XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

Hardware Wallet Firms Report Phishing Surge as Coldcard Exploit Losses Mount Toward $130M

Security researchers have documented coordinated phishing campaigns targeting Coldcard users, as manufacturers Trezor and Foundation warn of increased attacks capitalizing on the recent firmware vulnerability.

JM
by Jacob Marquez · Markets Desk
Published August 4, 2026 · 2 min read

Phishing Campaign Exploits Coldcard Vulnerability

Following the disclosure of a critical Coldcard firmware vulnerability, hardware wallet manufacturers are reporting a sharp uptick in phishing attempts. According to Proofpoint, researchers have identified a sophisticated phishing campaign specifically targeting Coldcard users with spoofed emails claiming to offer a “coordinated hardware audit”—a theme directly exploiting the fears generated by the original security incident.

The attackers have created a cloned Coldcard website complete with a “Start Hardware Audit” button. Clicking it downloads a batch file from GitHub that installs ScreenConnect, a legitimate remote-access tool that attackers weaponize for data theft, financial theft, or deployment of follow-on malware such as ransomware. Notably, the fake site operates a customer service chat staffed by real people rather than automated bots, who walk victims through the installation process. Proofpoint assessed this as an effective social engineering tactic because it exploits the genuine fear users now feel about their cryptocurrency security.

Major Manufacturers Sound Alarm

Trezor and Foundation have both issued warnings about the phishing surge. Trezor emphasized that its own hardware remains unaffected by the Coldcard vulnerability and reminded users that wallet backups should only ever be entered on the device itself, never on a computer. Foundation warned users about emails impersonating the firm that direct recipients to fake websites and malicious downloads, clarifying that it will never request recovery phrases or ask users to install software to secure their wallets.

Losses Climb as Multiple Attackers Exploit the Flaw

The scale of damage from the original Coldcard exploit continues to mount. According to Galaxy Research, the vulnerability stemmed from a March 2021 firmware build that drew wallet seeds from a software fallback rather than the device’s hardware random number generator, making private keys potentially guessable. Galaxy Research has confirmed three waves of thefts since July 30, with documented losses reaching 1,596 BTC—over $100 million. When accounting for a suspected fourth wave not yet verified with victims, total losses could reach $130 million. Galaxy Research noted that at least 15 separate attackers are exploiting the flaw, with every confirmed wave after the first identified through victim reports rather than proactive discovery.

This convergence of a critical hardware vulnerability and coordinated phishing attacks underscores how security breaches cascade through the crypto ecosystem, eroding trust in otherwise secure hardware solutions.

Source: Proofpoint, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.