The malicious search results, flagged by researcher Cyber Scrilla, mimic the official Ledger interface to trick users into revealing the private keys that secure their digital assets. While some reports suggested the phishing site attracted over one million visits, experts note that such figures often misattribute traffic from Google’s own internal advertising metrics. This mirrors a September campaign documented by Zscaler, where attackers utilized verified Google ad accounts to redirect users through shifting Vercel domains to capture sensitive data.
Separately, Ledger is probing reports of missing funds involving devices purchased through the distributor CryptoBilis, which operates across Indonesia, Malaysia, and the Philippines. Blockchain analysts, including Specter and Bitquery, estimate total losses from these compromised devices could range between $86 million and $92 million. Ledger has instructed the reseller to halt all operations while the company advises customers who purchased units in the last 90 days to migrate their assets to new, securely generated wallets. The company maintains that legitimate support will never request a recovery phrase, emphasizing that users should only interact with software downloaded directly from its official domain.
Comments (0)
No comments yet. Be the first!