On August 18, Switzerland's National Cyber Security Centre (NCSC) flagged an active phishing campaign delivered through ordinary postal mail: letters designed to look like official communications from cryptocurrency wallet providers, instructing recipients to scan a printed QR code to install an "urgent security update." The code leads to a convincing but fraudulent website that asks the victim to enter their wallet's recovery phrase — the seed phrase that grants complete, irreversible control over every asset the wallet holds. There is no password reset for a compromised seed phrase; once entered on an attacker-controlled page, the funds are gone before the victim finishes reading the confirmation screen. The campaign is notable less for its sophistication than for its channel: it sidesteps every email gateway, browser isolation policy, and endpoint detection control that Swiss enterprises have spent years building, because the entire attack surface is a piece of paper and a smartphone camera.
Why the postal channel defeats existing controls
Enterprise anti-phishing programmes are built almost entirely around digital delivery: email filtering, URL sandboxing, DNS-based blocklists, browser warnings for known-bad domains. A letter arriving through the postal system triggers none of these. The QR code itself is generated fresh for each mailing wave, pointing to short-lived domains that rotate faster than blocklists update, and the "device" doing the browsing is typically a personal smartphone scanning the code directly — outside any corporate MDM policy, EDR agent, or web proxy that would otherwise catch the redirect. For Swiss organisations with treasury functions, payroll operations, or any staff holding corporate or personal crypto-asset custody responsibilities, this is a genuine blind spot: security awareness training that only ever rehearses "suspicious email" scenarios leaves employees with no learned reflex for a "suspicious QR code on a printed letter."
The targeting logic is also worth noting. Attackers do not need to know who holds meaningful crypto balances before mailing; postal campaigns work at scale precisely because printing and postage are cheap relative to the payout from even a small conversion rate among recipients who do hold wallets. That economics means Swiss organisations should assume any employee, executive, or family member associated with the company could plausibly receive one of these letters, not just those with publicly known crypto holdings.
The broader shift: QR codes as an unmonitored delivery mechanism
This campaign sits inside a wider pattern NCSC has tracked through 2026 — QR codes used as a delivery mechanism precisely because they are opaque to both humans and most security tooling until the moment of scanning. Parking-meter QR fraud, fake delivery-notice stickers, and now postal wallet phishing all share the same structural advantage: the malicious destination is encoded, not displayed, so a target cannot visually inspect a URL before committing to visit it the way they might scrutinise a suspicious hyperlink in an email. Swiss enterprises that have invested heavily in phishing-resistant MFA and email security have, in most cases, not extended equivalent scrutiny to QR codes encountered outside digital channels — posters, letters, physical mail, printed invoices — leaving a gap between where the controls are strongest and where this attack class is evolving.
What a credible response looks like
The fix is not technical; it is behavioural, and the barrier to a compromised seed phrase should be procedural rather than dependent on individual vigilance. No legitimate wallet provider requires a recovery phrase to apply an "update" — that instruction alone is the tell, and it should be trained as a hard rule rather than a judgement call. Organisations with any crypto-custody exposure, whether corporate treasury or informal employee holdings that could be leveraged for social engineering against the business, need to extend awareness programmes explicitly to physical-mail and QR-code scenarios, not assume email training generalises.
Hardware wallets remove the underlying weakness entirely: a device that never displays or transmits the seed phrase to a connected computer or browser cannot be drained by a phishing page, no matter how convincing the page is. For any organisation holding crypto-assets as part of treasury operations, mandating hardware-wallet custody and banning browser-based seed-phrase entry outright is a stronger control than relying on staff to recognise every variation of this scam as it evolves. This is also a useful test of whether existing security policies have kept pace with how employees actually use crypto — informal holdings acquired outside any corporate onboarding process are common, and they represent an attack surface security teams rarely inventory precisely because nobody declared them.
◆ Key Takeaway
Postal QR-code phishing bypasses every email and browser control a Swiss enterprise has built, because the delivery channel and the scanning device both sit outside corporate monitoring. The only durable defence is a trained, absolute rule: no legitimate service ever asks for a wallet recovery phrase.
- Extend phishing-awareness training explicitly to physical mail and QR codes, not only email and browser scenarios.
- Train staff on the absolute rule: no legitimate wallet provider, bank, or software vendor ever requests a recovery seed phrase for an update, login, or verification.
- Require hardware wallets or dedicated cold-storage devices for any corporate or treasury-related crypto holdings, removing the ability to type a seed phrase into a browser at all.
- Advise employees to report suspicious postal mail referencing financial services or crypto wallets to security teams, even when addressed personally rather than to the company.
- Review any internal policy or documentation that instructs staff to enter recovery phrases into any web form, and eliminate that pattern entirely.
- Coordinate with corporate mailroom or facilities staff to flag unsolicited financial-services mail for security review before distribution.
- Monitor NCSC advisories for updates on this campaign's domain rotation patterns and share indicators with relevant staff promptly.
Attackers will keep moving to channels defenders have not yet instrumented, and physical mail — cheap, untracked, and outside every digital control stack — is a rational next step after years of hardened email defences. Swiss organisations that treat awareness training as a fixed annual exercise rather than a living response to NCSC's advisory cadence will keep discovering these gaps one successful scam at a time.