Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M
Trezor and Foundation warned that phishing has surged after disclosure of a Coldcard firmware exploit. Attackers are impersonating wallet brands, pushing fake sites and malicious downloads to steal recovery phrases and funds. Trezor told users to enter backups only on the device itself and said its hardware is unaffected. Foundation said it will never ask for a recovery phrase or tell users to install software to secure a wallet. Proofpoint found a campaign spoofing Coldcard emails and using a “hardware audit” theme. Victims are sent to a cloned site where clicking a button downloads a batch file from GitHub that installs ScreenConnect, enabling remote access, theft, or follow-on malware. The fake site also includes a live chat with a real operator guiding victims through installation. The exploit traces to a March 2021 firmware build that could generate recoverable seeds. Galaxy Research says at least 1,596 BTC, over $100 million, has been stolen across multiple waves, with losses potentially reaching $130 million. Coinkite has released patched firmware and urged users to move funds to new seeds.
