← Coldcard Fake Hardware Audit Phishing Campaign1 decision on this page
Audit log
Every state-changing event for Coldcard Fake Hardware Audit Phishing Campaign: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-04 23:14:27ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
Dj6hjJhctixA…so1uXRjCsha256 → base58
verifying row…canonical bytes (23704 B) ▸
{"actor":"system:backfill","investigation_id":"74c733a8-1c2a-4192-a238-a140c772db61","kind":"publish","page_slug":"coldcard-fake-hardware-audit-phishing-campaign","published_at":"2026-08-04T23:14:27.286Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Coldcard Fake Hardware Audit Phishing Campaign","sections":[{"content":"Security firm Proofpoint documented a phishing campaign targeting Coldcard hardware wallet holders that emerged in early August 2026. The operation was designed to exploit the fear and urgency created by the genuine Coldcard firmware vulnerability disclosed on July 30–31, 2026. Attackers sent emails spoofing official Coinkite communications, inviting recipients to complete a 'coordinated hardware audit' — language deliberately borrowed from the real incident to increase credibility. Proofpoint assessed the campaign as an effective social engineering lure because it 'preys on the fear and concern' that holders had developed following the firmware disclosure. Trezor and Foundation, two competing hardware wallet manufacturers, also issued independent public warnings about the surge in phishing attempts trading on the Coldcard incident, with Foundation reporting it was seeing emails impersonating the company and steering users toward fake sites and malicious downloads.","heading":"Campaign Overview and Attribution","severity":"critical","sources":[{"credibility":2,"name":"Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M — Decrypt","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"Hardware Wallet Providers Flag Dangerous Phishing Campaign — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"},{"credibility":2,"name":"Trezor Issues Urgent Phishing Warning Amid Coldcard Security Incident — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33244901/"}]},{"content":"The initial lure was delivered via email from an address spoofing official Coldcard or Coinkite communications. The message framed an urgent call to action: recipients were invited to participate in a 'coordinated hardware audit' in response to the disclosed firmware flaw, mirroring language from legitimate security advisories. The email directed victims to a cloned version of the Coldcard website that visually replicated the official site. The fake site prominently displayed a 'Start Hardware Audit' button as the primary call to action. Coinkite's own legitimate security outreach — which used retained customer email addresses from purchases dating back to 2019 to notify affected users — created an environment in which recipients were already expecting official email communications, significantly lowering the threshold of suspicion for the fraudulent messages.","heading":"Attack Vector: Spoofed Email and Cloned Website","severity":"critical","sources":[{"credibility":2,"name":"Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M — Decrypt","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"Hardware Wallet Providers Flag Dangerous Phishing Campaign — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"},{"credibility":2,"name":"Coinkite Under Fire for Retaining Customer Emails After $88M Coldcard Hack — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"},{"credibility":2,"name":"Coinkite Criticized for Retaining Customer Emails — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33237339/"}]},{"content":"When a victim clicked the fake 'Start Hardware Audit' button on the cloned site, the action triggered a download of a batch file hosted on GitHub. Upon execution, the batch script silently installed ScreenConnect, a commercially available legitimate remote-access tool. Proofpoint noted that once ScreenConnect was installed, attackers gained persistent remote access to the victim's machine, opening pathways to financial theft, credential harvesting, and the deployment of follow-on malware including ransomware. The use of a legitimate, signed remote-access tool rather than custom malware was noted as a technique to evade endpoint detection products that do not flag commercially available remote administration software. Hosting the delivery payload on GitHub similarly abused a trusted platform's reputation to avoid URL-level blocking.","heading":"Malware Delivery: GitHub-Hosted Batch File and ScreenConnect","severity":"critical","sources":[{"credibility":2,"name":"Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M — Decrypt","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"Hardware Wallet Providers Flag Dangerous Phishing Campaign — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"},{"credibility":3,"name":"Security Check-in Quick Hits: Coldcard $70M Bitcoin Drain — Rod Trent / Substack","type":"other","url":"https://rodtrent.substack.com/p/security-check-in-quick-hits-coldcard"}]},{"content":"A feature that distinguished this campaign from automated phishing operations was the deployment of a live human chat operator on the fake Coldcard site. Rather than a scripted