Cryptocurrency Wallet Manufacturers Warn of Phishing Attacks

cryptonews.ruPublished on 2026-08-04Last updated on 2026-08-04

Abstract

Hardware cryptocurrency wallet manufacturers Trezor and Foundation have warned users of a surge in phishing attacks following the disclosure of a vulnerability in Coldcard wallets. Trezor and Foundation both issued alerts via social media, stating they have observed an increase in phishing attempts where attackers impersonate the companies. They emphasized that they will never ask users for their wallet recovery seed or request the download of unknown software. Cybersecurity firm Proofpoint detailed the phishing scheme targeting Coldcard users. Attackers send emails pretending to be from the manufacturer, prompting users to perform a "hardware audit." This leads to a fake website where victims download a file that installs a legitimate remote access tool, potentially giving attackers control. This phishing wave coincides with a critical vulnerability in Coldcard devices, involving a flawed random number generator (RNG) in the firmware. This weakness could allow attackers to brute-force wallet seed phrases. Manufacturer Coinkite has released firmware patches but stressed that users with seed phrases generated on vulnerable versions must create new ones and transfer funds. According to Galaxy Research, confirmed losses from the Coldcard exploit are at least 1,596 BTC (~$100M) from about 7,300 addresses, with potential total losses reaching $130 million. The company warns at least 15 different attackers are actively exploiting the flaw.

Hardware cryptocurrency wallet manufacturers Trezor and Foundation have warned users about phishing attacks following the Coldcard incident.

Following the Coldcard vulnerability disclosure, we're already seeing an increase in phishing attempts.

Stay alert for scams ⚠️

• Never share your wallet backup, aka recovery seed (12/20/24 words)
• Only enter your wallet backup directly on your Trezor device during recovery...

— Trezor (@Trezor) August 4, 2026

Trezor stated that it has observed an increase in phishing attempts following the disclosure of the Coldcard vulnerability. The company reminded users to only enter their wallet backup (recovery seed) directly on the hardware device itself, and not on any website, app, or via instructions from unsolicited messages.

"Trezor will never contact you to request your wallet backup," the warning states.

Foundation representatives reported that scammers are sending emails impersonating the company. These emails attempt to trick users into visiting fake websites or downloading malicious software.

🚨 Phishing Alert 🚨

We’ve been made aware of phishing emails impersonating Foundation following the recent Coldcard security incident.

These emails attempt to trick users into downloading malicious software or visiting fake websites.

Please remember:0• Never download... pic.twitter.com/5zzblHuSj2

— FOUNDATION (@FoundationHQ) August 2, 2026

"Foundation will never DM you first, ask you to reveal your recovery phrase, or demand you install unknown software to 'protect' your wallet," the company stated.

How the Scheme Works

Specialists from Proofpoint described a phishing campaign targeting Coldcard owners. Scammers send emails allegedly from the manufacturer, offering to conduct a "hardware audit."

A COLDCARD hardware wallet vulnerability is being exploited by threat actors.

The reported firmware flaw has led to tens of millions worth of Bitcoin stolen.

We've observed social engineering w/ “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns. pic.twitter.com/1KSfZW3H2N

— Threat Insight (@threatinsight) August 3, 2026

The link leads to a copy of the company's website with a "Start Hardware Audit" button. Clicking it prompts the user to download a file from GitHub, which installs ScreenConnect—a legitimate remote access tool.

According to Proofpoint's assessment, this could give attackers access to data, steal funds, or install additional malware, including ransomware. The company also claims that a fake support chat operates on the counterfeit site: a person communicates with the victims, helping them through the installation process to enhance trust in the scheme.

What Happened with Coldcard

The phishing wave coincides with the previously disclosed Coldcard vulnerability. It is related to an error in seed phrase generation: the device used a deterministic software pseudorandom number generator instead of a hardware random number generator.

