Crypto & Web3·Aug 4, 2026

Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M

Fake "coordinated hardware audit" emails are steering holders to a cloned Coldcard site that installs remote-access software.

Decrypt3 min readVerified
Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M
Image · Decrypt
The gist
5-point summary · 1 min

Fake "coordinated hardware audit" emails are steering holders to a cloned Coldcard site that installs remote-access software.

  • In brief Trezor and Foundation both reported a surge in phishing attempts targeting hardware wallet owners following the Coldcard exploit.
  • Proofpoint identified a phishing campaign targeting Coldcard holders with a cloned site and "Hardware Audit" that installs remote-access software.
  • A person, rather than a bot, staffs the fake site's customer service chat and talks victims through the install.
  • Emails sent from a spoofed Coldcard address invite recipients to complete a "coordinated hardware audit," a theme lifted from the security incident itself, and link to a cloned Coldcard site carrying a "Start Hardware Audit" button.
  • In February, Trezor and Ledger users were hit by a physical mail campaign impersonating the firms, complete with holograms and forged executive signatures, built around the same manufactured deadline.
$130M$100 million$130 millionMarch 2021
In this article

In brief Trezor and Foundation both reported a surge in phishing attempts targeting hardware wallet owners following the Coldcard exploit. Proofpoint identified a phishing campaign targeting Coldcard holders with a cloned site and "Hardware Audit" that installs remote-access software. A person, rather than a bot, staffs the fake site's customer service chat and talks victims through the install. Hardware wallet manufacturers Trezor and Foundation have warned of a surge in phishing attempts trading on the Coldcard firmware exploit, with scammers chasing users' recovery phrases and pushing malicious downloads.Trezor said it was already seeing an increase in phishing attempts following the disclosure, telling users to enter a wallet backup only on the device itself and reiterating that its own hardware is unaffected. Foundation said it had been made aware of emails impersonating the firm that push recipients toward fake websites and malicious downloads, adding that it will never ask for a recovery phrase or tell users to install software to secure a wallet.Security firm Proofpoint documented a phishing campaign targeting Coldcard users on Monday. Emails sent from a spoofed Coldcard address invite recipients to complete a "coordinated hardware audit," a theme lifted from the security incident itself, and link to a cloned Coldcard site carrying a "Start Hardware Audit" button. A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering w/ “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns. pic.twitter.com/1KSfZW3H2N — Threat Insight (@threatinsight) August 3, 2026Clicking it pulls a batch file hosted on GitHub, which installs ScreenConnect, a legitimate remote-access tool. Proofpoint said that gives attackers a route to data and financial theft, or to follow-on malware such as ransomware.The fake site also runs a customer service chat window. Proofpoint said a real person, not a bot, answers it and walks victims through the installation, assessing the breach as an effective social engineering lure because it “preys on the fear and concern” holders now have about their crypto security.The exploit behind the lureThe Coldcard exploit stems from a March 2021 firmware build that drew wallet seeds from a software fallback instead of the device's hardware random number generator, leaving private keys guessable.Galaxy Research has confirmed three waves of thefts since July 30 and puts high-confidence losses at 1,596 BTC, above $100 million. Including a fourth wave it suspects but has not confirmed with victims, it said the total could reach $130 million.The firm's Head of Research Alex Thorn said Tuesday that at least 15 separate attackers are now exploiting the flaw, noting that every wave but the first was identified through victim reports. Coldcard manufacturer Coinkite has issued patched firmware and told affected users to move funds to newly generated seeds.A familiar playbookPhishing campaigns have used an array of methods to target hardware wallet owners. In February, Trezor and Ledger users were hit by a physical mail campaign impersonating the firms, complete with holograms and forged executive signatures, built around the same manufactured deadline. A counterfeit Ledger app drained millions from holders in April, and a March campaign used fake GitHub issues to lure developers onto a spoofed site.Galaxy Research said the Coldcard exploit is ongoing and urged holders to move funds to a fresh seed or a custodian—giving the phishing lure a long potential shelf life.Daily Debrief NewsletterStart every day with the top news stories right now, plus original features, a podcast, videos and more.

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at Decrypt. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Newsletter

Track crypto & web3 every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.