COLDCARD wallet random number generation security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A random number generation flaw in multiple COLDCARD models and firmware versions has been tied to theft of about 1,367 Bitcoin from 4,585 addresses, putting affected cold-storage wallet users at risk. The flaw is being used in the wild, and attackers are leveraging the theft to fuel a follow-on phishing campaign.
Related Happenings
COLDCARD ScreenConnect phishing campaign
Campaign
H score39
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
How related:
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
About this happening:
A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...
COLDCARD ScreenConnect phishing campaign
CampaignHow related: A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
About this happening: A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...
Coldcard seed-generation PRNG actively exploited security flaw
Vulnerability
H score35
First: 01.08.2026 20:17
Last: 01.08.2026 20:17
Sources 1
About this happening:
Coldcard hardware wallet firmware carried a seed-generation flaw that used a deterministic software PRNG instead of the STM32 hardware RNG, enabling offline recons...
Coldcard seed-generation PRNG actively exploited security flaw
VulnerabilityAbout this happening: Coldcard hardware wallet firmware carried a seed-generation flaw that used a deterministic software PRNG instead of the STM32 hardware RNG, enabling offline recons...
Latest development: 03.08.2026 11:40
Galaxy Research identified a second and third Coldcard attack wave on August 1 that pushed the total stolen to 1,367 Bitcoin ($88.6m) from 4,385 victim addresses, and said on August 2 that the Coldcard exploit is ongoing while about 600 suspected hacker addresses tied to Coldcard-generated weak entropy funds were reported to investigators.
NFCShare fake banking-app update phishing campaign
Campaign
H score40
First: 09.06.2026 01:11
Last: 09.06.2026 01:11
Sources 1
About this happening:
The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding...
NFCShare fake banking-app update phishing campaign
CampaignAbout this happening: The NFCShare phishing campaign is using fake banking-app updates on GitHub to steal payment card data from customers of multiple banks across Europe, expanding...
NFCShare Android malware spreads via fake banking-app updates
Malware Activity
H score21
First: 09.06.2026 01:11
Last: 09.06.2026 01:11
Sources 1
About this happening:
The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions acr...
NFCShare Android malware spreads via fake banking-app updates
Malware ActivityAbout this happening: The NFCShare Android malware is being spread as fake banking-app updates on GitHub, broadening attacks against customers of multiple banks and financial institutions acr...
Timeline
-
05.08.2026 20:49 2 articles · 1h ago
COLDCARD audit phishing campaign delivers ScreenConnect
Technical Analysis UpdateProofpoint says a phishing campaign impersonates COLDCARD with fake security audit emails from [email protected], directs victims to coldcardcompliance.com and a "Security Verification & Incident Reporting Tool," and then downloads Coldcard_Diagnostic_Tool.bat from GitHub to drop a ConnectWise ScreenConnect installer. The lure leverages fear around the recently disclosed COLDCARD wallet vulnerability and a suspected $88.6 million Bitcoin theft tied to a random number generation flaw affecting multiple COLDCARD models and firmware versions.
Show sources
- COLDCARD security audit phishing attack installs remote access tool — www.bleepingcomputer.com — 05.08.2026 20:49
- COLDCARD security audit phishing attack installs remote access tool — www.bleepingcomputer.com — 05.08.2026 20:49