Specialists at Block indicated that the issue arose from an RNG integration error in the firmware. Their assessment suggests that for Mk2 and Mk3 on the vulnerable firmware branch, no cryptographic entropy was added, while for Mk4, Mk5, and Coldcard Q, only limited entropy was added. This did not grant instant access to the wallet but could allow attackers to brute-force candidate seed phrases offline and cross-check the derived addresses against public blockchain data.

Coinkite acknowledged the problem and released patched firmware versions for the affected models. The company emphasized that updating does not change an already created seed phrase: users need to generate a new one and transfer their funds.

According to Galaxy Research, confirmed losses from three attack waves and 14 smaller incidents amount to 1596 $BTC from approximately 7300 addresses. Researchers also identified a possible fourth wave. If confirmed, the total damage could rise to 2055 $BTC, or roughly $130 million.

🚨LOSSES FROM COLDCARD HACK EXCEED $100M

High confidence 1,596 $BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.

If we add suspected (but unconfirmed), the total balloons to $130m (2k $BTC).

More in the thread below 👇 pic.twitter.com/RAl3ib67qa

— Galaxy Research (@glxyresearch) August 3, 2026

Coinkite recommended that owners of wallets with seed phrases created on vulnerable firmware versions update the device, create a new seed phrase, and transfer funds to a new address. Simply installing the new firmware does not protect the old seed phrase.

On August 4, the Coldcard team, citing Galaxy Research, warned that at least 15 different malicious actors are exploiting the vulnerability, and new clusters of thefts continue to be identified.

COLDCARD HACK FALLOUT WORSENS AS BITCOIN RED TEAM FINDS CRITICAL BUGS ACROSS ECOSYSTEM@glxyresearch estimates at least 15 different attackers are now exploiting the COLDCARD vulnerability, with new theft clusters still being identified.

If your funds were stolen, report it to...

— Bitcoin News (@BitcoinNewsCom) August 4, 2026

"Even small reports from victims help identify new malicious actors. One report of a theft of less than 1 $BTC allowed researchers to uncover a previously unknown attack that resulted in 12 $BTC being withdrawn from 126 addresses," the post states.

Recall that on August 2, Glassnode analysts concluded that following reports about the cold wallet vulnerability, the first cryptocurrency's network showed abnormal activity across several metrics simultaneously. Holders were meanwhile sending funds to new addresses, not to trading platforms.

For an analysis on why the Coldcard incident hits the Bitcoin industry harder than any exchange hack, read the article on ForkLog.

Sleep at Night Technology: How Coldcard Turned Its Users' Sleep into a Nightmare
end-content

Related Questions

QWhich hardware wallet manufacturers warned users about phishing attacks following the Coldcard vulnerability disclosure?

AThe hardware wallet manufacturers Trezor and Foundation warned users about phishing attacks following the Coldcard vulnerability disclosure.

QWhat is the core advice from Trezor and Foundation to users to avoid phishing scams?

AThe core advice is to never share the wallet recovery seed (the 12/20/24 words), and to only enter it directly on the physical hardware wallet device itself during recovery, not on any website, app, or as instructed in an unsolicited message.

QAccording to Proofpoint, how are phishing emails impersonating Coldcard trying to trick users?

AThe phishing emails impersonating Coldcard trick users by claiming to offer a 'hardware audit.' A link leads to a fake website with a 'Start Hardware Audit' button, which downloads a file from GitHub that installs ScreenConnect, a legitimate remote access tool, potentially giving attackers access to the victim's data.

QWhat was the fundamental vulnerability discovered in certain Coldcard wallet models?

AThe fundamental vulnerability was an error in the firmware's generation of the seed phrase. It used a deterministic software-based pseudo-random number generator instead of a proper hardware random number generator, making the seed phrases predictable and susceptible to offline brute-force attacks.

QWhat is the estimated financial impact of the Coldcard vulnerability exploitation according to Galaxy Research?

AAccording to Galaxy Research, confirmed losses from the exploitation are estimated at 1,596 BTC stolen from approximately 7,300 addresses. If suspected but unconfirmed incidents are included, the total estimated loss could rise to around 2,055 BTC, which is approximately $130 million.

Related Reads

Trading

Spot
活动图片