Loading market data...

Coldcard Users Lose Nearly $130 Million in Phishing Attacks, Firms Warn

Coldcard Users Lose Nearly $130 Million in Phishing Attacks, Firms Warn

Hardware wallet companies are raising alarms about a sharp increase in phishing attacks targeting Coldcard users. The attackers have stolen nearly $130 million through a campaign that uses fake 'coordinated hardware audit' emails to trick victims into visiting a cloned website that installs remote-access software.

How the Attack Works

The phishing emails appear to come from Coldcard or a related hardware wallet firm. They claim the recipient's device needs a 'coordinated hardware audit' to verify its security. The message includes a link to a website that looks nearly identical to the official Coldcard site. Once a user clicks the link and follows the instructions, the site secretly downloads remote-access software onto their computer. That software gives the attackers control over the machine, letting them steal cryptocurrency wallet credentials and private keys.

Losses Mount as Attacks Surge

The $130 million figure represents losses tied directly to Coldcard-related phishing, according to the warnings from hardware wallet firms. The companies did not say how many users have been affected or over what time period the losses accumulated. But they described the recent wave as a 'surge,' suggesting the campaign has accelerated in recent weeks. The scale of the thefts makes it one of the larger phishing operations targeting hardware wallet users in recent memory.

What Users Should Watch For

The firms are urging Coldcard holders to be skeptical of any unsolicited email about a hardware audit. Legitimate audits, if they exist, would not be initiated through email links or require downloading software from a third-party site. The cloned website used in the attack is designed to look authentic, but the URL often differs from the real Coldcard domain by a single character or uses a different top-level suffix. Users who receive such an email should not click any links and should report it to the company directly.

The warning from hardware wallet firms underscores the need for users to verify any communication claiming to be from Coldcard. The companies have not said whether they plan to issue software updates or additional security tools. In the meantime, users are advised to treat any unsolicited email about a hardware audit as suspicious and to only access Coldcard's official website by typing the address manually.