Fake Ledger Site Tops Google Search: “Once the recovery phrase has been handed over, the wallet must be regarded as compromised”
A security researcher reports a rebuilt Ledger site high up in Google's results that asks for the 24-word phrase. Running alongside it are emails with an invented deadline of October 15.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Anyone searching for the software for a Ledger hardware wallet through a search engine can currently land on a copy. On Saturday the security researcher Cyber Scrilla reported a counterfeit Ledger site together with a matching app, which appeared high up in Google's organic results and asks visitors for their 24 words. Those 24 words are the access to the entire balance. Anyone who types them in loses control of the wallet, even if nobody ever had the device itself in their hands.
For holders in Germany what follows is not another checklist for suspicious emails but a habit: wallet software is reached through a bookmark or an address typed in yourself, never through the search box. This article sets out what has been reported, how a counterfeit gets to the top at all, and what to do if the phrase has already been entered.
Counterfeit Ledger site in Google search: what security researchers have reported
The report goes back to the security researcher Cyber Scrilla, who on Saturday pointed to a rebuilt Ledger site and an app belonging to it. Both are designed to ask for the 24-word recovery phrase. Coinfomania reports that the site gathered more than a million visits over the past month, and traces the figure back to Google data.
Caution is in order with that figure. Other reports from the same day take over the order of magnitude but write it down expressly as a claim and name no measurement basis of their own. What is robust is therefore the direction, not the decimal place: the counterfeit reached not a few dozen people but a number on the order of a mid-sized German city. The reports do not name the domain concerned, which makes checking harder for readers.
Also important for the assessment is what has not happened here. There is no indication that Ledger's hardware has a flaw or that the company has lost keys. What is under attack is the route to the manufacturer, not the product.
Recovery phrase: why 24 words are the actual point of attack
The recovery phrase, often called the seed phrase, is a list of usually 24 words from which all the private keys of a wallet can be calculated. This word list does not work like a password that can be reset. Whoever holds it holds the balance.
From that follows the hard rule behind every hardware wallet: the phrase never leaves the device and the piece of paper. No manufacturer, no support desk, no verification page and no update needs it. A hardware wallet is secure precisely because the keys never leave the device; an input field in the browser undoes that protection in a single step. It is kept offline, on paper or stamped metal, and in a place only the owner knows.
The forensic analyst Albert Quehenberger is quoted by BTC-Echo with the sentence: "Once the recovery phrase has been handed over, the wallet must be regarded as compromised." That is the technical consequence, not a formula of caution. An attacker who knows the words can rebuild the wallet on any device and has nothing further to overcome.
Search poisoning and malvertising: how a copy reaches the top of the results list
A fraudulent site standing at the top of search is no accident and no sign of a hacked search engine either. Two mechanisms work together here, and both are cheaper than many assume.
The first is paid placement. Whoever books an advertisement on a brand name lands above the first unpaid result. The security firm Zscaler had already found malicious Google adverts in September that passed themselves off as Ledger and led users to counterfeit verification pages; Coinfomania points to that in its report. Adverts are reviewed, but review takes time, and a few hours of run time are already enough.
The second is organic placement, and it explains the present case. A copy of the genuine site inherits its structure, its texts and its terms. If enough links from other sites are added, the search engine rates the copy as a fitting answer to a brand query. Specialists call that search poisoning: the results list stays technically correct, only at the top of it stands the wrong address.
On this hangs the insight that sets this case apart from the usual phishing waves. Until now search counted as the safe route and the unexpected email as the dangerous one. That order no longer holds. Anyone wanting to check which device and which software actually fit their own requirements will find the models with their differences in custody and operation in the hardware wallet comparison.

