Within days of the public disclosure of the Coldcard entropy vulnerability, cybercriminals began treating the incident as a social engineering opportunity.
PhishFort identified an active phishing campaign impersonating Coinkite that tries to convince Coldcard users to download a fake “hardware audit” utility. Rather than helping users verify their device’s integrity, the downloaded application installs remote access software capable of giving attackers persistent control over the victim’s computer.
This campaign follows a pattern seen repeatedly after major cryptocurrency security incidents: attackers capitalize on fear and uncertainty by impersonating trusted vendors and offering fake security tools, emergency patches, or compliance checks. While the investigation into the original entropy vulnerability continues, attackers had already started exploiting the attention surrounding it.
The Opportunity: Exploiting Uncertainty
Whenever a high-profile vulnerability affects the cryptocurrency ecosystem, users naturally start searching for answers. Am I affected? Is my wallet safe? Do I need to upgrade? Is there an official verification tool?
Threat actors understand that behavior well. Rather than exploiting the technical vulnerability itself, they exploit the human response to it. In this case, attackers built an entire phishing infrastructure designed to look like an official security initiative from Coinkite, urging users to complete what appeared to be a mandatory hardware audit.
The Email: Luring Victims Into a Fake Security Audit
The campaign begins with a professionally crafted phishing email impersonating Coldcard. The email originates from the domain coldcardteamnews[.]com, sent from compliance@coldcardteamnews[.]com, with the subject line “Hardware audit now available.”
The message claims Coinkite has initiated a coordinated hardware audit across all Coldcard devices following recent security findings, and instructs recipients to verify their hardware using a “Security Verification & Incident Reporting Tool.”

Several social engineering techniques show up throughout the message: references to an ongoing security incident, urgency built around a verification deadline, claims that participation is required, reassurance that no recovery seed is needed, and official-looking branding and language.
The attackers carefully avoid asking for the recovery phrase, likely because experienced Bitcoin users have been trained never to reveal it. Instead, they position the download as a harmless diagnostic utility meant to “verify device integrity.” That framing does a lot of work to increase the campaign’s credibility.
The Fake Website: Mimicking an Official Coinkite Portal
Clicking through from the email leads to coldcardcompliance[.]com. The site closely resembles an official compliance or security portal and continues the same narrative established in the email, telling visitors that Coinkite is conducting a coordinated hardware audit and instructing them to download the “Security Verification & Incident Reporting Tool.”

The site leans on several reassuring phrases designed to lower suspicion: network verification, incident reporting, hardware integrity validation, air-gapped verification, and “no recovery seed required.” These claims are technically believable, which makes the page especially convincing to users who already understand how hardware wallets work.
Rather than stealing credentials through a web form, the attackers rely on convincing users to voluntarily execute a malicious application. That’s a meaningful shift from traditional credential-phishing pages toward malware delivery through borrowed trust in a familiar brand.
Malware Analysis
What happens after a victim executes the downloaded file is the most interesting part of this campaign.
Instead of immediately behaving suspiciously, the malware presents what looks like a legitimate DocuSign Print Driver Installation Wizard, complete with official DocuSign branding, logos, and a familiar Windows installer interface. That serves two purposes: it distracts the user while the malicious payload runs in the background, and it gives a plausible explanation for the elevated-privilege prompts Windows displays during installation.
Behind that installer, the malware launches PowerShell and Command Prompt, decodes embedded payloads using CertUtil, installs ScreenConnect remote access software, modifies Windows services and registry entries, and establishes persistence on the compromised system.

Dynamic analysis of the downloaded application shows it’s far from a simple diagnostic utility. Execution begins with a batch file named Coldcard_Diagnostic_Tool.bat, which launches PowerShell and Command Prompt with elevated privileges before decoding additional payloads using Microsoft’s built-in CertUtil utility.
The malware then installs ScreenConnect, a legitimate remote monitoring and management platform that’s frequently abused by threat actors to gain persistent remote access to victim systems.

During execution, the sample demonstrates a full range of malicious behavior: PowerShell execution, privilege escalation attempts, command execution through CMD, Base64 payload decoding via CertUtil, ScreenConnect installation, registry modifications, persistence mechanisms, Windows service creation, startup folder modifications, system certificate changes, and remote management capability.
The sandbox classified the sample as malicious, flagging multiple indicators associated with remote administration software, persistence, privilege escalation, and suspicious system modifications.

Unlike credential phishing campaigns that go after recovery phrases or passwords immediately, this operation focuses on compromising the victim’s endpoint. Once remote access is established, attackers can monitor activity, capture sensitive information, manipulate cryptocurrency transactions, or deploy additional malware later.
A Familiar Pattern After Major Cryptocurrency Incidents
This campaign fits a recurring trend across the crypto ecosystem. Whenever a widely publicized vulnerability, wallet compromise, exchange breach, or software exploit becomes public, attackers rapidly launch phishing campaigns impersonating the affected organization. Rather than exploiting the underlying vulnerability directly, they exploit the confusion surrounding it.
Users searching for official guidance become prime targets for fake security updates, emergency patches, wallet verification tools, compliance checks, incident reporting portals, and customer support pages. The Coldcard campaign is another example of how quickly threat actors move to capitalize on breaking security news.
Protecting Yourself
Stay cautious with unsolicited communications tied to security incidents. Before downloading any software or following instructions in an email:
Verify announcements through the vendor’s official website and social media channels. Never trust security tools distributed through unsolicited emails. Inspect domains carefully for subtle impersonation attempts. Be cautious of messages that manufacture urgency around an ongoing incident. Download software only from official sources.
Attackers are consistently faster at exploiting public attention than users are at verifying what they’ve received.
Conclusion
The original Coldcard entropy incident showed how a single implementation flaw can put cryptocurrency at risk. The phishing campaign that followed it almost immediately shows something just as important: public security incidents create fertile ground for social engineering.
By impersonating Coinkite and distributing malware disguised as a security audit tool, attackers shifted from targeting wallets directly to targeting the users trying to protect themselves. As high-profile cryptocurrency incidents continue to draw attention, expect phishing campaigns to follow within hours or days of public disclosure, not weeks.
Worried about attackers impersonating your brand during a security incident of your own?
See how PhishFort detects and takes down impersonation campaigns before they reach your users →



