Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Scammers Target Coldcard Wallet Users With Fake Security Audit Emails After Bitcoin Theft Claims

Scammers Target Coldcard Wallet Users With Fake Security Audit Emails After Bitcoin Theft Claims

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 6, 2026

Human Written
Scammers Target Coldcard Wallet Users With Fake Security Audit Emails After Bitcoin Theft Claims
  • Scammers are using fears over a recent eighty-eight million dollar Bitcoin theft to send fake security audit emails to Coldcard wallet users.

  • The attack leads victims to a fake compliance site featuring live human chat operators who trick users into approving administrative access prompts.

  • The downloaded diagnostic file secretly installs ScreenConnect remote access software, giving attackers full control over victim computers.

A dangerous phishing campaign is exploiting recent security worries among cryptocurrency investors. Cyber criminals are taking advantage of growing panic around a suspected $88 million Bitcoin theft. Scammers are sending deceptive messages to target owners of Coldcard hardware cold storage devices.

The emails in question falsely state that a device audit is currently ongoing on all devices. Cyber thieves utilize such bogus warnings to lure people to install harmful applications on their devices. The security firm Proofpoint discovered this ongoing threat and warned device owners to stay cautious.

Unsuspecting targets risk losing full control of their personal computers if they follow the deceptive instructions. The attack tricks users into installing remote access software that grants hackers entry to personal files. Crypto holders must understand how this fake security scheme works to protect their digital assets.

Fake Compliance Messages and Live Web Chat Tactics

Cybercriminals are distributing deceptive email messages sent from [email protected]. The email subject line mentions that a hardware audit is currently available to create an urgent sense of danger. The text informs readers that the recent discovery requires Coldcard to check device integrity across all hardware revisions.

Furthermore, the messages pressure recipients by stating that participation is strictly required before an August deadline. The attackers claim the checking process is air-gapped and will never ask for secret recovery seeds.

People who click on the audit tool button are redirected to a fraudulent site named coldcardcompliance.com. This dangerous page resembles the authentic brand site closely and appears to be original. Furthermore, the fake website has a live customer support chat that real people operate. The human agents chat with uncertain users to help them with the unsafe installation process.

his blend of sophisticated social engineering mirrors another Android-based fraud campaign. ESET researchers recently uncovered 28 apps on Google Play that defrauded millions by using fake call history previews to lure victims into paying for fabricated data.

If a victim shows doubt after seeing the request for administrative authorization, the online agent draws the attention of the user immediately. The agent reassures the victims and tells them to click the confirm button. The crimes occur through real people with the intent to ensure that the victims do not get suspicious.

Technical Breakdown of the Batch File and Malicious Payloads

The download link on the fraudulent webpage delivers a batch file known as Coldcard_Diagnostic_Tool.bat. Security experts investigated the large file and discovered two independent Base64-encoded files concealed inside.

At first, the script shows a basic diagnostic screen while simultaneously executing stealthy checks for permission. In case the user does not have the admin rights, the script activates a User Account Control prompt using PowerShell.

After securing elevated access, the code saves the hidden files to a temporary folder. The script names these extracted files setup.msi and docusign.exe before decoding them with a built-in Windows utility.

Once decoding completes, the automated installer executes setup.msi silently on the operating system of the victim. Meanwhile, the script launches docusign.exe, which installs a real DocuSign printer driver to act as a distraction.

The setup.msi file actually contains a ConnectWise ScreenConnect installer, which grants hackers remote control capabilities. Once installed, the remote tool connects back to a command-and-control server at address activeretirementrelocation.com.

Consequently, threat actors gain full access to view files, log keypresses, and extract saved web credentials. Security experts have issued a warning that criminals are able to deploy more malicious applications or ransomware through this open back door.

Crucial Steps to Protect Hardware Wallets and Personal Computers

Cryptocurrency holders must remember that hardware wallet creators never run mandatory remote software updates on host computers. Official device manufacturers will never force users to download external diagnostic utilities from unverified web links.

Always ignore unsolicited security audit alerts sent through regular email messages. Moreover, check official community channels whenever news of a widespread device security flaw surfaces online.

If you clicked on the suspicious audit link, disconnect your computer from the internet immediately. Terminate any active remote sessions and check your running processes for unauthorized software like ScreenConnect.

Furthermore, move your digital funds to a completely clean wallet using a separate, secure device. Never type your recovery seed phrases into any computer keyboard or web form under any circumstances.

Report suspicious domain names and phishing emails to the security response team. Additionally, verify domain names before downloading files to your computer.

Computer users should regularly update operating systems and maintain active antivirus protection to block unauthorized script execution.

It is always better to be careful when dealing with alerts from technical support, as it is the only real protection from complex social engineering attacks.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.