Incident case file
Sign in to watchColdcard-Themed 'Hardware Wallet Audit' Phishing Campaign
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatAugust 3, 2026: Security firm Proofpoint (via its official @threatinsight account) documents an active phishing campaign that directly exploits public anxiety surrounding the concurrent, high-profile Coldcard hardware wallet vulnerability disclosure that was dominating Bitcoin security news the same week. The campaign sends phishing emails referencing a 'coordinated hardware audit,' directing recipients to a professionally cloned website. A prominent 'Start Hardware Audit' button on the fraudulent site triggers the download of a batch script file, hosted on GitHub, which installs the ScreenConnect remote access tool onto the victim's computer — granting the attacker full remote control of the machine rather than directly harvesting a seed phrase in the moment. Reports further indicate that attackers staff live chat support during the fraudulent 'audit' process using real human operators, substantially increasing the campaign's perceived legitimacy and likely success rate compared to a purely automated phishing flow. August 4, 2026: Both Trezor and Foundation, two prominent hardware wallet manufacturers unrelated to Coldcard, independently issue public warnings about a broader industry-wide resurgence in phishing activity capitalizing on the ongoing Coldcard news cycle, urging users across the entire hardware wallet ecosystem — not merely Coldcard device owners — to exercise significantly heightened caution regarding unsolicited 'security audit' outreach. August 5, 2026: BleepingComputer publishes detailed technical coverage of the ScreenConnect delivery mechanism and associated indicators of compromise, aiding defenders in identifying and blocking the campaign. As of the close of the reporting window, no specific financial loss figures, total victim counts, or attacker attribution have been publicly disclosed for this particular campaign — it remains characterized in ongoing coverage as an active and continuing threat rather than a closed, fully quantified incident.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)