COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is targeting users of the COLDCARD hardware wallet by playing on fear around a recently disclosed COLDCARD wallet vulnerability and a…
By Dillip Chowdary • Aug 05, 2026 • Source: BleepingComputer
A phishing campaign is targeting users of the COLDCARD hardware wallet by playing on fear around a recently disclosed COLDCARD wallet vulnerability and a suspected $88.6 million Bitcoin theft. Attackers use that story to push victims toward installing ScreenConnect, a remote access tool, rather than delivering a wallet patch or a legitimate security fix. BleepingComputer reported the campaign.
The technical mechanics are social engineering, not a direct exploit of the wallet chip. Operators frame the pitch around the security audit and the large suspected loss so that ScreenConnect looks like emergency support or remediation. Once installed, ScreenConnect gives remote control of the machine: screen viewing, file access, and the ability to observe or influence later wallet-related actions on that host.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders working on wallet UX, support flows, or incident response, the lesson is that disclosure of a real vulnerability plus a large dollar figure becomes ready-made bait. Users who rush to “secure” funds after a public scare are easy to redirect into installing remote access software. Product and support teams should treat unsolicited installers, especially remote desktop or remote support packages, as high risk during any wallet-related incident window.
In market context, hardware wallets sell isolation: keys stay off general-purpose machines. This campaign bypasses that model by compromising the user’s computer instead of the device itself. ScreenConnect is a known remote access product; in a phishing chain it functions as a foothold for account takeover, seed capture from software running on the PC, or guided transfer of assets. The $88.6 million figure raises urgency and reduces skepticism, which is the campaign’s leverage.
Practical takeaway: do not install ScreenConnect or any remote access tool from cold outreach, “audit” emails, or links tied to COLDCARD vulnerability news. Verify COLDCARD security guidance only through official channels. Watch for follow-on lures that reuse the same vulnerability narrative, the same theft number, or other remote access installers under support or recovery branding.
Advertisement
🔎 More interesting news
- OpenAI, Anthropic AI Models Breached Systems During UK Safety Tests
- Anthropic Is Building Its Own Chip
- Claude Mythos 5 made sock puppet accounts to socially engineer developers: here's what…
- Show HN: HUD, an open-source minimal terminal UI for ClaudeCode, Codex, OpenCode
- Today's full Tech Pulse briefing →