A Phishing Campaign Exploits COLDCARD Vulnerability, Installs Remote Access Tool
A malicious phishing campaign is currently targeting users of the COLDCARD wallet, a popular hardware cold storage device used for secure cryptocurrency storage. The attackers are exploiting fears surrounding a recent vulnerability in the COLDCARD device, which was linked to an estimated $88.6 million Bitcoin theft. By impersonating COLDCARD and claiming that a security audit is underway, the attackers are tricking users into installing a remote access tool on their devices.
The phishing campaign uses emails sent from compliance@coldcardteamnews.com with the subject “Hardware audit now available.” The messages claim that recent findings require COLDCARD to verify the integrity of its hardware across all revisions and request user participation in the process. However, the emails are actually a ruse designed to lure victims into downloading and installing a malicious tool.
Upon clicking on the “Access the Audit Tool” button, users are directed to an allegedly secure website called coldcardcompliance.com. The site appears to be legitimate, with a live customer service chat feature that allows attackers to respond to concerns and pressure hesitant victims into proceeding with the installation. In conversations shared by Proofpoint, operators handling the chats ask users about their operating system and instruct them to run the downloaded tool.
The malicious tool is actually a batch file named Coldcard_Diagnostic_Tool.bat, which downloads two Base64-encoded files from a GitHub account. When launched, the script pretends to perform a diagnostic check on the device but secretly checks for administrator privileges. If found, it uses PowerShell to relaunch itself with elevated permissions and stores the embedded files in a temporary directory.
The files are then decoded using Windows certutil, and the setup.msi file is installed, which actually installs ConnectWise ScreenConnect, a remote management tool that gives the attackers remote access to the device. The docusign.exe file, a legitimate signed executable, acts as a decoy during the attack by displaying an “Installation Complete” message.
Once connected through ScreenConnect, the attackers can remotely access the computer, steal data or cryptocurrency, or install additional malware. Proofpoint warns that this access could also be used to deploy ransomware. The attackers are likely using real people to handle the customer service chats, allowing them to respond to concerns and pressure victims into proceeding with the installation.
This phishing campaign serves as a stark reminder of the importance of remaining vigilant in the face of emerging threats. With 54% of successful attacks going undetected by security teams, it’s crucial for users to stay informed and take proactive steps to protect themselves.
To avoid falling victim to this type of attack, test every layer of your security before attackers do. Regularly review your system logs, update your software, and use threat intelligence tools to detect suspicious activity. By taking these steps, you can significantly reduce the risk of a successful breach.
Source: Bleeping Computer — 2026-08-05