We usually think of phishing as a purely digital annoyance—spam emails, sketchy SMS links, or malicious DMs. But recently, crypto scammers have been getting desperate, reaching back in time to try an analog approach: snail mail.
Yep, physical letters arriving in your actual mailbox.
Likely fueled by a previous data leak, attackers initiated a massive, expensive physical mailing campaign targeting crypto holders. The bait? A highly convincing letter prompting the victim to scan a QR code to secure their hardware wallet.
You can check out what the physical bait looked like from this user who received one in the mail
The mechanics were pretty straightforward:
The Bait: Scan the printed QR code (qr[.]c-6542[.]cc).
The Trap: Get redirected to secure[.]portal-coldcard[.]com.
The Steal: The site acts as a seed phrase stealer. If you punch in your recovery phrase, your wallet gets drained immediately.
The Takedown (or, Why Analog Phishing is a Terrible Idea)
Here’s where it gets fun. I started investigating the infrastructure behind this trap. The scammers thought they were being incredibly slick by hiding their backend behind Cloudflare. But with a bit of digging, I managed to unmask the real hosting provider (spoiler: it was BL Networks).
Once I had the real infrastructure pinned down, managed to get the campaign blocked
As a reminder: Never, ever type your seed phrase into a website. Not even if a very official-looking piece of paper arrives at your house telling you to do it.
Indicators of Compromise (IOCs)
QR Code Redirect Domain: qr[.]c-6542[.]cc
Seed Phrase Stealer Domain: secure[.]portal-coldcard[.]com
Hidden Host (Unmasked): BL Networks