A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
Proofpoint, which discovered the campaign, says it uses emails impersonating COLDCARD that claim a security audit is underway across its hardware cold storage wallet devices.
The phishing campaign comes after attackers recently stole approximately 1,367 Bitcoin, worth an estimated $88.6 million, from 4,585 addresses using what is believed to be a random number generation flaw affecting multiple COLDCARD models and firmware versions.
The emails are sent from [email protected] with the subject "Hardware audit now available" and tell recipients that recent findings require COLDCARD to verify the integrity of devices across all hardware revisions.
"We are writing to inform you of a coordinated security audit now underway across the COLDCARD device network. Recent findings have prompted us to verify the integrity of hardware across all revisions, and your participation is needed," reads the fake security audit emails.
COLDCARD phishing email
Source: Proofpoint
The emails direct users to an alleged "Security Verification & Incident Reporting Tool," claiming the process is air-gapped, will not request their recovery seed, and must be completed by August 10.
Clicking an "Access the Audit Tool" button opens the site coldcardcompliance.com, which impersonates COLDCARD with a message to click on the "Start Hardware Audit" button to download the tool.
The fake website also includes a live "Customer Service" chat feature that allegedly allows targets to receive support for their COLDCARD devices.
... continue reading