Crypto

Coldcard phishing scam follows firmware flaw as reported losses near $130 million

Coinkite has issued fixed Coldcard firmware and migration steps as phishing emails reportedly exploit the security incident.

Theo Nakamura

By Theo Nakamura · Staff Writer

· 3 min read

Coldcard phishing scam follows firmware flaw as reported losses near $130 million
Photo: Decrypt

A Coldcard phishing scam is spreading alongside a disclosed firmware issue that put some wallet-generated seeds at risk. For holders, the immediate concern is twofold: determine whether an older seed falls within Coinkite’s advisory, then avoid emails or downloads that use the incident to steal access.

Coinkite, Coldcard’s manufacturer, said a series of firmware bugs prevented the device’s hardware random-number generator from contributing randomness in certain versions. The company has released fixes, but stressed that installing an update does not repair a seed created on affected firmware. Affected users need to create a new seed after updating and move their funds to the new wallet.

Separately, Decrypt reported that Galaxy Research had identified three confirmed theft waves since July 30, with high-confidence losses of 1,596 bitcoin valued above $100 million. Galaxy’s possible total rises to $130 million only if a fourth suspected wave is included, according to the report. The larger figure is therefore not a confirmed loss total.

Which Coldcard wallets are affected?

Coinkite says Mk2 and Mk3 seeds generated on firmware versions 4.0.1 through 4.1.9 may be at risk. The advisory also covers seeds created on Mk4, Mk5 and Q devices before their respective fixed releases.

  • Mk2 and Mk3: version 4.2.0 or later
  • Mk4 and Mk5, standard release: version 5.6.0 or later
  • Q, standard release: version 1.5.0Q or later
  • Mk4 and Mk5, Edge release: version 6.6.0X or later
  • Q, Edge release: version 6.6.0QX or later

The scope has important qualifications. Coinkite says a seed created with at least 50 fair, independent and private dice rolls is not considered at risk from this random-number-generator issue alone. A strong, unique BIP-39 passphrase adds a separate barrier, but Coinkite still advises owners of affected seeds to migrate as soon as practical. TAPSIGNER, OPENDIME and SATSCARD are not affected, according to the company, because they use separate codebases.

How should affected Coldcard users respond?

Coinkite’s process is to confirm that fixed firmware is installed, generate and record a new seed, verify the wallet information, send a small test transaction, and then transfer the remaining balance. Its advisory warns that a passphrase should not be entered into a website or an untrusted device.

That caution matters because the reported phishing campaign borrows the language of the Coldcard incident. Proofpoint, as cited by Decrypt, found spoofed Coldcard emails inviting recipients to conduct a “hardware audit.” The messages linked to a cloned Coldcard website with a button that downloaded a batch file hosted on GitHub. Decrypt reported that the file installed ScreenConnect, a legitimate remote-access tool that Proofpoint said could enable data or financial theft and follow-on malware.

Proofpoint also found a customer-service chat window on the fake site that was answered by a person who guided victims through the installation process, Decrypt reported. The report said Trezor had told users to enter a wallet backup only on the device itself, while Foundation said it would not ask for a recovery phrase or direct customers to install software to secure a wallet.

For holders responding to the advisory, the safest route in the supplied guidance is to obtain firmware through official vendor channels, complete the migration steps carefully, and avoid entering recovery material on a website.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto