Scam via SNAIL MAIL
We usually think of phishing as a purely digital annoyance—spam emails, sketchy SMS links, or malicious DMs. But recently, crypto scammers have been getting desperate, reaching back in time to try an analog approach: snail mail.
Yep, physical letters arriving in your actual mailbox.
Likely fueled by a previous data leak, attackers initiated a massive, expensive physical mailing campaign targeting crypto holders. The bait? A highly convincing letter prompting the victim to scan a QR code to secure their hardware wallet.
You can check out what the physical bait looked like from this user who received one in the mail
FAKE WEBSITE
The Scam Flow
The mechanics were pretty straightforward:
The Bait: Scan the printed QR code (qr[.]c-6542[.]cc).
The Trap: Get redirected to secure[.]portal-coldcard[.]com.
The Steal: The site acts as a seed phrase stealer. If you punch in your recovery phrase, your wallet gets drained immediately.
The Takedown (or, Why Analog Phishing is a Terrible Idea)
Here’s where it gets fun. I started investigating the infrastructure behind this trap. The scammers thought they were being incredibly slick by hiding their backend behind Cloudflare. But with a bit of digging, I managed to unmask the real hosting provider (spoiler: it was BL Networks).
Once I had the real infrastructure pinned down, managed to get the campaign blocked
As a reminder: Never, ever type your seed phrase into a website. Not even if a very official-looking piece of paper arrives at your house telling you to do it.
Stay safe out there!
Indicators of Compromise (IOCs)
QR Code Redirect Domain: qr[.]c-6542[.]cc
Seed Phrase Stealer Domain: secure[.]portal-coldcard[.]com
Hidden Host (Unmasked): BL Networks
ASN: AS399629
Regs NICENIC and CNOBIN















