
Security researchers have warned that a fake Ledger website and application have appeared prominently in Google search results, attempting to steal cryptocurrency wallet recovery phrases as the hardware wallet maker investigates more than $86 million in suspected customer losses.
Summary
- Researchers warned that fake Ledger websites appeared prominently in Google searches and requested recovery phrases.
- Zscaler documented malicious Google ads that redirected Ledger users through multiple websites to phishing pages.
- Claims of one million visits remain unverified, with earlier advertising data referring to Google itself.
- Ledger is investigating suspected losses involving CryptoBilis customers, while researchers estimate over $86 million stolen.
- Ledger advises users never to type their 24-word recovery phrase into websites or downloaded applications.
Bitcoin News reported on October 10 that security researcher Cyber Scrilla had identified fraudulent Ledger-branded search results directing users toward a fake website and application. The impersonation campaign reportedly displayed a claim of more than 1 million visits over 30 days, although that figure has not been independently confirmed as traffic to the malicious website.
The warning follows a September investigation by cybersecurity firm Zscaler, which documented a separate campaign using fraudulent Google advertisements to collect Ledger recovery phrases.
Fake Ledger website targets users through Google Search
The latest warning concerns a website designed to resemble the official Ledger platform, including an application presented as legitimate wallet software.
According to Cyber Scrilla’s reported findings, the fraudulent website appeared near the top of Google search results, where users searching for Ledger products or wallet software could encounter it before reaching the company’s official website.
The operators reportedly attempted to convince visitors to enter their 24-word recovery phrases, which provide access to cryptocurrency held in the corresponding wallets. Ledger hardware wallets are designed to keep private keys protected within a physical device. However, anyone who obtains the associated recovery phrase can recreate the wallet through compatible software without possessing the original hardware.
The reported traffic figure requires caution. Several reports repeated a claim that the phishing website received more than 1 million visits in the preceding month, but they did not establish a verified count of visits to that particular domain.
Zscaler’s September investigation documented a similar advertising display. Its researchers found that a malicious Google advertisement showed more than 1 million monthly visits alongside a google.com address.
The cybersecurity firm explained that the figure appeared to refer to Google itself, not the phishing destination. The visit count could have made the advertisement appear more trustworthy to users.
No verified victim count or amount stolen has been established for the newly reported phishing website. The available evidence does not confirm whether the October warning concerns the same infrastructure that Zscaler previously investigated.
Zscaler uncovers fake Ledger ads collecting wallet recovery phrases
In a September 25 investigation, Zscaler ThreatLabz revealed how attackers used fraudulent Google advertisements to direct Ledger users toward malicious wallet verification pages.
The researchers first examined the campaign in August 2026 and identified advertisements operating through a Google-verified advertiser account.
Those advertisements targeted users searching for Ledger-related terms in the U.S., Europe and parts of Asia. The verified advertising profile and familiar branding could make the search results appear legitimate. After users clicked an advertisement, the attackers directed them through Google Cloud Storage and Vercel before displaying a fake Ledger page using Google Sites.
During the investigation, the Vercel redirect addresses appeared to change approximately every 15 to 20 minutes, creating additional difficulties for systems attempting to identify and block the malicious infrastructure.
The fake page resembled Ledger’s official wallet interface and presented download options for different operating systems, including Windows, macOS, Linux and mobile devices. Visitors were instructed to select a device and follow what appeared to be a standard setup procedure.
The website then displayed misleading connection and firmware update messages before asking users to verify device ownership by entering their recovery phrase.
Zscaler found that the page used a list of 2,048 recognized recovery words to provide suggestions as victims entered their information. Once submitted, the recovery phrase was transmitted to an attacker-controlled Vercel domain.
The page then displayed an error message suggesting that the phrase was invalid and asked users to enter it again. Researchers observed that the second submission was sent to the attackers as well. Zscaler found no evidence that the page performed a legitimate device verification. Its analysis identified the process as an attempt to steal wallet credentials.
Ledger investigates $86 million in suspected wallet thefts
The phishing warning emerged while Ledger was investigating reports of missing cryptocurrency involving devices purchased through Southeast Asian reseller CryptoBilis.
On October 9, Ledger confirmed that it was examining complaints from users who obtained hardware wallets through the distributor, which operates in Indonesia, Malaysia and the Philippines.
The company requested that CryptoBilis suspend sales and shipments while the investigation continued. Customers who purchased devices from the reseller during the previous 90 days were advised not to begin setting them up.
For devices already initialized, Ledger recommended that users consider transferring their holdings to a new signing device protected by a newly generated recovery phrase. Blockchain researchers have reported different estimates of the suspected losses.
On-chain investigator tanuki42 identified more than $72 million in funds transferred to addresses believed to be connected to the thefts.
Another researcher, Specter, estimated that the suspected losses exceeded $86 million across Bitcoin, Ethereum and Tron.
The figures have not been confirmed by Ledger, and investigators have not established the final number of affected wallets.
A separate October 9 investigation by blockchain analytics firm Bitquery estimated losses above $92 million across multiple blockchain networks, identifying 311 wallets in its analysis.
Bitquery’s findings represent its own tracing estimates and should not be treated as the company’s confirmed financial losses.
Although both incidents concern Ledger users, researchers have not demonstrated that the Google phishing website caused the reported CryptoBilis losses.
The reseller investigation concerns devices obtained through a specific distribution channel, while the documented Google advertising campaign attempted to steal recovery phrases through fraudulent websites.
Ledger warns users against fake wallet verification requests
Ledger’s official security guidance states that users should never enter their recovery phrases into a website, downloaded application or online verification form.
The company warned that fraudulent wallet applications frequently imitate its official software and display fake error messages to convince users that they must restore or verify their devices. Ledger states that legitimate support personnel will never request the 24-word recovery phrase.
The company recommends obtaining its wallet management application directly from its official website and checking website addresses carefully, including for small spelling changes.
In February 2026, a separate phishing campaign targeting Ledger and Trezor users involved physical letters carrying QR codes that directed recipients to fraudulent verification pages.
The letters used security warnings and account verification instructions to persuade users to disclose their recovery phrases.
A similar attack affected another hardware wallet brand in August, when a user reported losing funds through a fake Trezor Google advertisement.
The victim claimed a sponsored search result directed him to a website impersonating Trezor and collecting wallet recovery information. The amount stolen in that case was not independently verified.
Ledger’s published phishing guidance identifies fake applications, fraudulent websites, impersonated support accounts and misleading device verification requests as recurring methods used to obtain recovery phrases.
The company advises users who believe their recovery phrase has been exposed to stop using the affected wallet credentials and transfer assets, where still possible, to a wallet generated from a new recovery phrase.


