Security researchers have warned that a fake Ledger website and application are appearing prominently in Google search results and are designed to steal wallet recovery phrases from users. The reported phishing operation surfaced through fraudulent Google ads that directed people to a counterfeit Ledger page made to resemble the company’s official software.

The warning comes while Ledger is also investigating suspected customer losses linked to devices bought through Southeast Asian reseller CryptoBilis. Investigators have estimated the missing crypto at more than $86 million across Bitcoin, Ethereum and Tron.

Phishing flow targets recovery phrases

According to the researchers’ warning, the fake site and app attempt to collect users’ 24-word recovery phrase, the key backup that can be used to restore access to a wallet. The scam reportedly uses a fake verification process and presents a list of recovery words to encourage victims to enter the phrase themselves.

By imitating Ledger’s branding and software experience, the fraudulent page appears intended to lower suspicion and make the request seem routine. The appearance of the ads high in Google search results adds another layer of risk, since users may assume promoted links are legitimate.

Ledger repeats core security guidance

Ledger has advised users not to enter their 24-word recovery phrase into any website or downloaded application. The company also recommends downloading its wallet management app only from Ledger’s official site.

The wallet maker said legitimate support will never ask for a recovery phrase. It also urged users to inspect web addresses carefully to avoid impersonation sites that are built to look like official Ledger pages.

Probe continues into losses tied to reseller devices

The phishing alert arrives as Ledger investigates missing cryptocurrency involving devices purchased through CryptoBilis, a reseller in Southeast Asia. The matter remains under investigation, and the source report attributes the estimate of losses to investigators rather than to a final confirmed total.

Those suspected losses were estimated at more than $86 million and span Bitcoin, Ethereum and Tron. The report did not provide further conclusions about how the funds were taken, but it placed the phishing warning alongside the broader security concerns now facing Ledger users.

What is confirmed so far

At this stage, the confirmed points are limited: researchers say a fake Ledger site and app have been promoted through Google ads, Ledger is warning users never to share their recovery phrase, and the company is probing reported losses connected to CryptoBilis-purchased devices.

The next confirmed step is continued investigation. Until more findings are published, Ledger’s stated guidance remains the clearest immediate measure: obtain software only from the official source and treat any request for a 24-word recovery phrase as a red flag.

Source: crypto.news