Attackers are impersonating COLDCARD in a phishing campaign that exploits concern over a recently disclosed wallet security issue and a suspected $88.6 million Bitcoin theft, urging users to complete a supposed hardware security audit. Victims are directed from email messages to a fake compliance site and told to download a Windows “diagnostic tool,” while live chat operators reportedly help guide them through the process and persuade them to approve administrator prompts.
Analysis of the fake tool found a batch file, Coldcard_Diagnostic_Tool.bat, that uses PowerShell and certutil to unpack payloads and install ConnectWise ScreenConnect from an attacker-controlled server, while showing decoy activity such as a legitimate signed DocuSign printer driver installer. Researchers said the campaign is separate from legitimate COLDCARD firmware or seed-migration workflows, and warned that affected systems should be treated as remotely exposed because the access could enable data theft, cryptocurrency theft, additional malware deployment, or ransomware.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The fake compliance site included a live customer service chat where operators asked victims whether they used Windows or macOS and instructed Windows users to run the downloaded tool. When victims encountered an administrator prompt, the operators told them to click "Yes," and Proofpoint assessed the chats were likely handled by real people.
The phishing emails directed victims to coldcardcompliance.com, which impersonated COLDCARD and offered a supposed hardware audit tool. Clicking "Start Hardware Audit" downloaded Coldcard_Diagnostic_Tool.bat, which unpacked setup.msi and docusign.exe, installed ConnectWise ScreenConnect, and connected to activeretirementrelocation.com for attacker-controlled remote access.
Proofpoint discovered a phishing campaign impersonating COLDCARD and exploiting publicity around the wallet vulnerability and suspected Bitcoin theft. The emails used compliance@coldcardteamnews.com and the subject line "Hardware audit now available" to lure targets to a fake audit process.
Attackers recently stole approximately 1,367 Bitcoin from 4,585 addresses, valued at an estimated $88.6 million. The theft is believed to be linked to a random number generation flaw affecting multiple COLDCARD models and firmware versions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.