Sunday, August 9, 2026 Latest news About 📈 Live coin prices →
Business

Your Hardware Wallet Is Safe — But Scammers Are Using a Real Hack to Trick You Anyway

Coldcard's $130M exploit has spawned a fake "audit" scam tricking hardware wallet owners into installing remote-access malware.

Marcus Whitfield3 min read
Your Hardware Wallet Is Safe — But Scammers Are Using a Real Hack to Trick You Anyway

If you own a hardware wallet, here’s a scam worth knowing about: criminals are using a real security incident at Coldcard, where losses are reportedly nearing $130 million, as bait to trick owners of other brands into handing over their recovery phrases. Two major manufacturers, Trezor and Foundation Devices, have both issued warnings this week about a surge in phishing emails riding on the back of the Coldcard news.

The scam works by exploiting genuine fear. After the Coldcard exploit made headlines, scammers began sending emails about a “coordinated hardware audit,” a term designed to sound official and urgent. Anyone who clicks through lands on a cloned website built to look like Coldcard’s real one.

How the fake “audit” actually steals your funds

According to security firm Proofpoint, which identified the campaign, the fake site pushes a so-called “Hardware Audit” tool that, once installed, is actually remote-access software. That gives the attacker a way into the victim’s computer, and potentially a path to any recovery phrase, password, or wallet file stored or typed there.

What makes this particular scam unusually convincing is the human element. Rather than an automated chatbot, a real person staffs the fake site’s customer support chat and talks victims through the download and installation process step by step, lending false credibility to the whole operation.

What Trezor and Foundation are telling their users

Trezor confirmed it has already seen a spike in phishing attempts since the Coldcard exploit was disclosed. The company was clear that its own hardware is not affected by the Coldcard issue, but it still urged users to only ever enter a wallet backup phrase directly on the physical device itself, never on a website or in software.

Foundation Devices, which makes the Passport hardware wallet, said it had become aware of emails impersonating the company and steering recipients toward fake websites and malicious downloads. Foundation stressed that it will never ask a customer for their recovery phrase, and will never instruct anyone to install software in order to “secure” a wallet.

Why this matters even if you don’t own a Coldcard

This is the classic pattern that follows any high-profile crypto security incident: scammers don’t need to hack you directly if they can get you to hack yourself by playing on panic and urgency. A real exploit at one company becomes the hook used to target customers of completely unrelated brands.

For everyday holders, the takeaway is simple and worth repeating: no legitimate hardware wallet maker will ever ask for your recovery phrase by email, phone, or live chat, and none will ask you to install “audit” or “security” software on your computer. Your seed phrase belongs only on the device itself, offline, and nowhere else. If an email creates urgency around a security scare, that urgency is usually the scam, not the fix.

Read more: Boltz Pulls the Plug on Bitcoin Swaps as AI-Powered Hackers Outpace Its Team

Sources

More Business