Scammers Deploy Live Support Operators to Exploit $130M Coldcard Crypto Wallet Flaw
Phishing campaigns deploy human support agents following a major firmware exploit affecting over 1,596 BTC.

Cybercriminals are deploying live human support operators on fraudulent helpdesks to hijack cryptocurrency wallets following a critical firmware vulnerability in Coldcard hardware devices that has put up to $130 million in Bitcoin at risk.
Cybersecurity firm Proofpoint identified an active phishing campaign capitalizing on holder panic. Attackers dispatch spoofed emails pretending to originate from Coldcard, instructing users to perform an urgent “coordinated hardware audit.” Recipients who click the embedded link are directed to a cloned website featuring a live customer service chat window. Unlike automated attack vectors, the chat is staffed by a real person who actively guides victims through downloading a GitHub-hosted batch file.
The malicious script installs ScreenConnect, a legitimate remote-access tool commonly used by enterprise IT departments. Once executed, the software grants attackers full administrative control over the victim’s computer, allowing them to steal stored credentials, intercept seed phrases, or deploy follow-on malware such as ransomware.

The security incident has triggered secondary exploits across the broader cold storage ecosystem. Competitors Trezor and Foundation have both issued emergency warnings after detecting a surge in brand impersonation. Foundation reported that scammers are sending emails pretending to be company representatives, pushing recipients toward malicious software downloads to secure their funds. Foundation reminded users it will never request a seed phrase or require software installation for wallet protection.
Trezor confirmed an uptick in phishing attempts targeting its client base following the public disclosure of the Coldcard flaw. The company advised users to only enter wallet recovery backups directly into the physical hardware device itself, emphasizing that Trezor units remain completely unaffected by the vulnerability.
The underlying flaw traces back to a March 2021 firmware release for Coldcard wallets. The software build failed to properly utilize the device’s dedicated hardware random number generator during initial setup, deriving wallet seed phrases from a software fallback mechanism instead. This implementation error resulted in weak cryptographic entropy, rendering generated private keys predictable and vulnerable to off-chain brute-force calculations.
Data compiled by Galaxy Research reveals that at least 1,596 BTC, valued at over $100 million, has been stolen across three distinct theft waves since July 30. Alex Thorn, Head of Research at Galaxy Research, stated that at least 15 separate attackers are currently exploiting the vulnerable addresses. Galaxy Research estimates that an unconfirmed fourth wave of thefts could push total losses past $130 million.
Coldcard manufacturer Coinkite has released patched firmware and instructed all impacted users to immediately transfer their assets to newly generated seeds. However, because funds must be moved manually across the blockchain, security analysts warn that the vulnerability leaves wallet holders exposed to social engineering tactics for an extended period.
The exploit follows a series of increasingly deceptive physical and digital campaigns targeting cold storage users. In February, attackers distributed physical mailers containing fake hardware devices, holograms, and forged signatures to Trezor and Ledger customers. In March, malicious actors leveraged fake GitHub issues to lure developers onto cloned sites, followed by an April incident where a counterfeit Ledger application on official platforms drained millions from user balances.









