Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M
Hardware wallet manufacturers Trezor and Foundation have warned of a surge in phishing attempts targeting users of their devices, following the disclosure of a Coldcard firmware exploit. Scammers are chasing users' recovery phrases and pushing malicious downloads.
Intelligence analysis by Llama

Trezor and Foundation have warned of a surge in phishing attempts targeting hardware wallet owners following the Coldcard exploit. Scammers are chasing users' recovery phrases and pushing malicious downloads.
Imagine you have a special kind of safe that stores your important secrets. Scammers are trying to trick people into giving them the combination to the safe, so they can steal the secrets inside. This is called phishing, and it's a big problem for people who use special hardware wallets to store their cryptocurrency.
Analysis
A Growing Threat to Hardware Wallet Security
The recent Coldcard firmware exploit has led to a surge in phishing attempts targeting hardware wallet owners. Trezor and Foundation, two prominent hardware wallet manufacturers, have issued warnings to their users about the increased risk of phishing attempts. Scammers are using cloned sites and 'Hardware Audit' tools to install remote-access software on users' devices, allowing them to access sensitive information such as recovery phrases.
The phishing campaign is sophisticated, with a person rather than a bot staffing the fake site's customer service chat. This makes it more convincing for victims, who are talked through the installation process by the scammer. Trezor has already seen an increase in phishing attempts following the disclosure of the exploit, and is advising users to enter their wallet backups only on the device itself. The company is also reiterating that its own hardware is unaffected by the exploit.
Foundation has also warned its users about the phishing attempts, and is advising them to be cautious when interacting with their hardware wallets. The company is also working to educate its users about the risks of phishing and how to protect themselves.
The surge in phishing attempts highlights the importance of users being cautious when interacting with their hardware wallets. Users should never enter their recovery phrases on untrusted sites, and should always be wary of suspicious emails or messages. By being vigilant and taking steps to protect themselves, users can reduce the risk of falling victim to phishing attempts and keep their sensitive information safe.
Key points
- Trezor and Foundation have warned of a surge in phishing attempts targeting hardware wallet owners following the Coldcard exploit.
- Scammers are using cloned sites and 'Hardware Audit' tools to install remote-access software on users' devices.
- Users should never enter their recovery phrases on untrusted sites and should always be wary of suspicious emails or messages.
- Trezor is advising users to enter their wallet backups only on the device itself and is reiterating that its own hardware is unaffected by the exploit.
If users are cautious and take steps to protect themselves, they can reduce the risk of falling victim to phishing attempts and keep their sensitive information safe.
The surge in phishing attempts could lead to a significant number of users falling victim to scams, resulting in the loss of sensitive information and potentially even financial losses.



