Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M
Fake "coordinated hardware audit" emails are steering holders to a cloned Coldcard site that installs remote-access software.
Hardware wallet manufacturers have issued urgent warnings following a sophisticated phishing campaign targeting Coldcard users, with reported losses approaching $130 million. The attack involves fraudulent emails impersonating official communications, falsely claiming recipients must participate in a "coordinated hardware audit." Victims who follow the instructions are redirected to a cloned Coldcard website, where remote-access software is installed on their devices, enabling attackers to compromise private keys and drain funds.
The campaign represents a notable escalation in social engineering tactics directed at hardware wallet holders, a demographic historically considered among the most security-conscious in the cryptocurrency space. Hardware wallets are physical devices designed to keep private keys offline and protected from internet-based threats. However, this attack bypasses the device itself by targeting the user's computer, exploiting trust in official-sounding institutional language to lower suspicion.
The incident carries broader implications for the self-custody sector, which has seen growing adoption following high-profile exchange collapses in recent years. Security researchers note that attackers are increasingly crafting campaigns specifically tailored to hardware wallet users, recognizing that these individuals often hold significant crypto holdings. Industry observers warn that no hardware security solution can protect against users being deceived into installing malicious software.
Users are advised to verify all wallet-related communications directly through official manufacturer websites, avoid clicking links in unsolicited emails, and never install software prompted by unverified audit requests. Further developments in the investigation are expected in the coming days.
Source: Decrypt