The invented deadline of October 15: how the Ledger emails are built
Alongside the counterfeit site, counterfeit emails are running. BTC-Echo describes messages that warn in Ledger's name of a security flaw and demand a manual security update by October 15, 2026. That deadline does not exist; it is the lever of pressure.
The pattern is well known in fraud research and doubly effective in this case, because an incident genuinely is under way. A real news situation makes the false email plausible. Added to that are counterfeit support requests in which, according to BTC-Echo, attackers pose as helpers after a supposed security incident and ask for credentials or have transactions approved.
Three features carry through almost every one of these emails: a date that creates haste, an action that is supposed to take place in the browser, and a request that goes beyond a plain login. If the date is missing, what remains is the demand to enter something that is otherwise never entered.
Ledger hack via the reseller CryptoBilis: what is established so far and what is not
The background against which the counterfeits are working so well just now is a second incident. Since October 9 Ledger has been investigating reports of emptied balances among customers who had obtained their devices in Southeast Asia through the reseller CryptoBilis. The onchain analyst Specter arrives, according to BTC-Echo, at more than $86 million said to have flowed out across several blockchains.
Honesty requires noting that BTC-Echo could not confirm that sum itself: the portfolio cited at Arkham Intelligence could not be found under the name given. A public statement of cause by Ledger is likewise still missing. What cryptoticker.io gathered on October 9, 2026 about the tampered devices and the halted reseller is set out in our account of the Ledger incident.
For owners in Germany this part stays manageable. CryptoBilis sold in Southeast Asia, not here. Ledger Support recommends, according to BTC-Echo, not setting up a device bought from this reseller in the past 90 days and, for devices already set up, moving the holdings to a new device with a new phrase. Anyone who bought their device from the manufacturer or from German specialist retail is not addressed by that recommendation.
How to proceed now if you have entered your recovery phrase
An entered phrase cannot be repaired. Such a sequence of words cannot be changed, blocked or recalled, and the time pressure is real: automated tools often clear out affected addresses within minutes.
The first step is a new wallet with a newly generated phrase, created on a device that never came into contact with the counterfeit. Only then are the holdings moved there, beginning with the largest position. Resetting the old device does not help, because the phrase is already out of the house. Nor does it help to keep watching the old wallet: whoever has the words needs no second attempt.
If it stayed at a click on the site, without any entry, nothing is lost. Then deleting files downloaded from such sources and a check of the approvals granted are enough. A phrase that was typed in nowhere remains a working phrase.

Hardware wallets comparedBookmark instead of search box: how to reach Ledger Live and other wallet software safely
Against search poisoning, attentiveness helps little. What carries is a change in the order of things. The address of the manufacturer's site is entered manually once, checked carefully and saved as a bookmark. After that every visit starts at that bookmark, and search drops out entirely for this one purpose.
When first saving it, the spelling of the domain is worth a look. Interchangeable characters, additional syllables or a different ending are the usual craft. Anyone who has already saved the address does not have to read it again each time; that is precisely the gain.
The same applies to software wallets, and there the damage is often done faster, because the keys sit on the computer or the phone anyway. There the route by which the software is obtained decides who holds the keys in the end. A second principle gives additional protection: programs are obtained from the source that sits in the bookmark, and never from a search result.
Hardware wallet or exchange: where your coins should sit after this incident
Two incidents in the same week tempt one into a short circuit, namely pushing everything back onto an exchange. That calculation only works out if the risks are set cleanly against each other, because they are different, not simply larger or smaller.
With self-custody the risk lies with your own person: a lost phrase, a typed-in seed, a device from a doubtful source. That risk is manageable, but it is entirely yours. With an exchange it lies with the provider: insolvency, a halt on withdrawals, an incident at a service provider. That risk is not manageable, but a regulated counterparty with obligations stands liable for it.
In practice many holders separate by purpose. Amounts that are moved or traded stay with a provider under European supervision; amounts that are left lying go into self-custody. Which providers are authorised in the EU under MiCA and how they keep customer holdings is set out in the survey of regulated crypto exchanges. A MiCA authorisation says something about supervision and obligations, nothing about returns.
Our assessment: the search channel is the weak point, not the device
From the newsroom's point of view this case shifts the most important piece of advice for self-custody. The evidence for it lies side by side: a counterfeit at the top of the organic results with a visitor figure in the millions according to Coinfomania, plus the adverts leading to counterfeit verification pages documented by Zscaler in September. Both hit people who have done nothing wrong except search for a brand name.
What argues against drawing this case too large: the visitor figure is not independently verified, the domain is not publicly named, and how many visitors actually entered their phrase is unknown. Damage on the order of the reseller incident is not established for the counterfeit. The recommendation stays the same all the same, because it costs nothing: set a bookmark and stop using the search box for this purpose. Crypto balances can be lost in full, and with self-custody there is no body that replaces them.
Ledger phishing: no genuine deadline runs to October 15
The deadline in the emails is invented, the incident at the reseller is not yet cleared up, and the counterfeit site can reappear under a new address. Three steps bring your own custody to a state that survives this wave all the same.
- Fix the route of access. Type the address of the manufacturer's site in manually once, check it and save it as a bookmark. Whether the current device fits your own requirements is shown by the hardware wallet comparison.
- Tidy up software sources. Obtain wallet programs only from the saved source and remove installations that came from search results. The differences in key custody are set out in the software wallet comparison.
- Split holdings by purpose. Keep trading amounts with a supervised provider, reserves in self-custody. Which houses are authorised in the EU is set out at the regulated crypto exchanges.
(As of October 10, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Regulated crypto exchanges at a glanceFrequently asked questions about Ledger phishing
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Wallet Phishing by Letter: Why the QR Code From Your Postbox Wants Your Recovery Phrase
- Trezor Hack Scare: That STM32 Entropy Email Is a Phishing Attack
- Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
- Phishing Email From the Real Sender Address: How to Check a Wallet Security Warning
- Crypto Wallet Provider Ledger Hacked: Data Leak Results in Phishing Scams
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 22, 2026 4:13 AM

