Incident-related scams and warnings
This record separates events supported by an artefact or first-person report from warnings about what might happen, and keeps a June campaign from being misdated as a response to the July disclosure.
The held record contains a Telegram impersonation artefact, four first-hand reports of phishing email sent to COLDCARD and Trezor owners, a repository that offered to reproduce the defect and was reported to carry an infostealer, an impersonation account on X, Trezor's report of increased phishing attempts and a first-person account of a migration into an impostor wallet app. Four vendors also published warnings about anticipated scams. Those warnings are preserved as statements by their publishers, not evidence that every described event occurred. Coinkite's own urgent migration language closely resembled the pretext an impersonator could use. V1
On 1 August Coinkite wrote: "Please treat this as urgent. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds."
Vendor warnings preserved below responded to this overlap by telling readers where firmware should come from, which contacts to distrust and which recovery material no support channel should request.
What is documented
The post-disclosure reports below are held as captures. One includes the underlying image, reproduced here from the archive. The rest are attributed reports whose screenshots are held inside the captured posts rather than reproduced on this page, and each carries the limits stated with it.
A dated prediction, then a dated artefact
On 31 July at about 14:59 UTC, Jameson Lopp wrote that it was "only a matter of time" before phishing mail claiming to be Coinkite security notices went out, trying to get readers to enter their seed words into a malicious site. R2 On 1 August at 18:02 UTC he quote-tweeted that post with a screenshot and the caption "The scammers have updated their playbooks." The prediction is a warning; the screenshot is an artefact. A warning published on 31 July does not become an event because something arrived on 1 August.
A Telegram account impersonating COLDCARD
The screenshot Lopp published shows a Telegram conversation opened by an account whose display name is "COLDCARD WALLET". The message is dated August 1 at 03:38 and reads, with the recipient's name blacked out: "Hello [redacted] Checking out on our database got you were one of our first users", followed by "I hope youre got an update about the hardware, I hope you were able to transfer your funds safely".
It asks for nothing. No link, no attachment, no request for seed words, no form. It opens a conversation and waits, which defeats the advice most owners have internalised, because "never type your seed" cannot fire against a message that has not asked for one. Whatever the request turns out to be, it arrives after the account has been treated as a correspondent rather than a stranger.
The blue mark is not verification. Telegram's own panel, visible in the same screenshot, explains that the mark denotes a Premium subscriber, which is a paid feature, and separately flags the account as "Not an official account". The platform contradicts the display name in the same view, and the contradiction is easy to scroll past.
The pretext is the vendor's own. "I hope you were able to transfer your funds safely" is a paraphrase of the advisory quoted above. An owner who read the advisory has already had this thought.
Phishing email reported first-hand
Four separate first-hand reports of incident-themed phishing email are held, dated 3 to 5 August. On 3 August a poster on r/coldcard reported a security advisory email from [email protected], a lookalike domain, offering to schedule a ten-minute session, and a second from [email protected]. A commenter in the same thread reported mail purporting to come from Ledger and claiming that Ledger was also affected because it used shared code libraries. R4
On 4 August at 03:24 UTC American HODL published four screenshots of a message urging him to download a "Coldcard Desktop App MK3 4.2.0", writing that "there never was, is or will be a coldcard desktop app". The screenshots show a message headed "Important Security Update — Coldcard MK3 4.2.0 Release and Required Action" and opening "Dear Coldcard Community", which apologises, numbers its instructions, tells the reader to "generate a brand-new seed phrase within the updated application" and then to "carefully migrate your assets from your previous wallet to the newly created wallet", directs anyone needing assistance to "our official support channels", and ends in a red button reading "Download MK3 4.2.0 Update". R5 The two instructions it numbers — generate a new seed, then carefully move the funds across — are the two instructions in Coinkite's own migration appeal quoted at the top of this page.
