August 04, 10:54

Coldcard Phishing Losses May Reach $130M After Firmware Vulnerability

Coldcard vulnerability-related losses may reach $130 million, hardware wallet manufacturers warn of increased phishing attacks

Odaily

Key Point

Trezor and Foundation warned that phishing attempts targeting hardware wallet holders increased after disclosure of a Coldcard firmware vulnerability. Proofpoint detected phishing emails impersonating Coldcard and inviting users to complete a "hardware audit" through a cloned website. Users who click the links download a batch file hosted on GitHub that installs ScreenConnect. Proofpoint said the fraudulent website also includes a customer service chat window where real people guide victims through installation. Galaxy Research confirmed three theft rounds since July 30 with high-confidence losses of 1,596 BTC exceeding $100 million, and total losses could reach $130 million if a fourth unconfirmed round is included.

Why it matters: Security incidents can weaken trust in self-custody tools when attackers use credible wallet-brand impersonation to reach users directly.

Market Sentiment

Bearish, Stress-on, Event-driven, Fear.

Reason: Galaxy Research confirmed high-confidence losses of 1,596 BTC exceeding $100 million, which supports a negative security-risk read.

Similar Past Cases

In June 2023, Atomic Wallet users reported unauthorized withdrawals, and ZachXBT estimated more than $35 million was stolen early in the incident. Atomic Wallet said fewer than 1% of monthly active users were affected, according to Fortune. (Fortune) The key difference is that the Coldcard-linked case involves hardware wallet phishing after a firmware vulnerability disclosure, while the Atomic Wallet case centered on a software wallet compromise.

Ripple Effect

Seed phrase theft can turn isolated wallet losses into broader self-custody trust risk if fake audit flows spread across vendors. If new victim confirmations expand the loss estimate, then hardware wallet users may become more cautious across self-custody channels.

Opportunities & Risks

Opportunities: If hardware wallet makers publish verified remediation steps, then using only official communication channels is a safer way to restore confidence before moving funds.

Risks: If cloned audit sites or ScreenConnect installers keep appearing, then avoiding recovery phrase entry and remote-access downloads limits direct wallet-drain risk.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.