Phishing Surge Hits Hardware Wallet Owners After Coldcard Exploit
A recent surge in phishing attempts targets owners of hardware wallets after a Coldcard firmware exploit was disclosed. Trezor and Foundation, two manufacturers of hardware wallets, have reported an increase in phishing attempts since the disclosure.
The attacks aim to steal recovery phrases and push malicious downloads. Proofpoint identified a phishing campaign targeting Coldcard holders with a cloned site and 'Hardware Audit' that installs remote-access software. A person, rather than a bot, staffs the fake site's customer service chat and talks victims through the install.
Coldcard manufacturer Coinkite has issued patched firmware and advised affected users to move funds to newly generated seeds. Galaxy Research has confirmed three waves of thefts since July 30 and puts high-confidence losses at 1,596 BTC, above $100 million. Including a fourth wave it suspects but has not confirmed with victims, the total could reach $130 million.