A COLDCARD hardware wallet vulnerability is being exploited by threat actors.
The reported firmware flaw has led to tens of millions worth of Bitcoin stolen.
Clicking it pulls a batch file hosted on GitHub, which installs ScreenConnect, a legitimate remote-access tool. Proofpoint said that gives attackers a route to data and financial theft, or to follow-on malware such as ransomware.
The fake site also runs a customer service chat window. Proofpoint said a real person, not a bot, answers it and walks victims through the installation, assessing the breach as an effective social engineering lure because it “preys on the fear and concern” holders now have about their crypto security.
The exploit behind the lureGalaxy Research said the Coldcard exploit is ongoing and urged holders to move funds to a fresh seed or a custodian—giving the phishing lure a long potential shelf life.


















