I am reporting an active phishing campaign impersonating the official Ledger platform.
The phishing infrastructure includes:
These websites are fraudulent copies of the official Ledger platform. They imitate Ledger's branding, Ledger Live interface, hardware wallet selection pages, and wallet recovery workflow in order to deceive users into believing they are interacting with the legitimate Ledger service.
The phishing infrastructure contains multiple stages of the attack:
• Fake Ledger device selection page.
• Fake Ledger Live interface.
• A recovery page that explicitly requests the victim's 24-word recovery phrase.
• Search-engine-indexed phishing pages titled "Ledger Live App | Hardware Wallet Management", allowing unsuspecting users to discover the phishing websites through public search results.
Once victims submit their recovery phrase, attackers immediately gain full access to their cryptocurrency wallets and steal all digital assets.
This criminal infrastructure is engaged in:
- Ledger trademark and brand impersonation
- Credential harvesting
- Recovery phrase theft
- Identity theft
- Cryptocurrency theft
- Financial fraud
The registrar has already received multiple abuse reports, yet the phishing infrastructure remains fully operational and continues targeting new victims every day.
Please investigate these domains, classify them as phishing, add them to any applicable blocklists, and, if possible, coordinate with registrars, hosting providers, browser security vendors, Safe Browsing services, and other trusted anti-phishing partners to maximize the chances of permanently removing this infrastructure.
Evidence attached includes:
- Search engine indexing of the phishing websites.
- Fake Ledger device selection interface.
- Fake recovery phrase page requesting a 24-word recovery phrase.
- Additional screenshots demonstrating active phishing activity.
Immediate action is required to prevent further financial losses and protect cryptocurrency users worldwide.

I am reporting an active phishing campaign impersonating the official Ledger platform.
The phishing infrastructure includes:
These websites are fraudulent copies of the official Ledger platform. They imitate Ledger's branding, Ledger Live interface, hardware wallet selection pages, and wallet recovery workflow in order to deceive users into believing they are interacting with the legitimate Ledger service.
The phishing infrastructure contains multiple stages of the attack:
• Fake Ledger device selection page.
• Fake Ledger Live interface.
• A recovery page that explicitly requests the victim's 24-word recovery phrase.
• Search-engine-indexed phishing pages titled "Ledger Live App | Hardware Wallet Management", allowing unsuspecting users to discover the phishing websites through public search results.
Once victims submit their recovery phrase, attackers immediately gain full access to their cryptocurrency wallets and steal all digital assets.
This criminal infrastructure is engaged in:
The registrar has already received multiple abuse reports, yet the phishing infrastructure remains fully operational and continues targeting new victims every day.
Please investigate these domains, classify them as phishing, add them to any applicable blocklists, and, if possible, coordinate with registrars, hosting providers, browser security vendors, Safe Browsing services, and other trusted anti-phishing partners to maximize the chances of permanently removing this infrastructure.
Evidence attached includes:
Immediate action is required to prevent further financial losses and protect cryptocurrency users worldwide.