
If you own a COLDCARD hardware wallet, watch out for official-looking emails claiming your device needs a mandatory security audit. Proofpoint has uncovered a phishing campaign that exploits the fear generated by the late July 2026 disclosure of a serious COLDCARD firmware vulnerability — the one that let attackers drain approximately 1,367 Bitcoin (around $88.6 million) from thousands of addresses by predicting supposedly random seed phrases. The phishing emails arrive from compliance@coldcardteamnews.com with a subject line like “Hardware audit now underway” and impersonate COLDCARD’s maker Coinkite, urging recipients to participate in a device validation process. Recipients who follow the instructions end up installing ScreenConnect, a legitimate remote monitoring and management tool from ConnectWise, which then hands the attacker full remote control of the victim’s computer.
The attack is a textbook example of crisis hijacking: a real, high-profile security incident creates an anxious audience of users who are primed to act on official-looking instructions without pausing to verify them. COLDCARD / Coinkite does not run security audits by emailing users and asking them to install software. Any email claiming otherwise is a scam. If an attacker gains remote access to a machine where a hot wallet or browser extension holds cryptocurrency keys, or where recovery phrases are stored, the funds can be stolen directly from that computer. The PRNG vulnerability itself affected the device’s firmware-level random number generator; the legitimate remediation path is firmware updates from coinkite.com only, not installing third-party remote-access tools.
How to check if you’re affected
If you received an email about a COLDCARD security audit and clicked any links or ran any software, check your affected products — any Windows or macOS computer you used — for an active ScreenConnect installation. On Windows, look for “ScreenConnect Client” in Settings > Apps or in Task Manager. On macOS, check Applications for “ScreenConnect Client.” Any version of any COLDCARD hardware wallet model could have made you a target if your email address was in a breach database. Remove ScreenConnect immediately if found and rotate any wallet seed phrases you may have stored or accessed on that machine.
