Manufacturers of hardware cryptocurrency wallets, Trezor and Foundation, have issued warnings to their users regarding a rise in phishing attacks following the Coldcard incident.
"Following the Coldcard vulnerability disclosure, we're already seeing an increase in phishing attempts. Stay alert for scams ⚠️ • Never share your wallet backup, aka recovery seed (12/20/24 words) • Only enter your wallet backup directly on your Trezor device during recovery…" — Trezor (@Trezor) August 4, 2026
Trezor noted that since the Coldcard vulnerability was revealed, they have observed a spike in phishing attempts. The company emphasized that users should only enter their wallet backup on the device itself, rather than on a website, app, or in response to unsolicited messages.
"Trezor will never contact you asking for your wallet backup," the warning stated.
Foundation representatives reported that scammers are sending emails impersonating the company, attempting to lure users into visiting fraudulent websites or downloading malicious software.
🚨 Phishing Alert 🚨
"We’ve been made aware of phishing emails impersonating Foundation following the recent Coldcard security incident. These emails attempt to trick users into downloading malicious software or visiting fake websites. Please remember:⁰• Never download… pic.twitter.com/5zzblHuSj2" — FOUNDATION (@FoundationHQ) August 2, 2026
"Foundation will never initiate contact with you via direct messages, request your recovery phrase, or demand that you install unknown software to 'secure' your wallet," the company stated.
Understanding the Scheme
Experts from Proofpoint have detailed a phishing campaign targeting Coldcard owners. Scammers are sending emails that appear to be from the manufacturer, suggesting a "hardware audit."
"A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering with 'hardware audit' themes impersonating #COLDCARD in email-based phishing campaigns." — Threat Insight (@threatinsight) August 3, 2026
The link in these emails directs users to a copy of the company’s website, featuring a button labeled Start Hardware Audit. Clicking this button prompts the user to download a file from GitHub, which installs ScreenConnect—a legitimate remote access tool.
According to Proofpoint, this could allow attackers to access sensitive data, steal funds, or install additional malware, including ransomware. The company also noted that the fake site includes a support chat feature, where a person assists victims with the installation, enhancing the scheme's credibility.
What Happened with Coldcard
This wave of phishing attacks coincides with the revelation of a vulnerability in Coldcard, linked to a flaw in the generation of seed phrases. The device utilized a deterministic software random number generator instead of a hardware random number generator.
Experts from Block identified that the issue arose from a misintegration of the RNG in the firmware. Their assessment indicated that for Mk2 and Mk3 models, no cryptographic entropy was added in the vulnerable firmware branch, while Mk4, Mk5, and Coldcard Q used limited additions. Although this did not grant immediate access to the wallet, it potentially enabled attackers to brute-force candidate seed phrases offline and cross-reference generated addresses with public blockchain data.
Coinkite acknowledged the issue and released updated firmware versions for affected models. The company stressed that the update does not alter existing seed phrases; users need to generate a new one and transfer their funds accordingly.
According to Galaxy Research, confirmed losses from three waves of attacks and 14 smaller incidents amount to 1,596 BTC, affecting approximately 7,300 addresses. Researchers also identified a potential fourth wave. If confirmed, total damages may rise to 2,055 BTC, or around $130 million.
🚨LOSSES FROM COLDCARD HACK EXCEED $100M
High confidence 1,596 BTC has been stolen from ~7,300 addresses across 3 confirmed waves + more 14 smaller incidents. If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC). More in the thread below 👇 pic.twitter.com/RAl3ib67qa" — Galaxy Research (@glxyresearch) August 3, 2026
Coinkite advised wallet owners with seed phrases generated on vulnerable firmware versions to update their devices, create new seed phrases, and transfer their funds to new addresses. Simply installing the new firmware does not secure the old seed phrase.
On August 4, the Coldcard team, referencing Galaxy Research, warned that at least 15 different attackers are exploiting the vulnerability, with new clusters of thefts still being identified.
"COLDCARD HACK FALLOUT WORSENS AS BITCOIN RED TEAM FINDS CRITICAL BUGS ACROSS ECOSYSTEM. @glxyresearch estimates at least 15 different attackers are now exploiting the COLDCARD vulnerability, with new theft clusters still being identified. If your funds were stolen, report it to…" — Bitcoin News (@BitcoinNewsCom) August 4, 2026
"Even small reports of victims help identify new attackers. One report of a theft involving less than 1 BTC allowed researchers to uncover a previously unknown attack that drained 12 BTC from 126 addresses," the post stated.
On August 2, analysts from Glassnode concluded that following the news of vulnerabilities in cold wallets, the Bitcoin network exhibited abnormal activity across several metrics. Holders were transferring funds to new addresses rather than to trading platforms.
For insights on why the Coldcard incident impacts the Bitcoin industry more significantly than any exchange hack, refer to the ForkLog article.
