Coldcard Fake Hardware Audit Phishing Campaign
Summary
In early August 2026, threat actors launched a coordinated social engineering campaign targeting Coldcard hardware wallet owners by spoofing Coinkite communications and directing victims to a cloned website bearing a fraudulent 'Start Hardware Audit' button. Clicking the button delivered a GitHub-hosted batch file that silently installed ScreenConnect remote-access software, granting attackers full control of the victim's machine. The campaign was documented by security firm Proofpoint and was timed to exploit the widespread panic triggered by the July 31, 2026 disclosure of a genuine Coldcard firmware RNG vulnerability that had already resulted in losses exceeding $88 million in Bitcoin.
Connected Entities
1 entitiesTimeline(8 events)
2021-03-01
Coldcard firmware version 4.0.0 shipped with a coding error that routed seed generation to a deterministic software PRNG (Yasmarang) instead of the STM32 hardware RNG, reducing effective entropy to approximately 40 bits on Mk3 devices.
Block Engineering Blog / CoinDesk2026-07-30
Block and independent researchers identified active exploitation of the Coldcard firmware RNG flaw. Coinkite published a preliminary vulnerability disclosure. An attacker drained 594 BTC ($38 million) from approximately 500 single-signature wallets in a 25-minute window.
CoinDesk / Block Engineering Blog2026-07-31
Coinkite released emergency patched firmware (4.2.0+ for Mk3; 5.6.0+ for Mk4/Mk5; 1.5.0Q+ for Q) and advised all users on affected firmware versions to generate new seeds and migrate funds. Coinkite confirmed the vulnerability in a formal blog announcement.
The Hacker News / Bitcoin Magazine2026-08-01
Galaxy Research tracked two additional waves of on-chain exploitation bringing total losses to 1,367 BTC (approximately $88.6 million) across 4,585 victim addresses, with at least 15 separate attackers identified.
Decrypt / Infosecurity Magazine2026-08-02
Coinkite dispatched security advisory emails to all reachable customer addresses using its store and newsletter subscription systems, reaching addresses retained from purchases beginning in 2019. This prompted public criticism over data retention practices inconsistent with prior company statements.
Bitcoin.com News / CryptoNews.net2026-08-03
Proofpoint documented the fake hardware audit phishing campaign, reporting that attackers had launched spoofed Coinkite emails directing victims to a cloned Coldcard website where a 'Start Hardware Audit' button delivered a GitHub-hosted batch file installing ScreenConnect remote-access software. A live human chat operator was observed guiding victims through the process.
Decrypt / Crypto Economy2026-08-04
Trezor issued an urgent public phishing warning citing the surge in scam activity exploiting the Coldcard incident, advising users never to share recovery seeds and to verify all communications through official channels. Foundation issued a parallel warning about impersonation emails steering users to malicious downloads.
CryptoNews.net / BitcoinWorld / Decrypt2026-08-04
Galaxy Research estimated potential losses could reach 2,055 BTC ($130 million) as a suspected fourth exploitation wave was under investigation. The Coldcard exploit and secondary phishing campaign together represented one of the largest self-custody security incidents in Bitcoin's history.
Decrypt / CryptoTimesDecision Log
- #1publish⛓ pending8/4/2026, 11:14:27 PMhash: Dj6hjJhctixAartsuGQTPMEYVJRCCsWgoXhoso1uXRjC
19 of 20 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/4/2026, 11:14:16 PM
last updated: 8/5/2026, 4:48:42 PM
avoid.net — verified advice for a post-truth world