MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / Scam Alerts / Ledger Phishing: Fake Google Ads Steal Recovery Phrases
Scam Alerts

Ledger Phishing: Fake Google Ads Steal Recovery Phrases

By MABOnChain Desk · Published · Updated · 2 min read

Abstract illustration for Ledger Phishing: Fake Google Ads Steal Recovery Phrases

Published October 5, 2026, 04:36 UTC. Based on research Zscaler ThreatLabz published on September 25, 2026.

Fraudulent Google search ads have been sending Ledger hardware wallet users to a fake setup page built to steal their secret recovery phrases, according to Zscaler ThreatLabz. The campaign did not involve any flaw in Ledger devices. It relied on persuading people to type their recovery phrase into a website.

Ads from a verified advertiser

ThreatLabz said it found the campaign in August 2026. The malicious ads appeared in search results for Ledger-related terms and targeted users in the United States, Europe and parts of Asia.

The ads displayed google.com as their destination. ThreatLabz said they came from a long-standing, verified advertiser account, with an advertiser location in Germany and no observed history of malicious ads. The researchers said the threat actor may have compromised that account.

A chain of trusted platforms

Clicking an ad sent users to a Google Cloud Storage URL, then to a page hosted on Vercel, and finally to a Google Sites page that showed the phishing site inside an iframe. ThreatLabz said the Vercel address in the redirect appeared to change every 15 to 20 minutes during its analysis, which makes blocking by domain reputation harder.

The fake page copied Ledger's interface and offered app downloads for desktop and mobile. It also collected device data and tracked keypresses and mouse movements, which ThreatLabz said could help attackers tell real visitors from security scanners.

The recovery phrase trap

After a user picked a device, the page showed messages such as "Connecting your Ledger" and "Initializing Firmware Update," then asked the user to confirm ownership by entering their recovery phrase. It even offered autocomplete from the standard 2,048-word BIP-39 list.

On first submission, the phrase was sent to an attacker-controlled server and the page showed an "Invalid seed" error. A second submission was sent too, before the user was redirected back to the landing page. With the phrase, ThreatLabz noted, attackers can restore the wallet in other software and move funds without the physical device.

How to stay safe

A recovery phrase should never be typed into a website or "verification" page. Download wallet software only by typing the vendor's address yourself rather than clicking sponsored search results. A Google-owned address in the browser bar does not mean Google or Ledger made the page, because Google Sites and Cloud Storage host content from anyone.

For more red flags, see our explainer on how to spot a crypto scam.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading