A sophisticated phishing campaign discovered by Proofpoint is targeting COLDCARD Bitcoin hardware wallet users, exploiting widespread anxiety over the device's hardware RNG vulnerability to trick victims into installing ScreenConnect — a legitimate remote desktop tool weaponized as a remote access trojan (RAT).
Background: The RNG Vulnerability
The phishing campaign builds on a real and serious security incident. COLDCARD firmware version 4.0.1 (released March 2021, affecting Mk3 and later models) contained a bug in which seed generation fell back to a weak software PRNG instead of the intended hardware random number generator.
The consequences were severe: the collapsed entropy allowed attackers to enumerate candidate seeds offline, derive wallet addresses, match them against the blockchain, and sweep funds without any physical access to the hardware wallet.
By August 2026, the damage tracked across multiple theft waves had reached staggering numbers:
- ~1,816 BTC (~$116 million) drained from 5,200+ addresses (Galaxy Research)
- 4,585 addresses compromised in confirmed theft waves (TRM Labs)
- At least 15 distinct attacker clusters identified
Coinkite (COLDCARD's manufacturer) has advised all affected users to generate a completely new seed on updated firmware and transfer funds to the new address — simply updating firmware does not protect seeds generated during the vulnerable period.
The Phishing Campaign
Proofpoint researchers identified emails impersonating COLDCARD sent from compliance@coldcardteamnews.com with the subject line "Hardware audit now available." The emails claim that a manufacturer security audit is underway across all hardware revisions and urge recipients to participate.
Attack Flow
- Email delivery: Phishing email lands with urgency framing around the real RNG vulnerability
- Fake website: Link leads to a convincing replica of the official COLDCARD website featuring a "Start Hardware Audit" button
- Malicious download: Clicking the button downloads
Coldcard_Diagnostic_Tool.batfrom a GitHub-hosted account - Human operator assist: A live chat feature on the fake site — staffed by a real human, not a bot — asks whether the victim runs Windows or macOS, then walks them through running the batch file and clicking through the Windows UAC elevation prompt ("click Yes — this is required to begin the installation")
- RAT installation: Running the batch file silently installs ScreenConnect, granting the attacker full remote access
Why ScreenConnect?
ScreenConnect (ConnectWise Control) is a legitimate commercial remote access product widely used by IT support teams. Using it instead of custom malware offers attackers key advantages:
- Bypasses antivirus and EDR products that flag known malicious executables
- Appears as legitimate software in process lists and installed programs
- Provides full GUI and file transfer access to the victim's machine
- Does not require custom C2 infrastructure
Once installed, attackers can steal crypto wallet software data, drain other wallets, install ransomware, or exfiltrate sensitive files.
Broader Phishing Surge
COLDCARD is not the only hardware wallet maker seeing increased targeting. Both Trezor and Foundation (makers of the Passport wallet) have independently warned their user bases of a surge in phishing attempts seeking seed phrases and recovery words, driven by the same fear cycle surrounding the COLDCARD RNG news.
What To Do
If you received this email:
- Do not click any links or download any files
- Report the sender domain to your email provider
- Verify any COLDCARD communications at the official Coinkite website directly (type the URL manually)
If you ran the batch file:
- Immediately disconnect from the internet
- Check installed programs and running services for ScreenConnect or ConnectWise Control
- Uninstall ScreenConnect and run a full malware scan
- Assume your machine is compromised — change all passwords from a clean device
- Transfer any cryptocurrency from wallets accessible from the affected machine immediately
COLDCARD users with firmware 4.0.1 seeds:
- Generate a new seed on updated firmware
- Transfer all funds to the new address
- Do not reuse the old addresses
Key Takeaways
- Attackers are weaponizing real security vulnerabilities to make phishing emails credible and urgent
- Using legitimate remote access software (ScreenConnect) instead of custom malware bypasses most AV/EDR
- Live human operators coaching victims through UAC prompts dramatically increases phishing success rates
- Hardware wallet users should verify all communications by navigating directly to manufacturer websites
- The COLDCARD RNG flaw has resulted in $116M+ in confirmed losses — update firmware and regenerate seeds immediately