Coldcard's $130M bad-seed day sprouts a phishing boom 💸
Trezor and Foundation are flagging a surge in phishing attempts that piggyback on the disclosed Coldcard firmware exploit, with scammers chasing users' recovery phrases and pushing malicious downloads. Trezor said it was already seeing an increase in phishing attempts following the disclosure, telling users to enter a wallet backup only on the device itself and reiterating that its own hardware is unaffected. Foundation said it had been made aware of emails impersonating the firm that push recipients toward fake websites and malicious downloads, adding that it will never ask for a recovery phrase or tell users to install software to secure a wallet.
Security firm Proofpoint documented a phishing campaign targeting Coldcard users on Monday. Emails sent from a spoofed Coldcard address invite recipients to complete a "coordinated hardware audit," a theme lifted from the security incident itself, and link to a cloned Coldcard site carrying a "Start Hardware Audit" button. Clicking it pulls a batch file hosted on GitHub, which installs ScreenConnect, a legitimate remote-access tool. Proofpoint said that gives attackers a route to data and financial theft, or to follow-on malware such as ransomware. The fake site also runs a customer service chat window. Proofpoint said a real person, not a bot, answers it and walks victims through the installation, assessing the breach as an effective social engineering lure because it "preys on the fear and concern" holders now have about their crypto security.
The Coldcard exploit stems from a March 2021 firmware build that drew wallet seeds from a software fallback instead of the device's hardware random number generator, leaving private keys guessable. Galaxy Research has confirmed three waves of thefts since July 30 and puts high-confidence losses at 1,596 BTC, above $100 million. Including a fourth wave it suspects but has not confirmed with victims, it said the total could reach $130 million. The firm's Head of Research Alex Thorn said Tuesday that at least 15 separate attackers are now exploiting the flaw, noting that every wave but the first targets Coldcard users specifically.
Small Bitcoin holders moved coins on July 31 at a rate not seen since the collapse of FTX, according to CryptoQuant, as news spread that Coldcard hardware wallets had been generating guessable keys for five years. Transfers of less than 1 BTC totaled 39,600 BTC (around $2.5 billion) that day, the firm's Head of Research Julio Moreno tweeted. The last comparable figure was 39,900 BTC on November 16, 2022, days after FTX failed.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.