Twelve minutes later Bitcoin Rothbard published a fifth screenshot with the caption "I got this one from 'Trezor'", quote-showing American HODL's images beneath it. The held capture shows an email headed "Message From Our Ceo" under a Trezor logo, addressed to "Hello Trezor Users", which links a Fortune article about the COLDCARD losses and then states that "CoinKite is a hardware wallet company which we were partnered with. We shared source code, internal tools, and updates. While our Suite was not directly effected, a lot of our infrastructure relied on CoinKite." It closes with a link to "our latest version in our web suite" and the sign-off "CEO - Matej Zak". R6 The shared-source-code claim in that screenshot runs against Trezor's own published position: the incident email Trezor sent its users, as reproduced by a poster in a held r/Bitcoin thread, states that "Trezor does not use Coldcard's firmware or code", and Trezor's own captured posts of 4 and 5 August say its devices are not affected. R7
On 5 August at 20:02 UTC Margot Paez published a screenshot of a further email posing as Trezor support, named the sending address as [email protected] and told readers not to click its green button. The held capture shows a "CRITICAL SECURITY BULLETIN" headed "TROPIC01 CHIP SECURITY PROTOCOL UPDATE", dated 5 August 2026 and given the reference TB-SEC-2026-00796, asserting an anomaly in the secure element verification protocol of "ALL Trezor hardware wallet models" and requiring readers to run a diagnostic test through a support portal, ending in a green button reading "ACCESS SUPPORT PORTAL NOW". R8 This one carries no COLDCARD pretext at all: it is a Trezor-branded alarm about a Trezor part, reported six days after the COLDCARD disclosure.
These are reports with artefacts attached, not captures of the messages themselves: this archive holds the posts, and the screenshots inside them, not the underlying email. Two of the four name Trezor rather than Coinkite. In the same r/Bitcoin thread about the incident email Trezor sent its own users, one commenter wrote that they had received "3 or 4 scam 'Trezor' emails before I got the real one". R9
A repository baited with the defect itself
On 5 August jrakibi warned that a repository which had gained many stars in 24 hours, and which claimed to reproduce the vulnerable COLDCARD RNG, pulled a dependency that downloaded and executed an infostealer searching for wallet seeds, private keys and passwords. The finding is described as LLM-assisted. The repository is not named or linked here, and this archive has neither run nor reviewed it. R10 Later the same day satsie described having starred that repository while using an LLM to understand the attack, then unstarring it once it was identified, and wrote that "the attacks are coming in from all angles". R11 The bait in this case is reproduction of the defect, so the people reached are those investigating the incident rather than the owners moving funds.
Impersonation during the response
On 5 August Rob Hamilton, an AnchorWatch co-founder whose chain analysis and migration warning are part of this record, wrote that he was no longer reachable by direct message because of "way too many scammers pretending to be media and even sometimes fake victims trying to get me to click links", and named colleagues as the contact route instead. R12 Hours later, early on 6 August, SoapMiner posted "I'm a complete idiot. I just got scammed", warned others and linked an account whose handle is a near miss of Hamilton's. R13 Separately, on 3 August, Joe Carlasare published a screenshot captioned "Scummy people trying to prey on fear" and "THIS IS FAKE. SHARE". The post's text does not say what the screenshot shows, so what was being called fake is legible only in the attached image. R14
Trezor reports increased phishing attempts
On 4 August, Trezor said it was already seeing an increase in phishing attempts following the disclosure. It warned users never to share a wallet backup, never to follow migration instructions from unsolicited contact and to enter a backup only on the Trezor device during recovery. R15 The increase is therefore a vendor report rather than a measurable incident count in this archive. The safety rules can still be checked directly against the captured post.
A reported fake-wallet migration loss
On 2 August, @lunymoon13 reported losing 6.06 BTC after reacting to the incident and moving funds into what the author described as a fake Wasabi app found in Apple's App Store. R16 The report is not independently verified. It records a distinct failure mode in which incident-driven migration was redirected through software selected under pressure.
What belongs to an earlier campaign, and is dated accordingly
two items that name Coinkite and predate this incident
Both items below circulate widely and predate this incident. They carry the highest misinformation risk on this page, because recirculating them as evidence of post-disclosure phishing is a date error that would be very easy to make in good faith.
