Hardware wallet makers Trezor and Foundation are warning users about a rise in phishing attempts tied to the Coldcard firmware exploit, as attackers try to steal recovery phrases and push malicious downloads.

Trezor and Foundation issue user warnings
Trezor said it had already seen more phishing attempts after the vulnerability was disclosed. The company told users to enter a wallet backup only on the device itself and said its own hardware is unaffected.
Foundation said it had been alerted to emails impersonating the firm and steering recipients to fake websites and malicious downloads. It added that it will never ask for a recovery phrase or tell users to install software to secure a wallet.
Proofpoint details a “hardware audit” phishing campaign
Security firm Proofpoint documented a phishing campaign targeting Coldcard users on Monday. The emails, sent from a spoofed Coldcard address, asked recipients to complete a “coordinated hardware audit,” borrowing language from the security incident itself. They linked to a cloned Coldcard website carrying a “Start Hardware Audit” button.
“A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering w/ ‘hardware audit’ themes impersonating #COLDCARD in email-based phishing campaigns.”
Clicking the button downloaded a batch file hosted on GitHub. Proofpoint said the file installs ScreenConnect, a legitimate remote-access tool that can give attackers a path to data theft and financial theft, or to later malware deployment such as ransomware.
The cloned site also ran a customer service chat window. According to Proofpoint, a real person, not a bot, answered the chat and guided victims through the installation steps. The firm said the lure works because it “preys on the fear and concern” holders now have about their crypto security.
The flaw behind the lure
The Coldcard exploit traces back to a firmware build from March 2021. In that version, wallet seeds were generated from a software fallback rather than the device’s hardware random number generator, leaving private keys guessable.
Galaxy Research said it has confirmed three waves of thefts since July 30 and estimates high-confidence losses at 1,596 BTC, worth more than $100 million. If a fourth wave that it suspects, but has not confirmed with victims, is included, total losses could reach $130 million.
Alex Thorn, Galaxy Research’s head of research, said Tuesday that at least 15 separate attackers are now exploiting the flaw. He added that every wave except the first was identified through victim reports.
Coldcard maker Coinkite has released patched firmware and told affected users to move funds to newly generated seeds.
A familiar pattern for hardware wallet users
Phishing campaigns aimed at hardware wallet owners have taken several forms this year.
- In February, Trezor and Ledger users were targeted by a physical mail campaign impersonating the two firms, complete with holograms and forged executive signatures, and built around the same manufactured deadline.
- In April, a counterfeit Ledger app drained millions from holders.
- In March, another campaign used fake GitHub issues to lure developers to a spoofed site.
Galaxy Research said the Coldcard exploit is still active and urged holders to move funds to a fresh seed or a custodian. That also gives the phishing lure a potentially long shelf life.

