Originally published on the RelayShield blog.
A phishing campaign targeting Ledger hardware wallet users has been running since at least August 2026, and it is notable for what it doesn't do: it doesn't use suspicious lookalike domains, misspelled brands, or obvious red flags. According to a full technical analysis published September 25 by Zscaler ThreatLabz (detection name HTML.Phish.Ledger), the attackers run fraudulent Google Ads impersonating Ledger, then route victims through a chain built entirely on trusted cloud platforms.
The redirect chain works like this. The sponsored ad appears in Google search results for Ledger-related queries, displaying "google.com" as its destination — a trust signal inherited from what Zscaler describes as a long-standing, verified advertiser account registered in Germany, assessed as likely compromised rather than created for fraud. Clicking sends the victim to a Google Cloud Storage bucket, then to a Vercel-hosted intermediate whose subdomain rotates every 15–20 minutes, and finally to a Google Sites page whose visible URL belongs to Google itself. The phishing interface is embedded in an iframe served from the Vercel origin. Because every hop sits on a reputable domain, URL-reputation and brand-protection filters that look for directly registered lookalike domains never fire.
The phishing page itself is a careful replica of Ledger's device-setup workflow. It asks the victim to pick a device type, plays simulated progress messages ("Connecting your Ledger," "Initializing Firmware Update"), confirms device ownership — and then asks for the 24-word Secret Recovery Phrase. To make typing feel authentic, it fetches the full 2,048-word BIP-39 English wordlist and implements live autocomplete as the victim types, mirroring Ledger's genuine tooling. After the first submission, a fake "Invalid seed. Please re-enter your recovery phrase carefully" error harvests a second, corroborating entry. Throughout the flow, the page monitors keypresses, touch, and mouse movement and loads an invisible hCaptcha widget at submission time — not to stop victims, but to fingerprint and filter out automated security scanners, extending the infrastructure's lifespan against takedowns. Captured phrases are POSTed to the attacker-controlled Vercel backend.
With the recovery phrase in hand, the attacker can restore the wallet in any compatible software and drain all associated funds — no physical access to the victim's Ledger required. No software vulnerability is involved; this is pure social engineering layered over abused legitimate platforms.
How RelayShield's bots catch this
This is exactly the kind of threat the RelayShield Telegram and WhatsApp bots are built to check. Before interacting with any setup, verification, or update flow that reached you through an ad, a search result, or a forwarded message, send the link to the bot:
- The bot resolves the full redirect chain — including the multi-hop GCS → Vercel → Google Sites pattern used here — and checks each hop against the threat-intel corpus.
- A screenshot of the "device verification" page run through
/scangets checked for phishing markers, including the classic seed-phrase-in-browser request. - The URL gets an immediate verdict before anything is typed into it.
The corpus flags the pattern even when the visible domain is google.com or vercel.app, because the check follows the actual redirect chain and the backend behavior, not just the domain in the address bar.
One takeaway
Never enter your Ledger Secret Recovery Phrase (or any hardware wallet seed phrase) into a website, browser flow, or "verification" page — it should only ever be entered on the physical device itself. Do firmware updates and setup only in the official Ledger Live app downloaded from ledger.com, which you navigate to directly rather than through sponsored search results.
Sources: Zscaler ThreatLabz, "Threat Actors Use Google Ads To Target Ledger Users" (full analysis Sept 25, 2026); Threadlinqs TL-2026-2673 (High severity, active); campaign publicly flagged by Zscaler in late August 2026, active since at least August 2026.
Top comments (0)