Leading players in the hardware crypto wallet market, including Trezor and Foundation, have issued urgent warnings to their clients. The reason is a sharp increase in malicious activity, as scammers attempt to capitalize on the panic arising from the discovery of a vulnerability in wallets made by rival brand, Coldcard.
What is the Core of the Coldcard Problem?
Recently, security specialists at Block discovered a serious flaw in the architecture of Coldcard devices. The issue lies in the seed phrase generation mechanism (RNG): instead of a reliable hardware random number generator, the device used a deterministic software algorithm. As a result, for vulnerable firmware versions, cryptographic entropy was either not added at all (Mk2 and Mk3 models) or was significantly limited (Mk4, Mk5, and Coldcard Q).
Although this flaw does not give hackers instant access to funds, it allows attackers to brute-force possible seed phrases offline and compare them against public addresses on the blockchain.
Coinkite, the manufacturer of Coldcard, has already acknowledged the problem and released updates. However, simply updating the firmware does not protect old wallets — users must generate a new seed phrase and transfer all funds to it.
The Anatomy of Phishing Attacks
The need for an emergency transfer of assets became the perfect catalyst for scammers. Analysts from Proofpoint have detailed one of the active phishing schemes:
- Attackers send emails masquerading as wallet manufacturers, offering an urgent “hardware audit.”
- The unsuspecting victim clicks a link to an exact replica of the official website and presses the Start Hardware Audit button.
- This triggers a file download from GitHub. Disguised as an update, a legitimate remote access tool called ScreenConnect is installed.
Once in control of the victim’s computer, hackers can steal data, drain cryptocurrency, or install ransomware. To lull victims into a false sense of security, fake support chats even operate on these counterfeit sites, where a live person helps the victims navigate the “audit” process, thereby building trust in the scheme.
🗣️ Official statements: Representatives emphasize: “Trezor and Foundation will never contact you first in direct messages, will never ask you to provide a wallet backup, and will never demand the installation of unknown software for protection.”
Scale of Damage and Network Reaction
According to Galaxy Research analysts, the situation has already led to serious financial losses. Researchers have confirmed three major waves of attacks and 14 local incidents.
- 📉 Compromised: ~7,300 addresses.
- 💸 Potential damage: Up to $130 million (2,055 BTC if a fourth wave is confirmed).
The Coldcard team notes that the vulnerability is being exploited by at least 15 different groups, and new clusters of thefts continue to be identified. The mass migration of users has not gone unnoticed: Glassnode analysts recorded anomalous activity on the Bitcoin network. Holders are actively transferring their savings to new, secure addresses, completely bypassing centralized trading platforms.
🛡️ Security Instructions: What to Do Right Now?
If you use hardware wallets (especially Coldcard with vulnerable firmware versions), strictly follow these rules:
- Update your device’s firmware exclusively from the manufacturer’s official website.
- Generate a new seed phrase on an already updated, secure device.
- Transfer all funds from the old address to the new one.
- Never enter your seed phrase on a PC keyboard, smartphone, in apps, or on websites. Entering the backup must be done only on the hardware device itself.










