Hardware Wallet Providers Flag Dangerous Phishing Campaign

04-Aug-2026 Crypto Economy

TL;DR

  • Phishing Surge: Scammers are exploiting the Coldcard flaw to target Hardware Wallet users with fake audits and malicious downloads.
  • Exploit Fallout: Galaxy Research reports over $100 million in confirmed losses, with multiple attackers leveraging the firmware vulnerability.
  • Ongoing Risk: Manufacturers warn that phishing threats will persist until all affected Hardware Wallet holders migrate to fresh seeds or custodial setups.

Phishing groups are escalating attacks against crypto holders after the Coldcard firmware flaw came to light, prompting multiple manufacturers to warn users about increasingly sophisticated traps. The surge has placed Hardware Wallet owners on high alert, with scammers leaning on fear, urgency, and impersonation to pry recovery phrases from unsuspecting targets.

Rising phishing pressure on Hardware Wallet users

Trezor and Foundation both reported a noticeable uptick in phishing attempts tied to the Coldcard exploit disclosure. Trezor reminded customers that a wallet backup should only be entered directly on the device and stressed that its Hardware Wallet products are unaffected. Foundation said it had seen emails impersonating the company, steering recipients toward fake sites and malicious downloads. It reiterated that it will never ask for a recovery phrase or instruct users to install software to secure a Hardware Wallet.

Security firm Proofpoint documented a coordinated campaign targeting Coldcard users. Attackers sent emails from a spoofed address inviting holders to complete a “coordinated hardware audit,” echoing language from the real incident. The linked cloned site featured a “Start Hardware Audit” button that delivered a GitHub-hosted batch file. Once executed, it installed ScreenConnect, giving attackers remote access and opening paths to theft or follow-on malware. Proofpoint noted that the fake site even ran a live chat staffed by a real person guiding victims through the process, making the lure especially effective for anxious Hardware Wallet owners.

Exploit fallout and expanding theft

Exploit fallout and expanding theft

The Coldcard flaw traces back to a March 2021 firmware build that relied on a software fallback for seed generation rather than the Hardware Wallet’s random number generator, making private keys guessable. Galaxy Research confirmed three waves of thefts since July 30 totaling 1,596 BTC, above $100 million.

It said a suspected fourth wave could push losses toward $130 million. It identified at least 15 attackers exploiting the vulnerability. Coinkite has issued patched firmware and urged affected users to move funds to newly generated seeds on a secure Hardware Wallet.

Long tail of phishing threats

Phishing groups have repeatedly targeted Hardware Wallet owners this year, from physical mail campaigns to counterfeit apps and spoofed developer pages. Galaxy Research said the Coldcard exploit remains active, giving scammers a long runway to keep targeting Hardware Wallet holders who have not yet migrated to fresh seeds or custodial solutions.

Also read: Important Ripple News and XRP Price Update: August 4th
WHAT'S YOUR OPINION?
Related News