S&P 5007,600.50▲1.5% Nasdaq25,913.90▲2.1% Dow53,178.41▲1.3% Russell 2K2,981.91▲1.7% 10-Yr4.69%−6bp VIX15.86−0.13 WTI$80.00▼5.5% Gold$4,106.70▲1.4% EUR/USD1.151▼0.1% BTC$63,730▲0.4% Nikkei64,362▲4.0%
At close · Mon, Aug 3, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureColdcard phishing campaigns use fake audits and remote…

Coldcard phishing campaigns use fake audits and remote access tools

Security firm Proofpoint said the lure installs ScreenConnect, giving attackers a path to theft and possible follow-on malware such as ransomware.

Security researchers say scammers are ramping up phishing attempts aimed at hardware wallet owners in the wake of the Coldcard firmware exploit. Decrypt reports Proofpoint identified an email campaign that targets Coldcard users with a cloned website branded around a fake "coordinated hardware audit."

The emails, which Proofpoint said come from a spoofed Coldcard address, direct recipients to a page with a "Start Hardware Audit" button. Clicking it downloads a batch file hosted on GitHub that installs ScreenConnect, a legitimate remote-access tool, according to Proofpoint.

Decrypt says the fake site also includes a customer service chat window where a person, not an automated bot, talks victims through the installation. Proofpoint described the setup as effective social engineering because it plays on the fear and concern holders have about their crypto security after the Coldcard breach.

The Coldcard exploit traces back to a March 2021 firmware build that could pull wallet seeds from a software fallback rather than the device's hardware random number generator, leaving private keys guessable, Decrypt reports. Trezor and Foundation have separately warned users about phishing and reiterated that they will not ask for recovery phrases or direct customers to install software to secure a wallet.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.