Coldcard Exploit Losses May Hit $130M as Phishing Attacks Surge
Hardware wallet makers warn of rising phishing scams following Coldcard firmware flaw disclosure. Confirmed thefts exceed $100M in BTC, with potential total losses reaching $130M.
Woofun AI reports that Trezor and Foundation have issued warnings regarding a surge in phishing campaigns targeting hardware wallet users after the exposure of a Coldcard firmware vulnerability. Attackers are soliciting recovery phrases and deceiving victims into installing malware. Proofpoint identified fraudulent emails impersonating Coldcard that direct users to a cloned site for a "hardware audit", leading to the installation of the ScreenConnect remote access tool via a GitHub-hosted batch file. The fake site includes a live chat feature where operatives guide victims through the setup, enabling attackers to steal funds or deploy ransomware.
Galaxy Research has verified three distinct theft events since July 30, resulting in confirmed losses of 1,596 BTC, valued at over $100 million. If a fourth unconfirmed incident is included, the aggregate financial damage could amount to $130 million.
Comments
No comments yet.