chatbot, a real person answered the customer service chat interface and guided anxious victims through the process of downloading and executing the batch file. Proofpoint assessed that this human-operated social engineering element significantly increased the campaign's conversion rate compared to fully automated attempts, because it provided reassurance and addressed in-real-time doubts that a target might have about the legitimacy of the process. The campaign specifically targeted users who had not yet lost funds from the underlying firmware exploit and who were actively seeking remediation guidance — a psychographic profile especially susceptible to authoritative-sounding live assistance.","heading":"Social Engineering Sophistication: Live Human Chat Operator","severity":"critical","sources":[{"credibility":2,"name":"Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M — Decrypt","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"Hardware Wallet Providers Flag Dangerous Phishing Campaign — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"}]},{"content":"This phishing campaign is distinct from the underlying technical exploit that it piggybacks on. The firmware exploit involved a March 2021 coding error in Coldcard firmware that caused seed generation to route through a deterministic software pseudorandom number generator (the Yasmarang PRNG) instead of the device's STM32 hardware RNG. This reduced effective entropy to approximately 40 bits on Mk3 devices, making it mathematically feasible for attackers to reconstruct private keys offline without physical access to the device. Block's security team published a detailed technical advisory confirming the vulnerability on July 30, 2026. By August 2, 2026, Galaxy Research had tracked at least three waves of exploitation totaling 1,367 BTC (approximately $88.6 million) drained from 4,585 addresses, with potential losses rising toward 2,055 BTC ($130 million) as additional waves were suspected. The phishing campaign targeted a separate, non-overlapping population: users who had not yet been drained and were seeking remediation guidance, rather than users whose funds had already been swept by the on-chain exploit. Victims of the phishing campaign faced a different threat model — remote machine compromise and follow-on financial theft — rather than the direct seed reconstruction used in the firmware exploit.","heading":"Relationship to the Underlying Coldcard Firmware RNG Exploit","severity":"high","sources":[{"credibility":1,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":1,"name":"Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":2,"name":"Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M — Decrypt","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"}]},{"content":"A contributing factor to the phishing campaign's plausibility was Coinkite's decision to send security advisory emails to all customer email addresses it could reach, including addresses retained from purchases dating back to 2019. This was controversial because Coinkite CEO Rodolfo Novak had previously stated that customer data was erased 90 days after purchase and that the company offered anonymous purchase options. Critics noted that the existence of a retained customer email list — now confirmed by Coinkite's own mass mailing — created an expanded attack surface for threat actors, who could plausibly target the same recipient population that was already expecting official communications from Coinkite. Coinkite stated it retained email addresses to allow customers to log in and verify that other data had been deleted, and justified the outreach as crisis communication. The controversy added to the overall confusion experienced by affected users during the disclosure window.","heading":"Coinkite Email Retention Controversy and Phishing Attack Surface","severity":"medium","sources":[{"credibility":2,"name":"Coinkite Under Fire for Retaining Customer Emails After $88M Coldcard Hack — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"},{"credibility":2,"name":"Coinkite Criticized for Retaining Customer Emails — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33237339/"},{"credibility":2,"name":"Coldcard Sends Security Announcement Emails to All Reachable Users — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/coldcard-sends-security-announcement-emails-to-all-reachable-users"}]},{"content":"In response to the surge in opportunistic phishing activity following the Coldcard firmware disclosure, multiple hardware wallet manufacturers issued public safety advisories. Trezor issued an urgent public alert on approximately August 4, 2026 warning users against sharing recovery seeds with anyone, emphasizing that seeds should only be entered directly on a hardware device during wallet restoration, and noting that it never requests seed phrases under any circumstances. Foundation similarly reported seeing emails impersonating the company and directing recipients to fake sites and malicious downloads, and reiterated that it will never ask for a recovery phrase or instruct users to install software to secure a hardware wallet. Both companies warned specifically against unsolicited migration instructions or urgent warnings delivered via email, SMS, or phone calls.","heading":"Broader Hardware