Hardware Wallet Firms Report Phishing Surge as Coldcard Exploit Losses Mount Toward $130M
Security researchers have documented coordinated phishing campaigns targeting Coldcard users, as manufacturers Trezor and Foundation warn of increased attacks capitalizing on the recent firmware vulnerability.
Phishing Campaign Exploits Coldcard Vulnerability
Following the disclosure of a critical Coldcard firmware vulnerability, hardware wallet manufacturers are reporting a sharp uptick in phishing attempts. According to Proofpoint, researchers have identified a sophisticated phishing campaign specifically targeting Coldcard users with spoofed emails claiming to offer a “coordinated hardware audit”—a theme directly exploiting the fears generated by the original security incident.
The attackers have created a cloned Coldcard website complete with a “Start Hardware Audit” button. Clicking it downloads a batch file from GitHub that installs ScreenConnect, a legitimate remote-access tool that attackers weaponize for data theft, financial theft, or deployment of follow-on malware such as ransomware. Notably, the fake site operates a customer service chat staffed by real people rather than automated bots, who walk victims through the installation process. Proofpoint assessed this as an effective social engineering tactic because it exploits the genuine fear users now feel about their cryptocurrency security.
Major Manufacturers Sound Alarm
Trezor and Foundation have both issued warnings about the phishing surge. Trezor emphasized that its own hardware remains unaffected by the Coldcard vulnerability and reminded users that wallet backups should only ever be entered on the device itself, never on a computer. Foundation warned users about emails impersonating the firm that direct recipients to fake websites and malicious downloads, clarifying that it will never request recovery phrases or ask users to install software to secure their wallets.
Losses Climb as Multiple Attackers Exploit the Flaw
The scale of damage from the original Coldcard exploit continues to mount. According to Galaxy Research, the vulnerability stemmed from a March 2021 firmware build that drew wallet seeds from a software fallback rather than the device’s hardware random number generator, making private keys potentially guessable. Galaxy Research has confirmed three waves of thefts since July 30, with documented losses reaching 1,596 BTC—over $100 million. When accounting for a suspected fourth wave not yet verified with victims, total losses could reach $130 million. Galaxy Research noted that at least 15 separate attackers are exploiting the flaw, with every confirmed wave after the first identified through victim reports rather than proactive discovery.
This convergence of a critical hardware vulnerability and coordinated phishing attacks underscores how security breaches cascade through the crypto ecosystem, eroding trust in otherwise secure hardware solutions.
Source: Proofpoint, via Decrypt. Not financial advice.