Summary

  • Trezor and Foundation have reported a notable increase in phishing attempts aimed at hardware wallet users in the wake of the Coldcard exploit.
  • Proofpoint uncovered a phishing scheme specifically targeting Coldcard users, featuring a replicated website and a "Hardware Audit" that installs remote-access software.
  • Victims interact with a real person in the fake site's customer service chat, who guides them through the installation process.

Hardware wallet companies Trezor and Foundation have issued warnings about a rise in phishing attempts that exploit the Coldcard firmware vulnerability. These scams aim to extract users' recovery phrases and promote harmful downloads.

Trezor noted an uptick in phishing attempts since the exploit was made public, advising users to input their wallet backups solely on their devices and confirming that their hardware remains secure. Foundationreported awareness of phishing emails impersonating the company, directing users to counterfeit websites and malicious downloads. They emphasized that they will never request recovery phrases or instruct users to install software for wallet security.

Security firm Proofpoint identified a phishing campaign targeting Coldcard users on Monday. Emails originating from a spoofed Coldcard address invite recipients to partake in a "coordinated hardware audit," mirroring the security incident, and link to a cloned Coldcard site featuring a "Start Hardware Audit" option.

Threat actors are exploiting a vulnerability in the COLDCARD hardware wallet.

This firmware flaw has resulted in the theft of tens of millions in Bitcoin.

We have observed social engineering tactics using “hardware audit” themes in email phishing campaigns. #COLDCARD

— Threat Insight (@threatinsight) August 3, 2026

Clicking this link downloads a batch file hosted on GitHub, which installs ScreenConnect, a legitimate remote-access tool. According to Proofpoint, this provides attackers with a means for data and financial theft, or to deploy additional malware like ransomware.

The fraudulent site also features a customer service chat window. Proofpoint reported that a real person, not an automated bot, responds and assists victims through the installation process, which is deemed an effective social engineering tactic as it exploits the apprehension users have regarding their crypto security.

Understanding the Exploit

The Coldcard exploit originated from a firmware build released in March 2021 that extracted wallet seeds from a software fallback instead of the device's hardware random number generator, making private keys vulnerable to guessing.

Galaxy Research has confirmed three waves of thefts since July 30, estimating high-confidence losses at 1,596 BTC, valued over $100 million. Including a fourth wave that remains unverified, the total losses could reach $130 million.

Alex Thorn, Head of Research at Galaxy, stated on Tuesday that at least 15 distinct attackers are currently exploiting this flaw, highlighting that all but the initial wave were detected through reports from victims. Coldcard manufacturer Coinkite has released patched firmware and advised affected users to transfer funds to newly generated seeds.

Recurring Phishing Strategies

Phishing campaigns have employed various tactics to target hardware wallet owners. In February, Trezor and Ledger users faced a physical mail campaign impersonating the companies, complete with holograms and forged signatures, based around an artificial deadline. A counterfeit Ledger app siphoned millions from users in April, while a March campaign utilized fake GitHub issues to lure developers to a spoofed site.

Galaxy Research warns that the Coldcard exploit remains active, encouraging users to migrate their funds to a new seed or a custodian, which could prolong the effectiveness of the phishing lure.

Stay Updated with Daily News

Keep informed with the latest news stories and original features by subscribing to our daily newsletter.