Wallet Industry Warnings","severity":"medium","sources":[{"credibility":2,"name":"Trezor Issues Urgent Phishing Warning Amid Coldcard Security Incident — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33244901/"},{"credibility":2,"name":"Trezor Issues Urgent Phishing Warning Amid Coldcard Security Incident — BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/trezor-phishing-warning-coldcard-security-incident/"},{"credibility":2,"name":"Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M — Decrypt","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"}]},{"content":"Based on published reporting, the following indicators and guidance apply to this campaign. The phishing email lure uses language around a 'coordinated hardware audit' and invites the recipient to click a link to a site that is not coldcard.com. Coinkite has stated it will never ask for users' PIN codes, seed phrases, or BIP-39 passphrases, nor will it request users to sign any unverified PSBT transactions. Firmware should only be downloaded from coldcard.com/downloads. The fake site is reported to have hosted a live chat interface staffed by a human operator guiding victims through installation — legitimate hardware wallet manufacturers do not use chat to guide firmware or audit procedures that require downloading and executing batch files. The delivery mechanism — a GitHub-hosted batch file installing ScreenConnect — means that any prompt to execute a downloaded script as part of a wallet security procedure should be treated as a strong indicator of compromise. No specific phishing domain names or GitHub repository URLs were published in available reporting at the time of this investigation.","heading":"User Guidance and Indicators of Compromise","severity":"high","sources":[{"credibility":2,"name":"Hardware Wallet Providers Flag Dangerous Phishing Campaign — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"},{"credibility":2,"name":"Coldcard Sends Security Announcement Emails to All Reachable Users — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/coldcard-sends-security-announcement-emails-to-all-reachable-users"},{"credibility":2,"name":"COLDCARD Vulnerability: What Owners Need to Know — Bitcoin Well","type":"news_article","url":"https://bitcoinwell.com/coldcard-vulnerability"}]}],"sources_used":[{"credibility":2,"name":"Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M — Decrypt","type":"news_article","url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"credibility":2,"name":"Hardware Wallet Providers Flag Dangerous Phishing Campaign — Crypto Economy","type":"news_article","url":"https://crypto-economy.com/hardware-wallet-phishing-campaign-warning/"},{"credibility":2,"name":"Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes — The Hacker News","type":"news_article","url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"credibility":3,"name":"Security Check-in Quick Hits: Coldcard $70M Bitcoin Drain — Rod Trent / Substack","type":"other","url":"https://rodtrent.substack.com/p/security-check-in-quick-hits-coldcard"},{"credibility":1,"name":"Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware — Block Engineering Blog","type":"research","url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"credibility":1,"name":"Major Bitcoin Wallet Flaw Drains 594 BTC in 25-Minute Sweep — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"credibility":2,"name":"Coldcard Hardware Wallet Hacked via Firmware Bug That Bypassed RNG for Five Years — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/322392/20260731/coldcard-hardware-wallet-hacked-via-firmware-bug-that-bypassed-rng-five-years.htm"},{"credibility":2,"name":"Coldcard Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft — CyberSecurityNews","type":"news_article","url":"https://cybersecuritynews.com/coldcard-hardware-wallet-rng-flaw-bitcoin-theft/"},{"credibility":2,"name":"Hackers Exploit Coldcard Firmware Flaw, Stealing $89 Million in Bitcoin — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/coldcard-firmware-flaw-bitcoin-hack-89-million/"},{"credibility":2,"name":"Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach — Bitcoin Magazine","type":"news_article","url":"https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack"},{"credibility":2,"name":"Coinkite Under Fire for Retaining Customer Emails After $88M Coldcard Hack — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"},{"credibility":2,"name":"Coinkite Criticized for Retaining Customer Emails — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33237339/"},{"credibility":2,"name":"Coldcard Sends Security Announcement Emails to All Reachable Users — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/coldcard-sends-security-announcement-emails-to-all-reachable-users"},{"credibility":2,"name":"Trezor Issues Urgent Phishing Warning Amid Coldcard Security Incident — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33244901/"},{"credibility":2,"name":"Trezor Issues Urgent Phishing Warning Amid Coldcard Security Incident — BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/trezor-phishing-warning-coldcard-security-incident/"},{"credibility":1,"name":"Coldcard Users Lose $89M After Bitcoin Wallet Is Hacked — Infosecurity Magazine","type":"news_article","url":"https://www.infosecurity-magazine.com/news/coldcard-users-lose-89m-bitcoin/"},{"credibility":2,"name":"COLDCARD