Fake Ledger devices and Ledger scams: How to spot them

Blog » Fake Ledger devices and Ledger scams: How to spot them
Updated on Jul 28, 2026
Author: Robbert Bink
Two near-identical hardware wallets side by side on a wooden desk next to an opened box containing a pre-printed seed phrase card

Ledger is the most widely used hardware wallet brand in the world. It’s also the most frequently impersonated. The scams targeting Ledger users are varied, well-resourced, and designed to look entirely legitimate. That’s why experienced crypto users fall for them. The best protection is understanding how each type of attack works, not just knowing that scams exist.

Phishing emails and text messages

In July 2020, Ledger’s e-commerce database was breached, exposing the names, email addresses, and in many cases postal addresses of approximately 270,000 customers. What that breach involved, and what it didn’t expose, is explained here. What followed it was a sustained phishing campaign that used real customer data to make fake contact look credible: emails with your real name, referencing your real address, claiming your device needed a firmware update or your funds were at risk. Every one of them pointed to a website asking for your 24-word recovery phrase.

Ledger will never ask for your recovery phrase by email, text message, or any online form. The phrase is entered on the physical device only, during initial setup or restoration. If any communication asks for it (regardless of how official it looks), it is a scam.

Fake Ledger websites

Fraudulent domains mimicking Ledger’s website appear in search results, in paid advertising slots, and in links sent via phishing emails. Common patterns include ledger-live.net, ledgersupport.io, and variations using hyphens, deliberate misspellings, or additional words. These sites can look identical to the real thing and offer to help you sync, verify, or restore your wallet. All of them ultimately need your seed phrase.

The only legitimate domain is ledger.com. Ledger Live is downloaded from the official Ledger website or from official app stores only. Any download reached through a search result, an email link, or a pop-up should be treated as potentially compromised, even if the page looks correct.

Fake Ledger devices

Counterfeit Ledger hardware has been documented and analysed by multiple security researchers. Externally, these devices can look identical to genuine Ledgers. Internally, the firmware is modified. The most dangerous variant arrives pre-loaded with a seed phrase already known to the attacker: any funds sent to addresses derived from that phrase are immediately accessible to them, even before the device has been set up by the buyer.

Some fake devices instruct users to enter a phrase printed on a card inside the box, rather than generating a new one. A genuine Ledger always generates a fresh, random 24-word phrase during first-time setup and never provides one pre-written. Buy only from ledger.com or from Ledger’s officially listed authorized resellers. When a new device arrives, run the genuine check in Ledger Live: it uses a cryptographic challenge to verify that the Secure Element chip is authentic.

Fake customer support

Scammers actively monitor Reddit, Telegram, Discord, and Twitter/X for users posting about wallet problems and offer help via direct message. The assistance always leads in the same direction: a request for your seed phrase, or a link to a fraudulent website. Ledger’s official support channel is support.ledger.com. There is no official Ledger support via any direct messaging platform, and Ledger staff will never ask for your seed phrase under any circumstances.

If you’ve already given your seed phrase to a scammer

Act immediately. The wallet is compromised the moment someone else has those 24 words. They can regenerate every private key and drain every account. Move any remaining funds to a completely new wallet, generated on a clean device with a fresh seed phrase, as fast as possible. Transfer everything from the compromised wallet to the new one. Don’t attempt to change the PIN, update firmware, or take any other action on the compromised wallet first: none of those steps protect against someone who already has the seed phrase. Guidance on setting up secure seed phrase storage from the beginning is here.

What Crypto Recovers does

We work on legitimate access recovery: people who still own their funds but can’t reach them because of a forgotten PIN, a lost seed phrase, or a damaged backup. We don’t work on theft recovery or fraud cases. If your situation involves lost access rather than theft, start a free assessment here to recover your Ledger wallet.

Clear agreements before work begins. Before recovery work begins, both parties sign a service agreement setting out the assignment, fees, responsibilities, confidentiality and data handling. At your request, an NDA can also be signed before confidential details about your case are discussed.

Non-custodial wallet access recovery. Your wallet remains yours. We do not hold, manage or transfer your crypto-assets on your behalf. After a successful recovery, you move your funds to a new wallet yourself and pay the agreed success fee separately.

Robbert

Robbert Bink

Founder & CEO

Robbert Bink is the founder and a wallet recovery specialist at Crypto Recovers. He has more than 15 years of experience in programming and IT and has specialized in crypto wallet access recovery since 2019. Through Crypto Recovers, he helps rightful owners securely and efficiently regain access to inaccessible wallets.

Other Blogs by Crypto Recovers