discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

COLDCARD security audit phishing attack installs remote access tool

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.

By Lawrence Abrams·Aug 5·bleepingcomputer.com·4 min read

Intelligence analysis by Llama

COLDCARD security audit phishing attack installs remote access tool
Image: bleepingcomputer.com

A phishing campaign is exploiting fears surrounding the COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. The campaign uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices.

Why it matters

This story matters to someone following Security because it highlights a phishing campaign that is exploiting fears surrounding the COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft.

A phishing campaign is trying to trick people into installing a tool that lets hackers control their computers. The hackers are using fake emails that look like they're from COLDCARD, a company that makes cryptocurrency wallets. The emails say that there's a security audit going on and that the person needs to download a tool to help with the audit. But really, the tool is just a way for the hackers to get control of the person's computer.

Analysis

A Phishing Campaign Exploits COLDCARD Fears

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. The campaign uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices.

The emails are sent from compliance@coldcardteamnews.com with the subject "Hardware audit now available" and tell recipients that recent findings require COLDCARD to verify the integrity of devices across all hardware revisions. The emails direct users to an alleged "Security Verification & Incident Reporting Tool," claiming the process is air-gapped, will not request their recovery seed, and must be completed by August 10.

Clicking an "Access the Audit Tool" button opens the site coldcardcompliance.com, which impersonates COLDCARD with a message to click on the "Start Hardware Audit" button to download the tool. The fake website also includes a live "Customer Service" chat feature that allegedly allows targets to receive support for their COLDCARD devices.

In chats shared by Proofpoint, an operator asks whether the victim uses Windows or macOS and then instructs Windows users to run the downloaded tool. When one user reported seeing a black window and an administrator prompt, the operator explained that the prompt was required to begin the installation and told them to click "Yes."

Proofpoint believes these conversations are likely being handled by real people rather than an automated chatbot, allowing the attackers to respond to concerns and pressure hesitant victims into proceeding with the installation.

The Attack Unfolds

Batch file installs remote access software

Proofpoint shared on X that clicking on the website's "Start Hardware Audit" button downloads a batch file named Coldcard_Diagnostic_Tool.bat from a GitHub account. BleepingComputer analyzed the 25.7MB batch file shared by Proofpoint and found that it contains two Base64-encoded files embedded directly in the file.

When launched, the script first pretends to perform a diagnostic check on your device, but in the background it actually checks whether the user has administrator privileges. If it does not, it uses PowerShell to relaunch itself with a User Account Control prompt to request elevated permissions.

The script then stores the embedded Base64-encoded files in a randomly named directory as setup.msi [VirusTotal] and docusign.exe [VirusTotal] in the Windows temp folder and decodes them using Windows certutil.

After installing the setup.msi file, the script launches docusign.exe, displays an "Installation Complete" message, and then deletes the temporary directory.

The docusign.exe file is a legitimate signed executable that installs a DocuSign printer driver, which acts as a decoy during the attack.

The MSI launched setup.msi file is actually a ConnectWise ScreenConnect installer, which is a remote management tool that gives the threat actor remote access to the device.

When launched, Proofpoint says it connects to the activeretirementrelocation[.]com, which is the ScreenConnect command-and-control server used by the threat actor.

Once connected through ScreenConnect, the attackers could remotely access the computer, steal data or cryptocurrency, or install additional malware.

Proofpoint warns that this access could also be used to deploy ransomware.

Test Every Layer Before Attackers Do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Key points

  • A phishing campaign is exploiting fears surrounding the COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft.
  • The campaign uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices.
  • The emails direct users to an alleged "Security Verification & Incident Reporting Tool," claiming the process is air-gapped, will not request their recovery seed, and must be completed by August 10.
  • The fake website includes a live "Customer Service" chat feature that allegedly allows targets to receive support for their COLDCARD devices.
  • The batch file downloads a legitimate signed executable that installs a DocuSign printer driver, which acts as a decoy during the attack.
  • The MSI launched setup.msi file is actually a ConnectWise ScreenConnect installer, which is a remote management tool that gives the threat actor remote access to the device.
The Upside

If this development plays out positively, it could lead to increased awareness and vigilance among cryptocurrency users, reducing the likelihood of successful phishing attacks.

The Downside

The realistic downside risks or failure modes include the potential for widespread adoption of the phishing tool, leading to significant financial losses and compromised user data.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityphishingcolcoldcardcryptocurrencywalletvulnerabilitybitcointheft

Author

Lawrence Abrams

Intelligence analysis by

Llama

Published

Aug 5, 2026

Source

bleepingcomputer.com

Share

Topics

securityphishingcolcoldcardcryptocurrencywalletvulnerabilitybitcointheft

Related

More from this desk

Aug 5·wired.com

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

A security researcher, Vangelis Stykas, gained access to North Korean systems and found evidence of 1,640 companies across 57 countries being impacted by the country's hacking operations. Among these, around 700 to 800 organizations had 'really damaging' intrusions.

Aug 5·bleepingcomputer.com

Ransom Cartel ransomware creator sentenced to 16 years in prison

Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.

Aug 5·bleepingcomputer.com

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty to stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. The data was accessed through Snowflake's storage service without multi-factor authentication.

Aug 5·wired.com

DHS Wants Protesters’ Signal Group Chats

The Department of Homeland Security is seeking neighborhood “rapid response” Signal group chats as it defends itself in a lawsuit accusing it of violating protesters’ First Amendment rights.