Vulnerability: What Owners Need to Know — Bitcoin Well","type":"news_article","url":"https://bitcoinwell.com/coldcard-vulnerability"},{"credibility":2,"name":"A Five-Year-Old Coldcard Bug Let Hackers Guess Bitcoin Wallet Keys — Blockhead","type":"news_article","url":"https://www.blockhead.co/2026/08/03/coldcard-hardware-wallets-shipped-with-broken-randomness-for-five-years-coinkite-confirms/"},{"credibility":2,"name":"Nothing Is 100% Safe in Crypto: Bitcoin's Coldcard Exploit and Growing Security Crisis — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/04/nothing-is-100-safe-in-crypto-bitcoins-coldcard-exploit-and-growing-security-crisis/"},{"credibility":1,"name":"Coldcard Exploit Reignites Bitcoin Self-Custody Debate After $38 Million Theft — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/31/coldcard-s-usd38-million-so-far-exploit-shakes-faith-in-self-custody-may-push-investors-to-etfs"}],"summary":"In early August 2026, threat actors launched a coordinated social engineering campaign targeting Coldcard hardware wallet owners by spoofing Coinkite communications and directing victims to a cloned website bearing a fraudulent 'Start Hardware Audit' button. Clicking the button delivered a GitHub-hosted batch file that silently installed ScreenConnect remote-access software, granting attackers full control of the victim's machine. The campaign was documented by security firm Proofpoint and was timed to exploit the widespread panic triggered by the July 31, 2026 disclosure of a genuine Coldcard firmware RNG vulnerability that had already resulted in losses exceeding $88 million in Bitcoin.","timeline":[{"date":"2021-03-01","event":"Coldcard firmware version 4.0.0 shipped with a coding error that routed seed generation to a deterministic software PRNG (Yasmarang) instead of the STM32 hardware RNG, reducing effective entropy to approximately 40 bits on Mk3 devices.","source":"Block Engineering Blog / CoinDesk","source_url":"https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware"},{"date":"2026-07-30","event":"Block and independent researchers identified active exploitation of the Coldcard firmware RNG flaw. Coinkite published a preliminary vulnerability disclosure. An attacker drained 594 BTC ($38 million) from approximately 500 single-signature wallets in a 25-minute window.","source":"CoinDesk / Block Engineering Blog","source_url":"https://www.coindesk.com/tech/2026/07/31/major-bitcoin-wallet-flaw-drains-594-btc-in-25-minute-sweep"},{"date":"2026-07-31","event":"Coinkite released emergency patched firmware (4.2.0+ for Mk3; 5.6.0+ for Mk4/Mk5; 1.5.0Q+ for Q) and advised all users on affected firmware versions to generate new seeds and migrate funds. Coinkite confirmed the vulnerability in a formal blog announcement.","source":"The Hacker News / Bitcoin Magazine","source_url":"https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html"},{"date":"2026-08-01","event":"Galaxy Research tracked two additional waves of on-chain exploitation bringing total losses to 1,367 BTC (approximately $88.6 million) across 4,585 victim addresses, with at least 15 separate attackers identified.","source":"Decrypt / Infosecurity Magazine","source_url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"date":"2026-08-02","event":"Coinkite dispatched security advisory emails to all reachable customer addresses using its store and newsletter subscription systems, reaching addresses retained from purchases beginning in 2019. This prompted public criticism over data retention practices inconsistent with prior company statements.","source":"Bitcoin.com News / CryptoNews.net","source_url":"https://news.bitcoin.com/security/coinkite-under-fire-for-retaining-customer-emails-after-88m-coldcard-hack/"},{"date":"2026-08-03","event":"Proofpoint documented the fake hardware audit phishing campaign, reporting that attackers had launched spoofed Coinkite emails directing victims to a cloned Coldcard website where a 'Start Hardware Audit' button delivered a GitHub-hosted batch file installing ScreenConnect remote-access software. A live human chat operator was observed guiding victims through the process.","source":"Decrypt / Crypto Economy","source_url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"},{"date":"2026-08-04","event":"Trezor issued an urgent public phishing warning citing the surge in scam activity exploiting the Coldcard incident, advising users never to share recovery seeds and to verify all communications through official channels. Foundation issued a parallel warning about impersonation emails steering users to malicious downloads.","source":"CryptoNews.net / BitcoinWorld / Decrypt","source_url":"https://cryptonews.net/news/security/33244901/"},{"date":"2026-08-04","event":"Galaxy Research estimated potential losses could reach 2,055 BTC ($130 million) as a suspected fourth exploitation wave was under investigation. The Coldcard exploit and secondary phishing campaign together represented one of the largest self-custody security incidents in Bitcoin's history.","source":"Decrypt / CryptoTimes","source_url":"https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8e2f96e0-df20-4966-bc9d-6eb1ad641f1d
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.