All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Hardware Wallet Firms Warn of Phishing Surge After Coldcard Exploit

Created at 4 Aug · 11:00 AM1 source↑ Market-relevant
IN SHORT

Trezor and Foundation are alerting users to a rise in phishing attempts following the Coldcard firmware exploit. Scammers are using fake websites and social engineering to trick users into revealing recovery phrases or downloading malicious software, with losses nearing $130 million.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$130Mestimated total losses from Coldcard exploit
1,596 BTChigh-confidence Bitcoin stolen
March 2021Coldcard firmware build with vulnerability
15separate attackers exploiting the flaw

Who's Involved

Trezor
hardware wallet firm warning of phishing surge
Foundation
hardware wallet firm warning of phishing surge
Proofpoint
security firm documenting phishing campaign
Alex Thorn
Head of Research at Galaxy Research
Coinkite
Coldcard manufacturer that issued patched firmware
Hardware Wallet Firms Warn of Phishing Surge After Coldcard Exploit

↳ Why This Matters

The ongoing exploitation of hardware wallet vulnerabilities and subsequent phishing campaigns highlight critical security risks for cryptocurrency holders, potentially leading to substantial financial losses and eroding trust in digital asset security measures.

Key facts

  • Trezor and Foundation have warned of increased phishing attempts targeting hardware wallet owners.
  • Scammers are using a cloned Coldcard website and social engineering tactics to steal recovery phrases and push malicious downloads.
  • A vulnerability in a March 2021 Coldcard firmware build allows private keys to be guessable.
  • Losses from the Coldcard exploit are estimated to be near $130 million in Bitcoin.
  • Proofpoint identified a campaign that installs remote-access software via a GitHub-hosted batch file.

Hardware wallet manufacturers Trezor and Foundation have issued warnings about a significant increase in phishing attempts targeting their users, following a known exploit affecting Coldcard devices. Scammers are leveraging the fear and concern generated by the Coldcard incident to trick individuals into revealing their cryptocurrency recovery phrases or downloading malicious software.

Proofpoint, a security firm, detailed a specific phishing campaign that impersonates Coldcard by using emails with a "Hardware Audit" theme. These emails link to a cloned Coldcard website that prompts users to download a batch file from GitHub. This file installs ScreenConnect, a legitimate remote-access tool, which then grants attackers access to the victim's data and financial assets, potentially leading to ransomware attacks.

The Coldcard exploit originates from a firmware version released in March 2021. This version drew wallet seeds from a software fallback instead of the device's hardware random number generator, making private keys guessable. Galaxy Research has confirmed multiple waves of thefts since late July, estimating high-confidence losses at 1,596 Bitcoin, valued at over $100 million. The firm suggests that with a fourth suspected wave, total losses could approach $130 million, with at least 15 different attackers exploiting the vulnerability.

Coldcard manufacturer Coinkite has released patched firmware and advised affected users to transfer their funds to newly generated seeds. This incident is part of a broader trend of phishing campaigns targeting hardware wallet owners, including previous attacks involving physical mail, counterfeit apps, and fake GitHub issues.

Frequently asked questions

The exploit stems from a March 2021 firmware build that used a software fallback for wallet seeds instead of the hardware random number generator, making private keys guessable.

Scammers are using phishing emails with "Hardware Audit" themes to lure users to fake websites that prompt them to download remote-access software.

Losses are estimated to be near $130 million in Bitcoin, with at least 15 attackers exploiting the flaw.

Users should move funds to newly generated seeds or a custodian and be wary of phishing attempts.

What Happens Next

01Affected users are advised to move funds to newly generated seeds or a custodian.
02Users are urged to be vigilant against phishing attempts and verify all communications.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

A Coldcard hardware wallet vulnerability in a March 2021 firmware build was exploited.
Threat actors are using social engineering with "hardware audit" themes in phishing campaigns.
A cloned Coldcard site and a batch file hosted on GitHub install remote-access software.
A person staffs the fake site's customer service chat to guide victims through installation.
Galaxy Research confirmed three waves of thefts totaling at least 1,596 BTC, exceeding $100 million.
Total losses could reach $130 million, with at least 15 attackers exploiting the flaw.
Trezor and Foundation reported a surge in phishing attempts targeting hardware wallet owners.
Coldcard manufacturer Coinkite issued patched firmware and advised affected users to move funds.

Sources

T1
Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130MDecrypt

Related Stories

Coldcard Bitcoin Hack Losses Exceed $114 Million
3 Aug · 1:16 PM
Dormant Bitcoin Wallet Moves $31M Amid Coldcard Security Crisis
4 Aug · 4:56 AM
Coldcard Exploit Highlights Risks in Air-Gapped Bitcoin Wallets
3 Aug · 8:46 PM
Solo Bitcoin miner nets $200,000 as Coldcard exploit rattles holders
3 Aug · 11:26 AM
Bitcoin nears $64,000 as Coldcard exploit fears recede
4 Aug · 5:26 AM