The June 2026 paper campaign
From 20 June 2026 a physical letter impersonating Coinkite was reported first-hand with photographs. The letter used a post-quantum firmware-upgrade pretext and carried a 30 June deadline. On 24 June Coinkite published a response, "Paper spam attempts", which states that Coinkite would never send a paper letter, that the mail is a scam to steal coins, that Coinkite deletes customer data including physical addresses after 120 days, and that it uses no external customer-relationship tooling. Coinkite attributes the targeting data to aggregated leaks from other companies and says an audit of its own servers found no reason to suspect a breach. V17 Some people reporting the letters inferred a Coinkite data leak. Coinkite denies a breach. Both positions are recorded here and neither is adopted. R18
The 120-day practice named in that June statement has since changed. On 7 August 2026, first listed on its blog index as 6 August and then retimestamped, Coinkite published "Update on Customer Data Retention", which says that records are normally blanked automatically after 120 days with only email address and country of residence retained, and that this automated blanking has been temporarily suspended because of legal obligations arising from the incident. Customers who want the standard policy applied to their own data are asked to confirm that by contacting [email protected]. The retention change belongs to the vendor's statements and to the legal record and is treated there; it is noted here because the June statement quoted above rests on the practice that changed, and because the vendor's stated channel for the request is an email address. V19
This is a separate event, five weeks before the entropy disclosure. Presenting the June letter as post-disclosure phishing is a date error. As of 15 August 2026 this archive has found no evidence of a fresh letter wave posted after 30 July. Postal delay means an absence of reports that week would not settle the question either way.
The generic "do not open links from wallet brands" warning
A general warning about links in messages purporting to come from wallet brands circulated before this incident. R20 No artefact of it and no attribution for it are held here, it predates the 30 July disclosure, and it is not specific to this incident. It is recorded so that its recirculation is not mistaken for a report of something new.
What vendors warned about, which is not the same as what happened
From 31 July through 4 August, four vendors of competing hardware or software published scam guidance alongside their statements about this incident. V21 Everything in this section is a warning. None of it is a report that the described thing occurred, and none of it should be cited as one. Their lists overlap, so the rules are deduplicated and attributed below rather than printed four times.
- Any email or message carrying a firmware update is hostile, whoever the sender appears to be. Blockstream
- Never type your seed words into a website, form or "checker" tool, and treat any request to verify a seed somewhere as hostile. Blockstream, Foundation, Trezor
- No vendor DMs you first or asks for your seed words. Treat unprompted messages offering help, and anyone claiming to be Foundation or Coinkite staff, the same way. Blockstream, Foundation, Wizardsardine
- Never follow wallet-migration instructions from unsolicited emails, messages or phone calls. Trezor
- Pressure is the mechanism: scams need you to act before you check, and anyone saying your funds are at risk and they can help is applying it. Scams "will multiply in the coming days". Blockstream, Foundation, Wizardsardine
- Expect fake "recovery services" offering to get stolen coins back for a fee. Foundation, Wizardsardine
- Do not install software found in a hurry, do not buy a device from an unknown seller, and distrust search results and sponsored links for wallet software. Wizardsardine, Foundation
- Requests to share your screen or install remote-access software have no legitimate place in this. Foundation
Captures: Blockstream (Jade), 31 July 2026 · Foundation (Passport), 31 July 2026 · Wizardsardine (Liana), 1 August 2026 · Trezor (Trezor), 4 August 2026
KeychainX, which identifies itself as a paid wallet-recovery firm, warns on its incident page that any service promising to recover already-swept Bitcoin for a fee is "a second scam aimed at people already harmed by the first". R22 The distinction it draws is between recovering a lost key and reversing a completed spend, which the page says no service can do.
