Ledger Phishing: Fake Google Ads Steal Recovery Phrases
Published October 5, 2026, 04:36 UTC. Based on research Zscaler ThreatLabz published on September 25, 2026.
Fraudulent Google search ads have been sending Ledger hardware wallet users to a fake setup page built to steal their secret recovery phrases, according to Zscaler ThreatLabz. The campaign did not involve any flaw in Ledger devices. It relied on persuading people to type their recovery phrase into a website.
Ads from a verified advertiser
ThreatLabz said it found the campaign in August 2026. The malicious ads appeared in search results for Ledger-related terms and targeted users in the United States, Europe and parts of Asia.
The ads displayed google.com as their destination. ThreatLabz said they came from a long-standing, verified advertiser account, with an advertiser location in Germany and no observed history of malicious ads. The researchers said the threat actor may have compromised that account.
A chain of trusted platforms
Clicking an ad sent users to a Google Cloud Storage URL, then to a page hosted on Vercel, and finally to a Google Sites page that showed the phishing site inside an iframe. ThreatLabz said the Vercel address in the redirect appeared to change every 15 to 20 minutes during its analysis, which makes blocking by domain reputation harder.
The fake page copied Ledger's interface and offered app downloads for desktop and mobile. It also collected device data and tracked keypresses and mouse movements, which ThreatLabz said could help attackers tell real visitors from security scanners.
The recovery phrase trap
After a user picked a device, the page showed messages such as "Connecting your Ledger" and "Initializing Firmware Update," then asked the user to confirm ownership by entering their recovery phrase. It even offered autocomplete from the standard 2,048-word BIP-39 list.
On first submission, the phrase was sent to an attacker-controlled server and the page showed an "Invalid seed" error. A second submission was sent too, before the user was redirected back to the landing page. With the phrase, ThreatLabz noted, attackers can restore the wallet in other software and move funds without the physical device.
How to stay safe
A recovery phrase should never be typed into a website or "verification" page. Download wallet software only by typing the vendor's address yourself rather than clicking sponsored search results. A Google-owned address in the browser bar does not mean Google or Ledger made the page, because Google Sites and Cloud Storage host content from anyone.
For more red flags, see our explainer on how to spot a crypto scam.
This article is news reporting and is not investment advice.
Sources
- Zscaler ThreatLabz, Threat Actors Use Google Ads To Target Ledger Users (Sept. 25, 2026; includes indicators of compromise)
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
70 Fake Rewards Vote Sites Target Pendle, xStocks Users
Malwarebytes found 70 copycat sites posing as Pendle, xStocks, Zama and others, using a fake rewards vote to push visitors into wallet connections.
Belgium Flags 51 Scam Platforms; BaFin Warns on Crypto Site
Belgium's FSMA added 51 fraudulent trading platforms to its warning list, and Germany's BaFin warned about btcx(.)investments under its crypto law.
Illinois Agrees to Seek Crypto Tax Delay to July 2027
Illinois officials and two crypto groups jointly asked a court to push the state's 0.2% digital asset tax from Jan. 1 to July 1, 2027. A judge must still approve.
SEC Clears Cboe Listing of 3x Bitcoin and Ether ETPs
The SEC approved a Cboe BZX rule change to list six 3x leveraged Volatility Shares products, including bitcoin and ether, but trading has not started.



