Hardware cryptocurrency wallet manufacturers Trezor and Foundation have warned users about phishing attacks following the Coldcard incident.
Following the Coldcard vulnerability disclosure, we're already seeing an increase in phishing attempts.
— Trezor (@Trezor) August 4, 2026
Stay alert for scams ⚠️
• Never share your wallet backup, aka recovery seed (12/20/24 words)
• Only enter your wallet backup directly on your Trezor device during recovery...
Trezor stated that it has observed an increase in phishing attempts following the disclosure of the Coldcard vulnerability. The company reminded users to only enter their wallet backup (recovery seed) directly on the hardware device itself, and not on any website, app, or via instructions from unsolicited messages.
"Trezor will never contact you to request your wallet backup," the warning states.
Foundation representatives reported that scammers are sending emails impersonating the company. These emails attempt to trick users into visiting fake websites or downloading malicious software.
🚨 Phishing Alert 🚨
— FOUNDATION (@FoundationHQ) August 2, 2026
We’ve been made aware of phishing emails impersonating Foundation following the recent Coldcard security incident.
These emails attempt to trick users into downloading malicious software or visiting fake websites.
Please remember:0• Never download... pic.twitter.com/5zzblHuSj2
"Foundation will never DM you first, ask you to reveal your recovery phrase, or demand you install unknown software to 'protect' your wallet," the company stated.
How the Scheme Works
Specialists from Proofpoint described a phishing campaign targeting Coldcard owners. Scammers send emails allegedly from the manufacturer, offering to conduct a "hardware audit."
A COLDCARD hardware wallet vulnerability is being exploited by threat actors.
— Threat Insight (@threatinsight) August 3, 2026
The reported firmware flaw has led to tens of millions worth of Bitcoin stolen.
We've observed social engineering w/ “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns. pic.twitter.com/1KSfZW3H2N
The link leads to a copy of the company's website with a "Start Hardware Audit" button. Clicking it prompts the user to download a file from GitHub, which installs ScreenConnect—a legitimate remote access tool.
According to Proofpoint's assessment, this could give attackers access to data, steal funds, or install additional malware, including ransomware. The company also claims that a fake support chat operates on the counterfeit site: a person communicates with the victims, helping them through the installation process to enhance trust in the scheme.
What Happened with Coldcard
The phishing wave coincides with the previously disclosed Coldcard vulnerability. It is related to an error in seed phrase generation: the device used a deterministic software pseudorandom number generator instead of a hardware random number generator.
Specialists at Block indicated that the issue arose from an RNG integration error in the firmware. Their assessment suggests that for Mk2 and Mk3 on the vulnerable firmware branch, no cryptographic entropy was added, while for Mk4, Mk5, and Coldcard Q, only limited entropy was added. This did not grant instant access to the wallet but could allow attackers to brute-force candidate seed phrases offline and cross-check the derived addresses against public blockchain data.
Coinkite acknowledged the problem and released patched firmware versions for the affected models. The company emphasized that updating does not change an already created seed phrase: users need to generate a new one and transfer their funds.
According to Galaxy Research, confirmed losses from three attack waves and 14 smaller incidents amount to 1596 $BTC from approximately 7300 addresses. Researchers also identified a possible fourth wave. If confirmed, the total damage could rise to 2055 $BTC, or roughly $130 million.
🚨LOSSES FROM COLDCARD HACK EXCEED $100M
— Galaxy Research (@glxyresearch) August 3, 2026
High confidence 1,596 $BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.
If we add suspected (but unconfirmed), the total balloons to $130m (2k $BTC).
More in the thread below 👇 pic.twitter.com/RAl3ib67qa
Coinkite recommended that owners of wallets with seed phrases created on vulnerable firmware versions update the device, create a new seed phrase, and transfer funds to a new address. Simply installing the new firmware does not protect the old seed phrase.
On August 4, the Coldcard team, citing Galaxy Research, warned that at least 15 different malicious actors are exploiting the vulnerability, and new clusters of thefts continue to be identified.
COLDCARD HACK FALLOUT WORSENS AS BITCOIN RED TEAM FINDS CRITICAL BUGS ACROSS ECOSYSTEM@glxyresearch estimates at least 15 different attackers are now exploiting the COLDCARD vulnerability, with new theft clusters still being identified.
— Bitcoin News (@BitcoinNewsCom) August 4, 2026
If your funds were stolen, report it to...
"Even small reports from victims help identify new malicious actors. One report of a theft of less than 1 $BTC allowed researchers to uncover a previously unknown attack that resulted in 12 $BTC being withdrawn from 126 addresses," the post states.
Recall that on August 2, Glassnode analysts concluded that following reports about the cold wallet vulnerability, the first cryptocurrency's network showed abnormal activity across several metrics simultaneously. Holders were meanwhile sending funds to new addresses, not to trading platforms.
For an analysis on why the Coldcard incident hits the Bitcoin industry harder than any exchange hack, read the article on ForkLog.
Sleep at Night Technology: How Coldcard Turned Its Users' Sleep into a Nightmare





