← Back to Crime & Security

Phishing Campaign Targets Coldcard Users via Fake Security Alerts

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A sophisticated phishing campaign targeting users of the COLDCARD cryptocurrency hardware wallet has emerged, exploiting fears over a purported security vulnerability to install remote access software on victims' devices. The attack, identified by cybersecurity firm Proofpoint, utilizes deceptive emails and fraudulent websites designed to mimic official audit notifications from the wallet manufacturer.

The campaign began circulating globally in early August 2026. Threat actors sent unsolicited messages claiming that a critical flaw had been discovered in COLDCARD firmware, urging recipients to immediately download an emergency patch or participate in a mandatory security audit. These communications directed users to counterfeit domains closely resembling the legitimate COLDCARD website.

Once on the fraudulent sites, victims were prompted to install ScreenConnect, a remote desktop software tool often used by IT support teams but repurposed here for malicious ends. The attackers framed the installation as necessary to verify wallet integrity or apply security updates. Upon execution of the downloaded file, threat actors gained unauthorized control over the infected computers.

The primary objective of the intrusion is twofold: direct theft of cryptocurrency assets and data exfiltration leading to further compromise. By establishing a remote connection through ScreenConnect, attackers can view sensitive files, access stored credentials, and monitor user activity in real time. Security analysts warn that this level of control also facilitates the deployment of ransomware or other malware payloads onto compromised networks.

Proofpoint noted that the campaign's effectiveness relies heavily on social engineering tactics rather than technical exploits within the wallet itself. The attackers capitalized on the high value of digital assets held by COLDCARD users and their heightened sensitivity to security news. By fabricating a non-existent vulnerability, the group created a sense of urgency that bypassed standard caution.

The attack highlights the evolving nature of threats against cryptocurrency infrastructure, where human error remains a significant vector for breach despite robust hardware protections. While no specific number of confirmed victims has been released, the scope appears to be international given the distribution methods used.

Security experts advise users who received suspicious emails regarding wallet audits or firmware updates to verify information directly through official channels before taking any action. The incident raises questions about how quickly such campaigns can spread within niche financial communities and whether similar tactics will target other hardware wallet manufacturers in the coming months.

Discussion

0 / 2000