Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2225+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. COLDCARD Security Audit Phishing Attack Installs Remote Access Tool
COLDCARD Security Audit Phishing Attack Installs Remote Access Tool
NEWS

COLDCARD Security Audit Phishing Attack Installs Remote Access Tool

Attackers impersonating COLDCARD hardware wallet makers are sending fake 'security audit' emails to exploit user anxiety over the RNG vulnerability. Victims who run the downloaded batch file get ScreenConnect silently installed on their machine.

Dylan H.

News Desk

August 6, 2026
4 min read

A sophisticated phishing campaign discovered by Proofpoint is targeting COLDCARD Bitcoin hardware wallet users, exploiting widespread anxiety over the device's hardware RNG vulnerability to trick victims into installing ScreenConnect — a legitimate remote desktop tool weaponized as a remote access trojan (RAT).

Background: The RNG Vulnerability

The phishing campaign builds on a real and serious security incident. COLDCARD firmware version 4.0.1 (released March 2021, affecting Mk3 and later models) contained a bug in which seed generation fell back to a weak software PRNG instead of the intended hardware random number generator.

The consequences were severe: the collapsed entropy allowed attackers to enumerate candidate seeds offline, derive wallet addresses, match them against the blockchain, and sweep funds without any physical access to the hardware wallet.

By August 2026, the damage tracked across multiple theft waves had reached staggering numbers:

  • ~1,816 BTC (~$116 million) drained from 5,200+ addresses (Galaxy Research)
  • 4,585 addresses compromised in confirmed theft waves (TRM Labs)
  • At least 15 distinct attacker clusters identified

Coinkite (COLDCARD's manufacturer) has advised all affected users to generate a completely new seed on updated firmware and transfer funds to the new address — simply updating firmware does not protect seeds generated during the vulnerable period.

The Phishing Campaign

Proofpoint researchers identified emails impersonating COLDCARD sent from compliance@coldcardteamnews.com with the subject line "Hardware audit now available." The emails claim that a manufacturer security audit is underway across all hardware revisions and urge recipients to participate.

Attack Flow

  1. Email delivery: Phishing email lands with urgency framing around the real RNG vulnerability
  2. Fake website: Link leads to a convincing replica of the official COLDCARD website featuring a "Start Hardware Audit" button
  3. Malicious download: Clicking the button downloads Coldcard_Diagnostic_Tool.bat from a GitHub-hosted account
  4. Human operator assist: A live chat feature on the fake site — staffed by a real human, not a bot — asks whether the victim runs Windows or macOS, then walks them through running the batch file and clicking through the Windows UAC elevation prompt ("click Yes — this is required to begin the installation")
  5. RAT installation: Running the batch file silently installs ScreenConnect, granting the attacker full remote access

Why ScreenConnect?

ScreenConnect (ConnectWise Control) is a legitimate commercial remote access product widely used by IT support teams. Using it instead of custom malware offers attackers key advantages:

  • Bypasses antivirus and EDR products that flag known malicious executables
  • Appears as legitimate software in process lists and installed programs
  • Provides full GUI and file transfer access to the victim's machine
  • Does not require custom C2 infrastructure

Once installed, attackers can steal crypto wallet software data, drain other wallets, install ransomware, or exfiltrate sensitive files.

Broader Phishing Surge

COLDCARD is not the only hardware wallet maker seeing increased targeting. Both Trezor and Foundation (makers of the Passport wallet) have independently warned their user bases of a surge in phishing attempts seeking seed phrases and recovery words, driven by the same fear cycle surrounding the COLDCARD RNG news.

What To Do

If you received this email:

  • Do not click any links or download any files
  • Report the sender domain to your email provider
  • Verify any COLDCARD communications at the official Coinkite website directly (type the URL manually)

If you ran the batch file:

  • Immediately disconnect from the internet
  • Check installed programs and running services for ScreenConnect or ConnectWise Control
  • Uninstall ScreenConnect and run a full malware scan
  • Assume your machine is compromised — change all passwords from a clean device
  • Transfer any cryptocurrency from wallets accessible from the affected machine immediately

COLDCARD users with firmware 4.0.1 seeds:

  • Generate a new seed on updated firmware
  • Transfer all funds to the new address
  • Do not reuse the old addresses

Key Takeaways

  • Attackers are weaponizing real security vulnerabilities to make phishing emails credible and urgent
  • Using legitimate remote access software (ScreenConnect) instead of custom malware bypasses most AV/EDR
  • Live human operators coaching victims through UAC prompts dramatically increases phishing success rates
  • Hardware wallet users should verify all communications by navigating directly to manufacturer websites
  • The COLDCARD RNG flaw has resulted in $116M+ in confirmed losses — update firmware and regenerate seeds immediately
#Phishing#Cryptocurrency#Remote Access Trojan#Social Engineering

Related Articles

ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam

Threat actors are leveraging email addresses exposed in ShinyHunters data breaches to send highly personalized sextortion emails demanding $2,000 in...

5 min read

INTERPOL Arrests 5,800 Suspects in Operation First Light 2026 Global Fraud Bust

A 3.5-month INTERPOL-led operation spanning 97 countries resulted in 5,811 arrests, $293 million seized, and 142,000 victims identified — targeting...

4 min read

236,000 DCloud Uni-App Sites Powering Crypto Scams and Wallet Drainers

Infoblox researchers have uncovered over 236,000 websites built on the legitimate DCloud Uni-App framework being weaponized for investment scams,...

5 min read
Back to all News