Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Approach $130M
Key Takeaways
- •The Coldcard vulnerability originates from a March 2021 firmware build that used a software fallback instead of the device's hardware random number generator, making private keys predictable and guessable.
- •Galaxy Research has confirmed losses of at least 1,596 BTC exceeding $100 million across three theft waves, with a suspected fourth wave potentially bringing the total to $130 million.
- •Proofpoint documented a phishing campaign using spoofed Coldcard emails that lead victims to a cloned website with a live chat representative who assists in installing remote-access malware.
- •At least 15 separate attackers are now exploiting the Coldcard vulnerability, with every theft wave after the first identified through victim reports.
- •Coinkite has released patched firmware and advises all affected users to immediately transfer their funds to newly generated wallet seeds or a custodian.

Hardware wallet manufacturers Trezor and Foundation have issued warnings about a surge in phishing attempts exploiting the Coldcard firmware vulnerability, as scammers pursue users' recovery phrases and distribute malicious downloads. The campaigns highlight a broader risk for self-custody users: because hardware wallets are designed so that individuals control their own private keys, anyone who obtains a wallet's 12- or 24-word recovery phrase can move the funds without the physical device.
Trezor reported it was already observing an increase in phishing attempts following the disclosure of the Coldcard exploit, advising users to enter wallet backups only on the device itself and reiterating that its own hardware remains unaffected by the vulnerability. Foundation stated it had been made aware of emails impersonating the company that direct recipients toward fake websites and malicious downloads, emphasizing that it will never request a recovery phrase or instruct users to install software to secure a wallet.
Security firm Proofpoint documented a phishing campaign targeting Coldcard users on Monday. Emails sent from a spoofed Coldcard address invite recipients to complete a "coordinated hardware audit"—a theme borrowed directly from the security incident itself—and direct them to a cloned Coldcard website featuring a "Start Hardware Audit" button.
A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering w/ "hardware audit" themes impersonating #COLDCARD in email-based phishing campaigns. pic.twitter.com/1KSfZW3H2N
— Threat Insight (@threatinsight), August 3, 2026
Clicking the button downloads a batch file hosted on GitHub, which installs ScreenConnect, a legitimate remote-access tool. Proofpoint said this provides attackers with a pathway to data and financial theft, as well as the ability to deploy follow-on malware such as ransomware.
The fake website also operates a customer service chat window staffed by a live person rather than an automated bot, according to Proofpoint. The human representative guides victims through the installation process step by step. Proofpoint assessed the campaign as an effective social engineering lure because it "preys on the fear and concern" holders now have about their cryptocurrency security.
The Exploit Behind the Lure
The Coldcard exploit originates from a March 2021 firmware build that generated wallet seeds using a software fallback rather than the device's hardware random number generator, rendering private keys predictable and ultimately guessable. Coldcard, manufactured by Coinkite, is a Bitcoin-only hardware wallet popular among self-custody advocates for its air-gapped design and open-source firmware.
Galaxy Research has confirmed three waves of thefts since July 30 and estimates high-confidence losses at 1,596 BTC, exceeding $100 million. Including a fourth wave the firm suspects but has not yet verified with victims, the total could reach $130 million.
Galaxy Research's Head of Research Alex Thorn stated on Tuesday that at least 15 separate attackers are now exploiting the vulnerability, noting that every wave after the first was identified through victim reports. Coldcard manufacturer Coinkite has released patched firmware and advised affected users to transfer their funds to newly generated seeds immediately.
A Familiar Playbook
Phishing campaigns have employed a variety of methods to target hardware wallet owners in recent months. In February, Trezor and Ledger users were targeted by a physical mail campaign impersonating both firms, complete with holograms and forged executive signatures, all built around a fabricated deadline. A counterfeit Ledger application drained millions from holders in April, and a March campaign leveraged fake GitHub issues to lure developers onto a spoofed website. The pattern illustrates how attackers systematically exploit fear following security disclosures, timing their lures to moments when users are most likely to act urgently.
Galaxy Research said the Coldcard exploit remains ongoing and urged holders to move funds to a fresh seed or a custodian—giving the associated phishing lure a potentially long shelf life for as long as the vulnerability continues to be exploited.