Top StoriesBearish
83
BTC

Trezor, Foundation Warn of Phishing Surge After $130M Coldcard Hack

Hardware wallet makers Trezor and Foundation warned of a phishing surge exploiting fears from the Coldcard firmware hack that drained nearly $130M in Bitcoin. Proofpoint found scammers impersonating Coldcard, using a fake hardware audit and human-staffed chat to install malware.

DecryptDecrypt Agent

Quick Take

1

Phishing campaigns target Coldcard users with fake 'hardware audit' and malware.

2

Coldcard exploit losses top $130M; at least 15 attackers are exploiting the flaw.

3

Trezor and Foundation warn users: never share recovery phrases or install software from unverified sources.

4

Galaxy Research urges victims to move funds to new seeds or custodians immediately.

Market Impact Analysis

Bearish

Security breach erodes trust in hardware wallets and could prompt panic selling among affected users, adding sell pressure on BTC.

Timeframeshort

Speculation Analysis

Factuality90/100
RumorsVerified
Speculation Trigger80/100
MinimalExtreme FOMO

Key Takeaways

  • Phishing campaigns target Coldcard users with a fake “hardware audit,” delivering remote-access malware.
  • The Coldcard exploit has led to over $130 million in Bitcoin theft, with at least 15 attackers active.
  • Trezor and Foundation warn never to share recovery phrases or install software from unverified sources.
  • Galaxy Research urges victims to move funds to new seeds or custodians immediately.
Total Losses $130M in Bitcoin stolen
BTC Stolen 1,596 BTC since exploit began
Active Attackers 15+ exploiting the flaw
Phishing Lure Fake audit w/ human chat installs remote-access malware

What Happened

Phishing attacks are surging against hardware wallet users, as scammers exploit the fallout from a Coldcard firmware vulnerability that has already drained nearly $130 million in Bitcoin. Leading hardware wallet makers Trezor and Foundation have issued warnings, reporting a rise in phishing attempts aimed at stealing recovery phrases and pushing malicious downloads.

Cybersecurity firm Proofpoint identified a sophisticated phishing campaign specifically targeting Coldcard owners. Emails from a spoofed Coldcard address direct users to complete a “hardware audit” — a theme that mirrors the actual security incident. The cloned site features a “Start Hardware Audit” button that downloads a batch file, installing remote-access tool ScreenConnect. A live operator on the fake site’s chat walks victims through the installation, amplifying the social engineering effectiveness.

The Numbers

The Coldcard exploit has resulted in the theft of 1,596 BTC, valued near $130 million. At least 15 separate attackers are actively targeting vulnerable wallets. The phishing campaign uses voice-enabled human chat support to dupe users, making it one of the more advanced crypto phishing operations seen recently. The root cause is a firmware bug dating back to March 2021, where seed generation relied on a software fallback instead of the hardware random number generator.

Why It Happened

The phishing wave directly capitalizes on the fear and confusion generated by the Coldcard exploit. With significant funds at risk, users are desperate to secure their assets, making them more susceptible to fraudulent “security audits” and urgent warnings. The original firmware flaw—a software-based seed generation—made private keys guessable, providing a genuine crisis for phishers to mimic. The attackers are leveraging a trusted brand and a known vulnerability to bypass users’ defenses.

Broader Impact

The incident shakes confidence in hardware wallets, once considered the gold standard for crypto security. A breach of this magnitude could accelerate regulatory scrutiny and force wallet manufacturers to overhaul firmware update practices and user education. As fear spreads, some users may panic-sell Bitcoin, adding short-term bearish pressure on the market.

What to Watch Next

  • Expect further phishing waves as attackers refine social engineering tactics—watch for similar campaigns targeting other wallet brands.
  • Monitor whether Coldcard issues a firmware fix or patch, and how quickly users migrate to new seeds or custodial solutions as advised by Galaxy Research.
  • Keep an eye on Bitcoin trading volumes and volatility, as panic-driven sell-offs could emerge from affected holders.

Source: Decrypt

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Decrypt
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

Top StoriesBearish
86

Coldcard Users Must Move Bitcoin Now: $114M Exploit Still Active

Coldcard, a major Bitcoin cold wallet maker, warns users to immediately move their funds due to an ongoing exploit that has already caused $114 million in losses. Specific models and firmware versions remain vulnerable, highlighting critical security risks for hardware wallet users.

BTC
95% confidence
Aug 4, 2026, 12:00 PM UTC · CoinDesk
Coldcard Hack Sparks Phishing Surge, $130M Stolen | Bytewit