Scammers Send Physical Phishing Letters to Steal Ledger Wallet Seed Phrases

2026-05-17T20:51:42Zf02a15a5cc18965cd1095d3a9b916fdca7c6e098b6ca01bcc6b5d24ae28b1eaf
ai-serversamsi-bypasscalphishingclaw-chaincritical-vulnerabilitydevice-code-phishingeviltokensgithub-tokengrafanajobstealerledgerm365macosopenclawoutlook-calendarphishingphysical-phishingpyinstallerqr-coderansomratseed-phrase-theftsource-code-theftwindows','famoussparrow','ms-exchange','proxynotShell','oil-and-xworm

What happened

Multiple high-impact cyber incidents and trends were reported: scammers in Italy are mailing fake Ledger phishing letters with QR codes to trick users into revealing crypto wallet seed phrases; Grafana confirmed source-code theft after a GitHub token was abused but says no customer systems or data were impacted and it rejected a ransom demand; critical “Claw Chain” vulnerabilities in OpenClaw put thousands of AI servers at risk of data theft, backdoors and admin-level compromise; attackers are delivering XWorm RAT v7.4 using PyInstaller bundles and AMSI-patching to evade Windows defenses; “Cal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
f02a15a5cc18965cd1095d3a9b916fdca7c6e098b6ca01bcc6b5d24ae28b1eaf
Enrichment time
2026-05-17T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.