NewsCryptoTrezor Warns of Rising Phishing Attempts Following COLDCARD Exploit

Trezor Warns of Rising Phishing Attempts Following COLDCARD Exploit

Author: Tron Weekly·

Key Takeaways

  • A malicious actor exploited a five-year-old key-generation vulnerability in COLDCARD hardware wallets on July 31, stealing approximately 594 BTC worth around $38 million from roughly 500 self-custody wallets.
  • Phishing attackers are impersonating support teams from companies such as Trezor and Ledger, sending fraudulent emails and direct messages requesting urgent wallet migration or seed phrase verification.
  • Glassnode data shows the Revived Supply 1y+ metric surged to 119,423 BTC within three days of the exploit as users rushed to relocate their assets.
  • Galaxy has estimated that total losses from the COLDCARD exploit could ultimately reach 2,055 BTC, with the attack reportedly now in its fourth wave.
  • Trezor advises users to ignore unsolicited migration orders, never share their private seed phrases, and only install firmware updates through official channels.
Trezor Warns of Rising Phishing Attempts Following COLDCARD Exploit

Trezor, the hardware wallet provider, has identified a noticeable increase in phishing email campaigns targeting self-custody crypto investors in the wake of the July 31 COLDCARD exploit. The company advises users to ignore any unsolicited migration orders and to refrain from sharing their private seed phrases, warning that scammers are likely to exploit panic among affected users.

What Prompted the Alert

On July 31, a malicious actor leveraged a five-year-old vulnerability in the key-generation process of COLDCARD hardware wallets — Bitcoin-only devices manufactured by Coinkite — to steal approximately 594 BTC — worth roughly $38 million — from around 500 self-custody wallets.

While the thefts were relatively modest compared to daily Bitcoin transaction volumes, Glassnode data shows that the Revived Supply 1y+ metric surged to 119,423 BTC within three days as users rushed to move their assets.

Phishing Spree Follows On-Chain Incidents

Phishing attacks frequently follow wallet-related incidents. The 2020 Ledger customer data breach, which exposed personal information of roughly 270,000 customers, illustrates how a single incident can fuel sustained phishing campaigns lasting years. In the current case, attackers are impersonating support teams from companies such as Trezor, Ledger, and others, sending emails and direct messages that request "urgent migration" or "seed verification."

LATEST: 🚨 Trezor says it is seeing an increase in phishing attempts amid the ongoing COLDCARD hack, reminding users to never share their recovery seed or follow unsolicited wallet migration instructions. pic.twitter.com/ki0P18uBhQ — CoinMarketCap (@CoinMarketCap) August 5, 2026

Trezor's alert is consistent with longstanding industry recommendations: seed phrases should never be typed into any website, and firmware updates should only be installed through official channels. Self-custody users, institutions relying on multi-signature setups, and developers building crypto retail tools are among those most at risk.

Wallet Security — A Broader Perspective

The incident underscores a persistent dilemma within the crypto security industry. Hardware wallets remain a critical defense against exchange counterparty risk, yet the key-generation flaw at the center of the COLDCARD case — present for five years before exploitation — highlights that even widely trusted hardware is not immune to deeply embedded defects. Human error and social engineering continue to be among the most significant security threats.

Against the backdrop of large-scale Bitcoin ETF withdrawals from the U.S. spot market and a significant increase in on-chain activity, education and verification are becoming two foundational pillars for a more resilient ecosystem. Galaxy has estimated that COLDCARD exploit losses could ultimately reach 2,055 BTC, and the attack has reportedly entered its fourth wave, with 448 Bitcoin moving across wallets.