Key facts
- Trezor and Foundation have warned of increased phishing attempts targeting hardware wallet owners.
- Scammers are using a cloned Coldcard website and social engineering tactics to steal recovery phrases and push malicious downloads.
- A vulnerability in a March 2021 Coldcard firmware build allows private keys to be guessable.
- Losses from the Coldcard exploit are estimated to be near $130 million in Bitcoin.
- Proofpoint identified a campaign that installs remote-access software via a GitHub-hosted batch file.
Hardware wallet manufacturers Trezor and Foundation have issued warnings about a significant increase in phishing attempts targeting their users, following a known exploit affecting Coldcard devices. Scammers are leveraging the fear and concern generated by the Coldcard incident to trick individuals into revealing their cryptocurrency recovery phrases or downloading malicious software.
Proofpoint, a security firm, detailed a specific phishing campaign that impersonates Coldcard by using emails with a "Hardware Audit" theme. These emails link to a cloned Coldcard website that prompts users to download a batch file from GitHub. This file installs ScreenConnect, a legitimate remote-access tool, which then grants attackers access to the victim's data and financial assets, potentially leading to ransomware attacks.
The Coldcard exploit originates from a firmware version released in March 2021. This version drew wallet seeds from a software fallback instead of the device's hardware random number generator, making private keys guessable. Galaxy Research has confirmed multiple waves of thefts since late July, estimating high-confidence losses at 1,596 Bitcoin, valued at over $100 million. The firm suggests that with a fourth suspected wave, total losses could approach $130 million, with at least 15 different attackers exploiting the vulnerability.
Coldcard manufacturer Coinkite has released patched firmware and advised affected users to transfer their funds to newly generated seeds. This incident is part of a broader trend of phishing campaigns targeting hardware wallet owners, including previous attacks involving physical mail, counterfeit apps, and fake GitHub issues.
