▼ Bear
Impact
98 · High

Cold Card Hacking Incident Results in $13 Million in Losses...Warning Issued Regarding Treasure and Foundation Phishing Scams

BTC
Decrypt · 1d agoView original ↗
Phishing attacks exploiting vulnerabilities in Coldcard firmware have surged, prompting hardware wallet manufacturers Trezor and Ledger to issue warnings to their users. Following the disclosure of the security incident, Trezor stated that phishing attempts have noticeably increased, emphasizing that wallet backups should only be entered on the device itself and that the company's hardware is not directly affected. Ledger also warned that emails impersonating the company are being circulated, directing users to fake websites and malicious files. The company stressed that it has never requested recovery phrases or instructed users to install software for security purposes. On August 3rd, security firm Proofpoint revealed a specific phishing campaign targeting Coldcard users. Attackers send emails with forged Coldcard addresses, requesting users to complete a "cooperative hardware audit" and redirecting them to a cloned website with a "Start Hardware Audit" button. Clicking the button downloads a batch file uploaded to GitHub, which then installs ScreenConnect, a legitimate remote access tool. Proofpoint explained that this allows attackers to steal data and financial assets, as well as deploy subsequent malware. Notably, a real person, not a bot, is stationed in the customer support chat window on the fake website, guiding victims through the installation process step-by-step. Proofpoint described this as an effective social engineering technique that exploits users' security concerns. The root of the vulnerability lies in a firmware build from March 2021. This build used a software fallback instead of a hardware random number generator when creating wallet seeds, resulting in a situation where private keys could be potentially guessed. Galaxy Research confirmed three waves of thefts since July 30th, with a total loss of 1,596 BTC, exceeding $100 million. Including a fourth wave where victims are suspected but not yet confirmed, the total potential losses could reach $130 million. Alex Sun, Head of Research at Galaxy Research, stated that all waves except the first were identified through user reports, and that at least 15 individual attackers are currently exploiting this vulnerability. Coldcard manufacturer CoinKite has released a patched firmware and advises affected users to move their funds to a newly generated seed. This incident is the latest example of a phishing offensive targeting hardware wallet users. In February, a physical mail campaign targeting Trezor and Ledger users included holograms and forged executive signatures. In April, a fake Ledger app stole millions of dollars, and in March, a fake GitHub issue was used to lure developers to a malicious website. Galaxy Research emphasized that the Coldcard vulnerability is still ongoing and urged holders to immediately transfer their funds to a new seed or a custodial service. The concern is that the phishing campaigns could persist for a long time as long as the vulnerability remains unresolved.
This is an AI summary. Read the full article at the source.
Comments 0
Log in to write a comment
Loading…