Hardware wallet manufacturers are sounding the alarm over a fresh wave of phishing attacks, with losses tied to fraudulent Coldcard-related schemes climbing toward $130 million as scammers deploy increasingly sophisticated tactics to drain crypto holders' wallets.
How the Scam Works
The latest campaign centers on deceptive emails that pose as official communications from hardware wallet providers. Recipients receive messages urging them to participate in a supposed "coordinated hardware audit," a fabricated security measure designed to instill urgency and lower a victim's defenses.
Those who fall for the bait are directed to a counterfeit Coldcard website that closely mimics the genuine platform. Rather than performing any legitimate audit, the cloned site prompts users to install remote-access software, handing attackers direct control over the victim's device and, ultimately, their funds.
A fake security check is now the doorway criminals are using to empty crypto wallets.
A Growing Threat to Holders
The scheme highlights a troubling shift in phishing strategy, moving beyond simple credential theft toward the deployment of malicious software that grants attackers ongoing access. Once remote-access tools are installed, victims may not realize their systems have been compromised until their assets are already gone.
Hardware wallets are widely regarded as one of the safest ways to store cryptocurrency because private keys remain offline. But that security can be undermined when users are tricked into taking actions that expose their devices or recovery information to bad actors.
Industry figures warn that the mounting losses underscore how attackers are exploiting trust in established brands to reach otherwise cautious holders.
Staying Protected
Wallet firms and security researchers are urging users to remain skeptical of unsolicited messages and to verify any request through official channels before acting. Key precautions include:
- Ignoring emails that demand urgent "audits" or verification steps
- Never installing remote-access software at the request of an unsolicited message
- Confirming website addresses directly rather than following links in emails
- Treating any request for seed phrases or private keys as an automatic red flag
As losses continue to accumulate, the episode serves as a stark reminder that even the most secure storage devices offer little protection when users are manipulated into compromising them.
