Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases
2026-05-17T20:51:42Z•f02a15a5cc18965cd1095d3a9b916fdca7c6e098b6ca01bcc6b5d24ae28b1eaf
ai-serversamsi-bypasscalphishingclaw-chaincritical-vulnerabilitydevice-code-phishingeviltokensgithub-tokengrafanajobstealerledgerm365macosopenclawoutlook-calendarphishingphysical-phishingpyinstallerqr-coderansomratseed-phrase-theftsource-code-theftwindows','famoussparrow','ms-exchange','proxynotShell','oil-and-xworm
What happened
Multiple high-impact cyber incidents and trends were reported: scammers in Italy are mailing fake Ledger phishing letters with QR codes to trick users into revealing crypto wallet seed phrases; Grafana confirmed source-code theft after a GitHub token was abused but says no customer systems or data were impacted and it rejected a ransom demand; critical “Claw Chain” vulnerabilities in OpenClaw put thousands of AI servers at risk of data theft, backdoors and admin-level compromise; attackers are delivering XWorm RAT v7.4 using PyInstaller bundles and AMSI-patching to evade Windows defenses; “Cal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- f02a15a5cc18965cd1095d3a9b916fdca7c6e098b6ca01bcc6b5d24ae28b1eaf
- Enrichment time
- 2026-05-17T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.