Coldcard-related losses may reach $130 million, hardware wallet manufacturers warn of increased phishing attacks
2026-08-04 10:54
Odaily Planet Daily News Hardware wallet manufacturers Trezor and Foundation have warned that following the disclosure of the Coldcard firmware vulnerability, phishing attempts targeting hardware wallet holders have increased, with attackers seeking recovery phrases and luring victims into downloading malware.
Security firm Proofpoint discovered phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to cloned websites. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect.
Proofpoint stated that the fake websites also feature customer service chat windows, where real people guide victims through the installation process. This remote access tool can provide attackers with a path to steal data and funds, or further deploy malicious programs such as ransomware.
Galaxy Research confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.
Security firm Proofpoint discovered phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to cloned websites. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect.
Proofpoint stated that the fake websites also feature customer service chat windows, where real people guide victims through the installation process. This remote access tool can provide attackers with a path to steal data and funds, or further deploy malicious programs such as ransomware.
Galaxy Research confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.
