Skip to main content
AVOID.NET

Coldcard Fake Hardware Audit Phishing Campaign

avoid.net/coldcard-fake-hardware-audit-phishing-campaign0/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·MMmftZ…pk1F

Summary

In early August 2026, threat actors launched a coordinated social engineering campaign targeting Coldcard hardware wallet owners by spoofing Coinkite communications and directing victims to a cloned website bearing a fraudulent 'Start Hardware Audit' button. Clicking the button delivered a GitHub-hosted batch file that silently installed ScreenConnect remote-access software, granting attackers full control of the victim's machine. The campaign was documented by security firm Proofpoint and was timed to exploit the widespread panic triggered by the July 31, 2026 disclosure of a genuine Coldcard firmware RNG vulnerability that had already resulted in losses exceeding $88 million in Bitcoin.

Connected Entities

4 entities · 60 linked investigations
Organizations
Trezor57Coldcard Fake Hardware Audit Phishing Campaign
Tokens
CoinkiteBitcoin62
Relationships
  • Coldcard Fake Hardware Audit Phishing Campaignmentioned withBitcoin(65%)
  • Coldcard Fake Hardware Audit Phishing Campaignmentioned withCoinkite(70%)
  • Coldcard Fake Hardware Audit Phishing Campaignmentioned withTrezor(70%)
  • Coinkitementioned withBitcoin(70%)
  • Coinkitementioned withTrezor(60%)
  • Trezormentioned withBitcoin(65%)

Connected Through

3 shared actors · 503 investigations

Distinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.

Have evidence about Coldcard Fake Hardware Audit Phishing Campaign?

Timeline(8 events)

March 2021

Coldcard firmware version 4.0.0 shipped with a coding error that routed seed generation to a deterministic software PRNG (Yasmarang) instead of the STM32 hardware RNG, reducing effective entropy to approximately 40 bits on Mk3 devices.

Block Engineering Blog / CoinDesk

30 July 2026

Block and independent researchers identified active exploitation of the Coldcard firmware RNG flaw. Coinkite published a preliminary vulnerability disclosure. An attacker drained 594 BTC ($38 million) from approximately 500 single-signature wallets in a 25-minute window.

CoinDesk / Block Engineering Blog

31 July 2026

Coinkite released emergency patched firmware (4.2.0+ for Mk3; 5.6.0+ for Mk4/Mk5; 1.5.0Q+ for Q) and advised all users on affected firmware versions to generate new seeds and migrate funds. Coinkite confirmed the vulnerability in a formal blog announcement.

The Hacker News / Bitcoin Magazine

August 2026

Galaxy Research tracked two additional waves of on-chain exploitation bringing total losses to 1,367 BTC (approximately $88.6 million) across 4,585 victim addresses, with at least 15 separate attackers identified.

Decrypt / Infosecurity Magazine

2 August 2026

Coinkite dispatched security advisory emails to all reachable customer addresses using its store and newsletter subscription systems, reaching addresses retained from purchases beginning in 2019. This prompted public criticism over data retention practices inconsistent with prior company statements.

Bitcoin.com News / CryptoNews.net

3 August 2026

Proofpoint documented the fake hardware audit phishing campaign, reporting that attackers had launched spoofed Coinkite emails directing victims to a cloned Coldcard website where a 'Start Hardware Audit' button delivered a GitHub-hosted batch file installing ScreenConnect remote-access software. A live human chat operator was observed guiding victims through the process.

Decrypt / Crypto Economy

4 August 2026

Trezor issued an urgent public phishing warning citing the surge in scam activity exploiting the Coldcard incident, advising users never to share recovery seeds and to verify all communications through official channels. Foundation issued a parallel warning about impersonation emails steering users to malicious downloads.

CryptoNews.net / BitcoinWorld / Decrypt

4 August 2026

Galaxy Research estimated potential losses could reach 2,055 BTC ($130 million) as a suspected fourth exploitation wave was under investigation. The Coldcard exploit and secondary phishing campaign together represented one of the largest self-custody security incidents in Bitcoin's history.

Decrypt / CryptoTimes
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 19 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/4/2026, 11:14:16 PM

last updated: 8/26/2026, 9:04:16 AM

3 views

avoid.net — verified advice for a post-truth world