Bullish

Coldcard Exploit Losses May Hit $130M as Phishing Attacks Surge

2026-08-04 18:54

Hardware wallet makers warn of rising phishing scams following Coldcard firmware flaw disclosure. Confirmed thefts exceed $100M in BTC, with potential total losses reaching $130M.

Woofun AI reports that Trezor and Foundation have issued warnings regarding a surge in phishing campaigns targeting hardware wallet users after the exposure of a Coldcard firmware vulnerability. Attackers are soliciting recovery phrases and deceiving victims into installing malware. Proofpoint identified fraudulent emails impersonating Coldcard that direct users to a cloned site for a "hardware audit", leading to the installation of the ScreenConnect remote access tool via a GitHub-hosted batch file. The fake site includes a live chat feature where operatives guide victims through the setup, enabling attackers to steal funds or deploy ransomware.

Galaxy Research has verified three distinct theft events since July 30, resulting in confirmed losses of 1,596 BTC, valued at over $100 million. If a fourth unconfirmed incident is included, the aggregate financial damage could amount to $130 million.

WOOFUN AI

Impact Assessment · Quick Read

The escalation of sophisticated social engineering attacks following a technical vulnerability highlights the persistent risk to self-custody solutions. With losses potentially exceeding $130M in BTC, this event may accelerate industry scrutiny on firmware security standards and user education protocols. The use of live support in phishing campaigns suggests an evolution in attack complexity, which could impact user trust in hardware wallets generally.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions