Trezor and Foundation warned users about phishing attacks
8/4/2026, 01:49 PM • Евгения Слив

Hardware wallet manufacturers Trezor and Foundation have issued important warnings to users. Companies have recorded an increase in phishing attacks on the market. The attackers are actively sending fake emails on behalf of the brands. Scammers are trying to force customers to go to malicious sites. Foundation representatives noted attempts to install unknown software. Trezor employees recalled the basic rules of digital security. A backup copy of the wallet must be entered exclusively on a physical device. Companies never request seed phrases over the internet. Support staff do not write to users first in messengers. Users should ignore any unsolicited instructions on how to protect funds. Entering secret data on third-party resources leads to the loss of assets. Attackers are constantly improving their social engineering methods. Owners of digital assets should exercise maximum caution.
Proofpoint specialists have described in detail a new scheme to deceive Coldcard owners. The attackers suggest that users undergo a mandatory hardware audit. The link leads to an exact copy of the manufacturer's official website. The victim downloads the file from GitHub and installs the ScreenConnect program. This legitimate tool provides hackers with remote access to a computer. A fake technical support chat is running on the fake website. The fraudster helps to complete the installation and increases confidence in the scheme. The phishing wave overlapped with the revealed vulnerability of the Coldcard wallets themselves. The devices used a software generator instead of a hardware source of randomness. The Block specialists found an integration error in the original firmware. This allowed hackers to sort through potential seed phrases offline. The attackers could verify the received addresses with the public data of the blockchain. Hackers were able to calculate secret keys offline.
Coinkite has acknowledged the existence of a technical problem and released fixes. The firmware update does not change the previously created vulnerable seed phrase. Users need to generate a new key and transfer funds. Galaxy Research researchers estimated the confirmed losses at 1,596 bitcoins. The funds were withdrawn from approximately 7,300 public addresses. The total damage could rise to 2,055 bitcoins later. The Coldcard team reported the activity of at least fifteen different attackers. Glassnode analysts have recorded abnormal activity on the network of the first cryptocurrency. Holders sent funds en masse to new secure addresses. Users avoid transferring assets to centralized trading platforms. Researchers continue to identify new clusters of such thefts. Small loss reports help to uncover unknown attacks.
