


Perceptive Security
SOC/SIEM Consultancy

COLDCARD security audit phishing attack installs remote access tool
Published:
5 August 2026 at 17:49:41
Alert date:
5 August 2026 at 18:03:16
Source:
bleepingcomputer.com
Ransomware & Malware, Identity & Access, Email & Messaging
A phishing campaign is exploiting fears around a recently disclosed COLDCARD hardware wallet vulnerability and a suspected $88.6 million Bitcoin theft. Attackers are using this social engineering lure to trick COLDCARD users into installing ScreenConnect, a legitimate remote access tool being abused for malicious purposes. The campaign leverages the credibility of a 'security audit' narrative to appear legitimate. Once installed, ScreenConnect provides attackers with remote access to the victim's machine. This type of attack targets cryptocurrency users who may be anxious about the reported vulnerability and financial losses. The use of legitimate remote access software helps attackers evade detection by security tools. This campaign represents a targeted threat against cryptocurrency hardware wallet users with potentially high financial impact.
Technical details
A phishing campaign discovered by Proofpoint exploits fears surrounding a recently disclosed COLDCARD hardware wallet RNG vulnerability and associated $88.6 million Bitcoin theft (1,367 BTC from 4,585 addresses). Attackers send emails from compliance@coldcardteamnews.com with the subject 'Hardware audit now available', impersonating COLDCARD and urging users to participate in a fake security audit. The emails direct victims to coldcardcompliance.com, which hosts a fake audit tool with a live chat feature (operated by real humans, not bots) to pressure victims into installation. Clicking 'Start Hardware Audit' downloads a 25.7MB batch file named Coldcard_Diagnostic_Tool.bat from a GitHub account. The batch file contains two Base64-encoded payloads embedded directly within it. Upon execution, it simulates a fake diagnostic check while checking for administrator privileges; if not elevated, it uses PowerShell to trigger a UAC prompt. The embedded files are decoded via Windows certutil and stored in a randomly named temp directory as setup.msi (a ConnectWise ScreenConnect installer) and docusign.exe (a legitimate signed DocuSign printer driver used as a decoy). After installing ScreenConnect via setup.msi, the script launches docusign.exe to display an 'Installation Complete' message, then deletes the temp directory. ScreenConnect connects to the C2 server at activeretirementrelocation[.]com, giving attackers full remote access to the victim's machine. This access could be used to steal data, steal cryptocurrency, install additional malware, or deploy ransomware.
Mitigation steps:
1. Do not click links or download attachments from emails claiming to be COLDCARD security audits, especially from compliance@coldcardteamnews.com. 2. Verify any COLDCARD communications directly through the official COLDCARD website and official channels. 3. Block the domains coldcardteamnews.com, coldcardcompliance.com, and activeretirementrelocation[.]com at email gateways, DNS, and firewall levels. 4. Block or alert on the identified malicious file hashes (setup.msi and docusign.exe) in endpoint security tools. 5. Monitor for unauthorized ScreenConnect/ConnectWise installations on endpoints. 6. Educate users to be suspicious of unsolicited security audit requests, especially those requesting software installation and elevated privileges. 7. Implement application allowlisting to prevent unauthorized MSI and executable installations. 8. Review and audit any systems that may have executed Coldcard_Diagnostic_Tool.bat for signs of compromise and unauthorized remote access sessions. 9. If infected, isolate the affected machine, terminate ScreenConnect processes, and conduct a full forensic investigation.
Affected products:
COLDCARD hardware wallet (multiple models and firmware versions)
Microsoft Windows (target OS for the malicious batch file)
ConnectWise ScreenConnect (abused as remote access tool)
Related links:
https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/
https://x.com/threatinsight/status/2084328552481112429
https://www.virustotal.com/gui/file/7ad243cd358d916e029ba8ff9a616dfdcab29b594a9ebf08a66a1c4bd63fb7e2/
https://www.virustotal.com/gui/file/5f0dc835d9e37318f862c64db85cc094059bb5404a1c1752facdfd16a784570a
Related CVE's:
Related threat actors:
IOC's:
compliance@coldcardteamnews.com, coldcardteamnews.com, coldcardcompliance.com, activeretirementrelocation[.]com, Coldcard_Diagnostic_Tool.bat, setup.msi (SHA256: 7ad243cd358d916e029ba8ff9a616dfdcab29b594a9ebf08a66a1c4bd63fb7e2), docusign.exe (SHA256: 5f0dc835d9e37318f862c64db85cc094059bb5404a1c1752facdfd16a784570a)
This article was created with the assistance of AI technology by Perceptive.