The same question runs through the held community threads, in both directions. On 5 August, commenters on a first-hand loss thread described a paid-recovery pattern that escalates fee after fee, and argued that its real product is identity data: one wrote that victims would be asked to "verify their ownership of the bitcoin or coldcard hardware by providing those kinds of details, when in reality they cannot help the victims in any way", and another that a genuine whitehat would not charge for a recovery service. R23 On 6 August, in a captured r/coldcard thread about keeping affected devices, a commenter wrote "I love how people think that money can't be clawed back", without naming a mechanism, a case or a party who could do it. U24 Both are recorded as the form the recovery question takes in the record, and neither is adopted. What the archive holds on recovery itself is set out on the funds page: no recovery, seizure or payout has been reported in any captured source, and a 3 August relay of white-hat drains said to be underway is unconfirmed and names no amounts.
An absence in the vendor response
no scam guidance appears alongside the entropy advisory
As of 15 August 2026, Coinkite has published no scam or phishing guidance alongside the entropy advisory, and the advisory itself contains no text about impersonation, checker tools or which contact channels are official. V25 This is stated as an absence observed in the held captures, and it is worth recording precisely because Coinkite demonstrably publishes this kind of guidance: it did so on 24 June, in detail, for the paper campaign. No motive is attributed here, the advisory has been revised repeatedly since 30 July, and this is a statement about what the held captures contain on a given date rather than a characterisation of the vendor's conduct.
Activity that resembles the warning patterns
three reports not established here as fraudulent
These entries resemble patterns named in the warnings above. The available evidence does not establish them as fraud, so the behaviour pattern is recorded without applying that label to the party.
Swan Bitcoin is reported to have emailed customers on 31 July pausing withdrawals to wallets labelled as COLDCARD and asking recipients to reply to the email. The report describes a company protective measure. It is also, structurally, an unsolicited email about a wallet, sent during a crisis, that asks you to respond to it, which is the exact shape of the warning pattern published by the vendors above. The resemblance does not make the reported email fraudulent. R26
A law firm is running a page recruiting affected owners as potential claimants, published 31 July 2026 and first captured by this archive on 4 August. The page self-labels as advertising. Client solicitation after a mass loss event is legal marketing. It is separated here from the "recovery service" warning above, which concerns promises to reverse a completed spend. The captured page offers a possible legal claim against a counterparty, not retrieval of coins from the chain. V27
Around 2 August a recipient posted a screenshot of an email presented as a Trezor advisory and classified it as a phishing attempt. That classification is the recipient's, it has not been confirmed by Trezor, and this archive holds no capture of the message. Internal inconsistencies in the screenshot have been noted by others. This archive does not adjudicate it, and it is recorded here only so that it is not repeated as an established case. Two further Trezor-branded phishing reports, dated 4 and 5 August, are described above and are held as captures; this archive has not established whether the screenshot described here is one of them or a separate item, so it is kept recorded separately rather than merged into them. U28
Evidence on this page 28 items
- V1 Verified · contested
That Coinkite's own published guidance instructs owners to treat the situation as urgent, upgrade, generate a new seed and move funds
Source COLDCARD advisory and the 1 August migration appeal, as captured
Evidence → captured
- R2 Reported · contested
Lopp's 31 July forecast that phishing mail posing as Coinkite security notices would follow the disclosure
Source Jameson Lopp, posted 31 July 2026 at 14:59 UTC; a forecast, not a report of an event
Evidence → captured
- R3 Reported · contested
The existence and content of the Telegram impersonation screenshot above, and the interface details visible in it
Source Jameson Lopp published the screenshot on 1 August 2026 at 18:02 UTC. He does not say who received it and the recipient is redacted, so this is an artefact he published rather than an account of something he received. No vendor has confirmed or denied it
Evidence → captured 2 Aug 2026
- R4 Reported · contested
The r/coldcard reports of security-advisory email from the lookalike domains named, and the reported Ledger-branded mail in the same thread
