Coldcard Phishing Surge: $130M in Losses as Trezor, Foundation Warn

Editorial illustration for: Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M

In brief

  • Phishing emails impersonate Coldcard, inviting users to complete a fake 'coordinated hardware audit' on a cloned site
  • ScreenConnect remote-access tool installed via fake site; attackers guide victims through installation in real time
  • Galaxy Research confirms 1,596 BTC in high-confidence losses ($100M+); total theft estimated at $130 million
  • At least 15 separate attackers exploit Coldcard flaw; Coinkite released patched firmware and urged fund migration

The Phishing Mechanics

Emails sent from spoofed Coldcard addresses invite recipients to complete a "coordinated hardware audit," a theme lifted directly from the security incident itself. Clicking the "Start Hardware Audit" button pulls a batch file that installs ScreenConnect, a legitimate remote-access tool. What makes this campaign unusually effective is the human element: the fake site runs a customer service chat window staffed by a real person who walks victims through the ScreenConnect installation process.

Proofpoint, the security firm tracking the campaign, assessed it as an effective social engineering lure precisely because it "preys on the fear and concern" holders now have about their crypto security. The combination of a familiar brand, a plausible security narrative, and live human support creates a convincing attack surface that most users wouldn't question in the moment.

At least 15 separate attackers are now exploiting the Coldcard flaw. The wave of thefts began on July 30, with Galaxy Research confirming three waves and putting high-confidence losses at 1,596 BTC, above $100 million. Including a suspected fourth wave, Galaxy Research said the total could reach $130 million.

The Root Cause and Response

The Coldcard exploit stems from a March 2021 firmware build that drew wallet seeds from a software fallback instead of the device's hardware random number generator. This design flaw meant that seeds generated on affected devices weren't truly random, making them vulnerable to reconstruction by attackers who obtained the device.

Coldcard manufacturer Coinkite has issued patched firmware and told affected users to move funds to newly generated seeds. Galaxy Research urged holders to move funds to a fresh seed or a custodian immediately.

Foundation stated it will never ask for a recovery phrase or tell users to install software to secure a wallet. Trezor advised users to enter a wallet backup only on the device itself and reiterated that its own hardware is unaffected. The warnings come as hardware wallet users face an escalating threat landscape. In February, Trezor and Ledger users were hit by a physical mail campaign impersonating the firms, complete with holograms and forged executive signatures. A counterfeit Ledger app drained millions from holders in April.

The Coldcard exploit is ongoing. Holders who used affected firmware builds should treat their seeds as compromised and move to fresh ones without delay.