In brief

Trezor and Foundation both reported a surge in phishing attempts targeting hardware wallet owners following the Coldcard exploit.

Proofpoint identified a phishing campaign targeting Coldcard holders with a cloned site and "Hardware Audit" that installs remote-access software.

A person, rather than a bot, staffs the fake site's customer service chat and talks victims through the install.

Hardware wallet manufacturers Trezor and Foundation have warned of a surge in phishing attempts trading on the Coldcard firmware exploit, with scammers chasing users' recovery phrases and pushing malicious downloads.Trezor said it was already seeing an increase in phishing attempts following the disclosure, telling users to enter a wallet backup only on the device itself and reiterating that its own hardware is unaffected. Foundation said it had been made aware of emails impersonating the firm that push recipients toward fake websites and malicious downloads, adding that it will never ask for a recovery phrase or tell users to install software to secure a wallet.Security firm Proofpoint documented a phishing campaign targeting Coldcard users on Monday. Emails sent from a spoofed Coldcard address invite recipients to complete a "coordinated hardware audit," a theme lifted from the security incident itself, and link to a cloned Coldcard site carrying a "Start Hardware Audit" button.