Coldcard exploit sparks phishing wave as potential losses approach $130 million

Coldcard exploit sparks phishing wave as potential losses approach $130 million

N
News Editor
2026-08-04 10:52:57
Phishing activity aimed at hardware wallet users is picking up after disclosure of the Coldcard firmware flaw, with Trezor, Foundation and security firm Proofpoint all flagging new scams tied to the incident. Trezor said it has already seen more phishing attempts and reminded users that wallet backups should only ever be entered on the device itself, while stressing that its own hardware is not affected. Foundation reported emails impersonating the company and pushing victims to fake websites and malicious downloads, adding that it will never ask for a recovery phrase or tell users to install software to secure a wallet. Proofpoint said attackers are leaning on a “hardware audit” narrative lifted from the Coldcard incident. In the campaign it tracked on Monday, spoofed Coldcard emails directed recipients to a cloned site with a “Start Hardware Audit” button. Clicking it downloaded a GitHub-hosted batch file that installed ScreenConnect, a legitimate remote-access tool that can open the door to data theft, financial theft or follow-on malware, including ransomware. The fake site also featured a live chat operated by a human who guided victims through installation. Galaxy Research said the underlying flaw traces back to a March 2021 firmware build and has already been used in three confirmed theft waves since July 30, with high-confidence losses of 1,596 BTC, or more than $100 million. Including a suspected but unconfirmed fourth wave, total losses could reach $130 million.
Coldcardhardware walletsphishingBitcoincybersecurityTrezorFoundationGalaxy Research

Hardware wallet makers Trezor and Foundation are warning users about a rise in phishing attempts tied to the Coldcard firmware exploit, as attackers try to steal recovery phrases and push malicious downloads.

Coldcard exploit sparks phishing wave as potential losses approach $130 million 2

Trezor and Foundation issue user warnings

Trezor said it had already seen more phishing attempts after the vulnerability was disclosed. The company told users to enter a wallet backup only on the device itself and said its own hardware is unaffected.

Foundation said it had been alerted to emails impersonating the firm and steering recipients to fake websites and malicious downloads. It added that it will never ask for a recovery phrase or tell users to install software to secure a wallet.

Proofpoint details a “hardware audit” phishing campaign

Security firm Proofpoint documented a phishing campaign targeting Coldcard users on Monday. The emails, sent from a spoofed Coldcard address, asked recipients to complete a “coordinated hardware audit,” borrowing language from the security incident itself. They linked to a cloned Coldcard website carrying a “Start Hardware Audit” button.

“A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering w/ ‘hardware audit’ themes impersonating #COLDCARD in email-based phishing campaigns.”

Clicking the button downloaded a batch file hosted on GitHub. Proofpoint said the file installs ScreenConnect, a legitimate remote-access tool that can give attackers a path to data theft and financial theft, or to later malware deployment such as ransomware.

The cloned site also ran a customer service chat window. According to Proofpoint, a real person, not a bot, answered the chat and guided victims through the installation steps. The firm said the lure works because it “preys on the fear and concern” holders now have about their crypto security.

The flaw behind the lure

The Coldcard exploit traces back to a firmware build from March 2021. In that version, wallet seeds were generated from a software fallback rather than the device’s hardware random number generator, leaving private keys guessable.

Galaxy Research said it has confirmed three waves of thefts since July 30 and estimates high-confidence losses at 1,596 BTC, worth more than $100 million. If a fourth wave that it suspects, but has not confirmed with victims, is included, total losses could reach $130 million.

Alex Thorn, Galaxy Research’s head of research, said Tuesday that at least 15 separate attackers are now exploiting the flaw. He added that every wave except the first was identified through victim reports.

Coldcard maker Coinkite has released patched firmware and told affected users to move funds to newly generated seeds.

A familiar pattern for hardware wallet users

Phishing campaigns aimed at hardware wallet owners have taken several forms this year.

  • In February, Trezor and Ledger users were targeted by a physical mail campaign impersonating the two firms, complete with holograms and forged executive signatures, and built around the same manufactured deadline.
  • In April, a counterfeit Ledger app drained millions from holders.
  • In March, another campaign used fake GitHub issues to lure developers to a spoofed site.

Galaxy Research said the Coldcard exploit is still active and urged holders to move funds to a fresh seed or a custodian. That also gives the phishing lure a potentially long shelf life.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.