Cyber Attackers Exploit COLDCARD Wallet Vulnerability with Phishing Scam
A sophisticated phishing campaign is targeting users of the COLDCARD cold storage wallet, exploiting fears surrounding a recent vulnerability and suspected $88.6 million Bitcoin theft. The attackers are using emails impersonating COLDCARD to trick victims into installing remote access software, granting them unauthorized control over devices.
The phishing campaign comes after a reported attack on the COLDCARD wallet, which saw approximately 1,367 Bitcoins (valued at around $88.6 million) stolen from 4,585 addresses. The vulnerability is believed to be related to a random number generation flaw affecting multiple COLDCARD models and firmware versions.
The phishing emails are designed to appear legitimate, claiming that a security audit is underway across all hardware revisions of the COLDCARD device network. Recipients are directed to an alleged “Security Verification & Incident Reporting Tool” on a fake website called coldcardcompliance.com. The tool claims to be air-gapped and will not request users’ recovery seeds.
However, once victims click on the “Access the Audit Tool” button, they are redirected to a malicious download that installs remote access software. This software, named ConnectWise ScreenConnect, is used by attackers to gain unauthorized control over devices, allowing them to steal data or cryptocurrency, install additional malware, and potentially deploy ransomware.
What’s particularly concerning about this attack is the level of sophistication demonstrated by the attackers. The fake website includes a live “Customer Service” chat feature, which allows operators (believed to be real people) to respond to victims’ concerns and pressure them into proceeding with the installation of the remote access software.
The malicious batch file downloaded from the fake website contains two Base64-encoded files that are embedded directly in the script. When launched, the script checks for administrator privileges and launches a PowerShell prompt if necessary. It then installs the remote access software and deletes temporary directories, leaving no evidence of its presence.
This attack serves as a stark reminder of the importance of vigilance in the face of emerging threats. With the average organization experiencing 54% of successful attacks going undetected, it’s essential to test every layer of security before attackers do. This can be achieved through regular breach and attack simulation testing, which helps identify vulnerabilities and refine incident response strategies.
For COLDCARD wallet users, this means being cautious when receiving emails or notifications that claim to be from the company. Always verify the authenticity of such messages by contacting COLDCARD directly. Furthermore, never download software or click on links from unverified sources, as they may lead to malicious installations like the one described here.
Ultimately, this attack highlights the need for continued education and awareness among users about the tactics used by cyber attackers. By staying informed and vigilant, we can reduce the risk of falling victim to such scams and protect our digital assets from unauthorized access.
Source: Bleeping Computer — 2026-08-05