks for the phrase
A hardware wallet is a device that generates the private keys and holds them permanently in a sealed-off chip, so that they never leave the device. That is its entire purpose in life. If a piece of software, a website or a letter asks you for the phrase, it is asking for exactly what the device is built not to release. The request itself is the finding. How to store the phrase properly is described in our guide to storing your seed phrase safely.
QR code in a letter: why quishing bypasses the usual protections
Quishing means phishing via a QR code. The attack is effective because it defeats three layers of protection at once that would apply to an email.
A spam filter does not see a letter. A browser warning for known fraudulent sites often fails to apply, because freshly registered domains are not yet on any list. And the most important layer falls away entirely: with an email you can hover over the link and read the destination before you click. A QR code is meaningless to the human eye. You find out where it points only after scanning, and by then you are already there.
On top of that comes the change of device. The letter lies on the kitchen table; the scanning is done with the phone. With that, the process leaves the very device on which many people keep their security software and lands on the one whose screen truncates the address bar most severely. A domain name that looks wrong at once on a monitor often does not fit into view on a phone at all.

The Ledger letters from April to June 2026: the run-up to this wave
This ploy is not new in German-speaking countries. From late April 2026, customers of the French hardware wallet maker Ledger received printed letters demanding a quantum resistance security update. Cryptopolitan described the construction: professionally printed, with a QR code, and with the recipient's correct model number and order history. Ledger itself publicly confirmed in early June 2026 that the letters are forgeries, and pointed out that the company never asks for the 24-word recovery phrase.
Comparing the two waves shows what has changed. The Ledger letters were tailored to one brand and depended on recipients actually being customers of that brand. The letters BACS reported on in August run, according to the authority, on various crypto wallets. Anyone who has only learned to distrust letters bearing one particular brand name is no longer protected by that.
Hardware wallets comparedWhere the senders get your postal address: data breaches at wallet retailers
A phishing letter needs an address, and one behind which a crypto owner lives with heightened probability. Lists like that do not come about by guessing. The origin lies wherever order data leaks from a retailer or a shipping service provider.
In the Ledger case, the trail leads, on Cryptopolitan's account, to the company's 2020 data breach, in which customers' names, addresses and telephone numbers were stolen. Those data have been in circulation ever since and age slowly, because people rarely move house.
More current is the material from this August. On August 13 we reported on a data breach at the shipping service provider ShipMonk involving Trezor customer addresses, and on August 20 on leaked order data at SafePal. Both are reports from our own coverage rather than from the BACS notice. No public proof exists that precisely these holdings sit behind precisely these letters, and it will hardly be possible to establish that from outside.
In practical terms: if you have ordered a hardware wallet online in recent years, your delivery address is a plausible component of such lists. That is no reason to panic and no security problem with your device. It is the reason why you of all people receive such a letter and your neighbour does not. If you are reconsidering your choice of device, the criteria are in our hardware wallet comparison.
Two weeks' grace instead of time pressure: why this letter is built differently
The most striking detail of the BACS notice is a deadline. The letter grants the recipient more than two weeks, according to the authority. That is unusual for attempted fraud, because attackers otherwise build up artificial time pressure so that nobody stops to think or ask.
The authority classifies the long deadline as something that increases credibility, and that is plausible. A letter leaving you fourteen days reads like an administrative notice rather than a threat. It even allows you to set the letter aside and come back to it later, which reinforces the impression of respectability.
For you, the characteristic therefore inverts. Until now, time pressure counted as a warning sign. With this type of letter, the calm is the warning sign, because no manufacturer attaches a two-week grace period to a security update. Genuine security notices tell you to act immediately, and they reach you in the app or on the manufacturer's website rather than in the postbox.
Genuine firmware update or phishing: how to tell the difference
Firmware is the software that runs on the wallet device itself. It is installed through the manufacturer's official management software, which addresses the device directly and checks the update's cryptographic signature. That route always begins with you, never with a prompt from outside.
Three checks follow from this, none of which requires technical knowledge.
The first is the channel. An update is displayed in the manufacturer's app. It is not announced by post, nor by text message, nor in an email with a call to action.
