TL;DR
Phishing groups are escalating attacks against crypto holders after the Coldcard firmware flaw came to light, prompting multiple manufacturers to warn users about increasingly sophisticated traps. The surge has placed Hardware Wallet owners on high alert, with scammers leaning on fear, urgency, and impersonation to pry recovery phrases from unsuspecting targets.
Following the Coldcard vulnerability disclosure, we're already seeing an increase in phishing attempts.
Stay alert for scams
• Never share your wallet backup, aka recovery seed (12/20/24 words)
• Only enter your wallet backup directly on your Trezor device during recovery…— Trezor (@Trezor) August 4, 2026
Trezor and Foundation both reported a noticeable uptick in phishing attempts tied to the Coldcard exploit disclosure. Trezor reminded customers that a wallet backup should only be entered directly on the device and stressed that its Hardware Wallet products are unaffected. Foundation said it had seen emails impersonating the company, steering recipients toward fake sites and malicious downloads. It reiterated that it will never ask for a recovery phrase or instruct users to install software to secure a Hardware Wallet.
A COLDCARD hardware wallet vulnerability is being exploited by threat actors.
The reported firmware flaw has led to tens of millions worth of Bitcoin stolen.
We've observed social engineering w/ “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns. pic.twitter.com/1KSfZW3H2N
— Threat Insight (@threatinsight) August 3, 2026
Security firm Proofpoint documented a coordinated campaign targeting Coldcard users. Attackers sent emails from a spoofed address inviting holders to complete a “coordinated hardware audit,” echoing language from the real incident. The linked cloned site featured a “Start Hardware Audit” button that delivered a GitHub-hosted batch file. Once executed, it installed ScreenConnect, giving attackers remote access and opening paths to theft or follow-on malware. Proofpoint noted that the fake site even ran a live chat staffed by a real person guiding victims through the process, making the lure especially effective for anxious Hardware Wallet owners.

The Coldcard flaw traces back to a March 2021 firmware build that relied on a software fallback for seed generation rather than the Hardware Wallet’s random number generator, making private keys guessable. Galaxy Research confirmed three waves of thefts since July 30 totaling 1,596 BTC, above $100 million.
It said a suspected fourth wave could push losses toward $130 million. It identified at least 15 attackers exploiting the vulnerability. Coinkite has issued patched firmware and urged affected users to move funds to newly generated seeds on a secure Hardware Wallet.
Phishing groups have repeatedly targeted Hardware Wallet owners this year, from physical mail campaigns to counterfeit apps and spoofed developer pages. Galaxy Research said the Coldcard exploit remains active, giving scammers a long runway to keep targeting Hardware Wallet holders who have not yet migrated to fresh seeds or custodial solutions.