A phishing campaign targeting crypto hardware wallet users, particularly Ledger and Trezor, employs fake letters urging recipients to provide sensitive information. The letters, which mimic official communications, include QR codes leading to fraudulent sites that steal recovery phrases, putting users' funds at risk.