The second is the question about the phrase. No update process asks for it. Not even when a page claims merely to be "verifying" or "migrating" it.
The third is the address. When you visit a manufacturer's site, you type it in yourself or use your own bookmark. A QR code from an unsolicited letter is no substitute for that.
Related, though technically different, is the attack via fraudulent approval dialogues, in which you disclose no phrase at all but sign a transaction that does something other than what is displayed. How to read such dialogues is something we took apart in our piece on wallet drainers and signature approvals, along with a real manufacturer case in our analysis of the signature gap in the Ethereum app. Neither case has anything to do with the letter, except that both answer the same question: what really lies behind the thing I am confirming right now?

Hardware wallet, software wallet, exchange: whom this attack actually hits
The reach of the attack depends on where your holdings sit, and the three cases differ markedly.
With a hardware wallet, the attack hits you in full as soon as you enter the phrase. There is no body that recovers the transaction and no customer service that freezes the account.
With a software wallet on your phone or in the browser, the same applies. Here too the phrase is the master key. The only difference is that such a wallet sits on a device with internet access anyway and therefore has additional attack routes. An overview of the criteria is in our software wallet comparison.
If your holdings sit with a regulated exchange, by contrast, no recovery phrase exists for you at all, because the keys lie with the custodian. A letter asking for your phrase comes to nothing there. That offers no protection against other ploys, such as forged withdrawal demands, which we covered in a separate piece on phishing around exchange withdrawals.
Regulated crypto exchanges comparedWhat to do if you have already entered your recovery phrase
If you have scanned the QR code and typed in the phrase, speed counts, and the order matters.
First create a new wallet with a new phrase on a clean device. Then transfer the balance from the old wallet to the new one. In that order, because a transfer needs a destination, and the destination has to exist before you send.
The old wallet is permanently unusable afterwards. Changing a password, setting a new PIN or resetting the device do not help, because the phrase applies independently of the device. Whoever has it can set the wallet up again elsewhere at any time.
Expect tax consequences. A transfer between two of your own wallets is no sale in Germany, but it wants documenting, so that nobody later suspects an inflow where there was none. A theft, in turn, cannot readily be claimed as a loss for tax purposes. Both belong on the record, and the tools from our overview of tax tools and portfolio trackers are suited to that. Where actual financial damage has occurred, BACS expressly recommends filing a criminal complaint.
What you can report even without any damage
If the letter reached you but you did not act on it, the letter is worth something all the same. It proves that your address is on a list. Keep it, photograph it, and report it to the manufacturer in whose name it was sent. In Germany, the consumer advice centres and the Federal Office for Information Security accept such tip-offs. And treat future post to the same address with the same distrust, because an address list sold once gets sold on.
Crypto wallet phishing by letter: what to take away
- Remember the one rule that covers every variant. The recovery phrase is never typed in anywhere, except when restoring a wallet on a device you are physically holding at that moment. No update, no verification and no migration needs it. If you are unsure which device maintains this separation cleanly, the hardware wallet comparison helps to place them.
- Check your custody route, not just your postbox. Anyone holding everything in self-custody bears the full risk of this ploy alone. Anyone keeping part of it with a supervised provider shifts this particular risk, but takes on counterparty risk in exchange. Which providers are authorised in the EU is set out in the overview of regulated crypto exchanges.
- Document every move of your holdings straight away. If you switch to a new phrase on suspicion, transfers arise that you will not reconstruct from memory a year later. A tracker from the overview of tax tools and portfolio trackers takes that work off your hands while the data are still fresh.
The real finding of this week is unspectacular and therefore easy to underestimate. The attackers have learned nothing technical; they have learned something about trust. What they have noticed is that paper carries more credibility in a digital environment than an email does, and they are paying postage for it. As long as that pays off, the next wave will not come by email. How the market is developing alongside all this can be read in our Bitcoin price prediction; the price, however, has no bearing on the safety of your phrase.
(As of August 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.






