Source BarAdministrative999 and commenters, r/coldcard, 3 August 2026, as captured; the sender addresses and the classification as phishing are the posters' own, and no message is held here
Evidence → captured 4 Aug 2026
- R5 Reported · contested
The existence and visible content of the COLDCARD desktop-app phishing screenshots, and the statement that no COLDCARD desktop application exists
Source americanhodl8's captured X post of 4 August 2026 with four attached screenshots, read off the held capture; the message itself is not held, the report of receiving it is his own, and Coinkite has not commented on it in any held capture
Evidence → captured 4 Aug 2026
- R6 Reported · contested
The existence and visible content of the screenshot presented as an email from Trezor's chief executive
Source BitcoinRothbard's captured X post of 4 August 2026, read off the held capture; the post text says only that he received it, the message is not held, and Trezor has neither confirmed nor denied this specific item in any held capture
Evidence → captured 4 Aug 2026
- R7 Reported · contested
That the Trezor incident email, as reproduced by a poster, states Trezor does not use Coldcard's firmware or code
Source Text of the Trezor email as reproduced in the captured r/Bitcoin thread; the reproduction is the poster's and the message itself is not held, while Trezor's captured posts of 4 and 5 August state the same not-affected scope in the vendor's own voice
Evidence → captured 7 Aug 2026
- R8 Reported · contested
The existence and visible content of the screenshot presented as a critical Trezor security bulletin, and the sending address named for it
Source jyn_urso's captured X post of 5 August 2026, read off the held capture; the address, the receipt and the classification are as published by the reporter, and the message is not held here
Evidence → captured 6 Aug 2026
- R9 Reported · contested
The commenter's report of receiving several scam emails branded as Trezor before the genuine one
Source Comment in the captured r/Bitcoin thread on Trezor's incident email; a single unverified account, held as a capture and not corroborated elsewhere in this archive
Evidence → captured 7 Aug 2026
- R10 Reported · contested
The report that a repository claiming to reproduce the vulnerable RNG pulled a dependency executing an infostealer
Source jrakibi's captured X post of 5 August 2026; the finding is the reporter's LLM-assisted review, is not verified here, and no independent confirmation is held
Evidence → captured 6 Aug 2026
- R11 Reported · contested
satsie's first-person account of starring and then unstarring the repository while researching the attack
Source satsie's captured X post of 5 August 2026, crediting jrakibi for the check; a first-person account, not verified here
Evidence → captured 6 Aug 2026
- R12 Reported · contested
Rob Hamilton's statement that he closed his direct messages because of impersonators posing as media and as victims
Source Rob1Ham's captured X post of 5 August 2026; his own account of messages he received, none of which is held here. He co-founded AnchorWatch and originated the Slipstream migration recommendation this record holds elsewhere
Evidence → captured 6 Aug 2026
- R13 Reported · contested
SoapMiner's first-person report of being scammed and the linked account whose handle closely resembles Rob Hamilton's
Source soapminer1's captured X post of 6 August 2026; the post does not state what was taken or by what means, and the linked account is not held as a capture here
Evidence → captured 6 Aug 2026
- R14 Reported · contested
Joe Carlasare's 3 August warning that a post preying on holder fears was fake
Source JoeCarlasare's captured X post of 3 August 2026 with one attached screenshot; the post text identifies neither the account nor the content it calls fake, and nothing else in this archive identifies it
Evidence → captured 4 Aug 2026
- R15 Reported · contested
Trezor's report of increased phishing attempts and its quoted safety guidance
Source Captured primary post from Trezor; the post provides no phishing message, count, channel breakdown or measurement method
Evidence → captured
- R16 Reported · contested
The first-person report of a 6.06 BTC loss through an impostor Wasabi app during migration
Source @lunymoon13's captured primary X post of 2 August 2026; no transaction identifier, app-listing artefact or independent confirmation is held
Evidence → captured
- V17 Verified · contested
Coinkite's 24 June 2026 statement about the paper campaign, including the never-a-paper-letter position, the 120-day address deletion and the no-breach finding
Source Coinkite, 'Paper spam attempts', published 24 June 2026, as captured
Evidence → captured 2 Aug 2026
- R18 Reported · contested
The first-hand reports and photographs of the June letter itself, its 30 June deadline, and the inference by some reporters that a Coinkite data leak explains the targeting
Source First-hand r/Bitcoin and r/coldcard reports with photographs, 20 and 29 June 2026, held as captures; