← Radar

Incident case file

Sign in to watch

Coldcard-Themed 'Hardware Wallet Audit' Phishing Campaign

Incident date 2026-08-02Last updated Aug 14, 2026

1 views

Activewallet-agnostic phishingremote access trojan campaignPhishing / social engineering (RAT deployment)Cluster: COLD-PHISH-2026-08

Estimated loss

$0

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

25%

Facts and investigation

Ledger

Attacker

MISSING — not publicly disclosed.

Funds moved to

MISSING — not quantified. This campaign is designed to deliver a remote access trojan (ScreenConnect) to victim machines rather than to directly drain cryptocurrency funds in a single traceable transaction; the $0 amount_lost_usd field reflects the absence of a quantified figure, not a confirmed zero-impact outcome.

Linked

This campaign directly exploits the fear and confusion generated by the concurrent, but technically unrelated, Coldcard hardware wallet firmware RNG vulnerability (see cluster COLD-RNG-2026-08) to lure hardware wallet owners into engaging with it. Delivery mechanism: phishing emails referencing a 'coordinated hardware audit,' leading recipients to a cloned website featuring a prominent 'Start Hardware Audit' button that triggers download of a malicious batch file (hosted on GitHub) which install

Chronology

1 beat
  1. August 3, 2026: Security firm Proofpoint (via its official @threatinsight account) documents an active phishing campaign that directly exploits public anxiety surrounding the concurrent, high-profile Coldcard hardware wallet vulnerability disclosure that was dominating Bitcoin security news the same week. The campaign sends phishing emails referencing a 'coordinated hardware audit,' directing recipients to a professionally cloned website. A prominent 'Start Hardware Audit' button on the fraudulent site triggers the download of a batch script file, hosted on GitHub, which installs the ScreenConnect remote access tool onto the victim's computer — granting the attacker full remote control of the machine rather than directly harvesting a seed phrase in the moment. Reports further indicate that attackers staff live chat support during the fraudulent 'audit' process using real human operators, substantially increasing the campaign's perceived legitimacy and likely success rate compared to a purely automated phishing flow. August 4, 2026: Both Trezor and Foundation, two prominent hardware wallet manufacturers unrelated to Coldcard, independently issue public warnings about a broader industry-wide resurgence in phishing activity capitalizing on the ongoing Coldcard news cycle, urging users across the entire hardware wallet ecosystem — not merely Coldcard device owners — to exercise significantly heightened caution regarding unsolicited 'security audit' outreach. August 5, 2026: BleepingComputer publishes detailed technical coverage of the ScreenConnect delivery mechanism and associated indicators of compromise, aiding defenders in identifying and blocking the campaign. As of the close of the reporting window, no specific financial loss figures, total victim counts, or attacker attribution have been publicly disclosed for this particular campaign — it remains characterized in ongoing coverage as an active and continuing threat rather than a closed, fully quantified incident.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)