SafePal Data Breach: 39,798 Customers Exposed With Names, Addresses and Phone Numbers
SafePal confirmed a data breach on August 16, 2026: the names, delivery addresses, phone numbers and order details of 39,798 customers were exposed. Seed phrases and private keys were not affected, but the phishing risk is substantial.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
August 23, 2026 4:36 PM

Operation ASTERIX: How a Fake Support Call Delivers a Counterfeit Wallet App
Security researchers analysed an open server on which a phone system, phishing interfaces and cloned wallet programs all came together. The largest list of numbers was the German one.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
October 9, 2026 5:36 PM

Ledger Hack? $86 Million Drained: What Is Behind the Tampered Wallets From Southeast Asia
Since Friday, Ledger users in Southeast Asia have been reporting empty wallets, and analysts count more than $86 million. Ledger has halted the reseller CryptoBilis. An implant inside the device reportedly reads the seed phrase. What is known, what CZ advises and what you should do now.
September 19, 2026 10:11 PM

North Korean Hackers Drain 7,000 Crypto Wallets: What to Check on Job Offers and Coding Tests
Seven agencies, among them Germany's BND and BfV, warn about the WaterPlum group: 30,000 infected machines, more than 7,000 drained wallets. The bait is a job offer, the trap a coding test.
September 19, 2026 1:23 AM

Hardware wallet lost: how to rescue your coins and what the tax office accepts
Your hardware wallet is gone, your coins are still on the blockchain: all that matters is whether you still have your recovery phrase. What goes wrong during a restore, and why the tax office as a rule does not recognise permanently lost access as a loss under Section 23 of the Income Tax Act.
September 15, 2026 10:14 PM

AI Crypto Crime: How Scams Are Getting More Convincing
AI is sharpening fake support, deepfakes and phishing across the crypto space. Why the data still needs a careful reading and which security routines protect a wallet.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
August 25, 2026 10:11 PM

Ledger Closes a Gap in the Ethereum App: When the Display Shows Something Other Than What You Sign
Ledger has closed a flaw in its Ethereum app that let a malicious application swap the reviewed transaction for a different one. Anyone holding Ether or ERC-20 tokens on the device should check the app version and clear out old token approvals.
August 21, 2026 7:26 PM

Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
Your seed is yours; the device belongs to a company. This article explains what the open BIP39 standard actually guarantees, why a wrong derivation path makes a full wallet look empty, and the test that settles both in twenty minutes.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
September 13, 2026 10:19 PM

Reporting Duty for Wallet Makers: What Has Applied Since September 11, 2026
Since September 11, 2026, anyone offering a wallet commercially in the EU must report an actively exploited vulnerability within 24 hours and inform the affected users. What Article 14 of the EU Cyber Resilience Act requires, where the limit of interpretation lies, and what you should take from it for your own custody.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 30, 2026 7:16 AM

Tangem Wallet: The Card Without a Seed Phrase vs the Classic Hardware Wallet
The Tangem Wallet secures crypto with two or three identical cards instead of 24 words. What the sets cost, what the EAL6+ chip delivers and why losing every card is final.
September 16, 2026 4:12 AM

Wallet Drops a Network: How to Rescue Your Coins Before the Deadline
Phantom is ending Sui support on September 24, 2026, and Trust Wallet has already removed 25 networks: five shutdowns of this kind in four weeks alone. What really happens to your balance, which two routes you have before the deadline and where the move most often fails.
May 15, 2024 12:04 PM

Crypto Scams: How to Protect Your Cryptos?
With the rise of crypto scams, and while international efforts are still working to combat these threats and protect investors, some recent tactics have been identified, and here is your full guide.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 22, 2026 4:34 PM

BitBox02: Firmware 9.26.5 Closes Three Security Vulnerabilities. What to Check Now
BitBox released firmware 9.26.5 on August 17, 2026, closing three security vulnerabilities in the BitBox02 and BitBox02 Nova. Existing seeds are not affected according to the manufacturer; an update is due anyway, and with unused devices the order matters.
December 14, 2023 3:12 PM

BREAKING News: Ledger Library Compromised, Urgent Security Alert for Multiple DApps and Ledger Users
In a shocking turn of events, the widely used Ledger library has been compromised, posing a significant threat to funds.
April 8, 2022 10:30 AM

Forgot Your Bitcoin Password? How to Recover Your Crypto, and When It Is Lost for Good
Bitcoin has no password reset. Whoever loses the private key or the recovery phrase cannot restore access. What you can still try, and how to keep your coins safe.
October 6, 2026 4:29 PM

Setting up MetaMask: the twelve words that control your coins
MetaMask is set up in ten minutes, and in those ten minutes you make the decisions that later determine what happens to your balance. This guide walks through installation, the recovery phrase, networks, approvals, fees and the German tax position.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million (later revised to $387.5 million) and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
More from CryptoTicker
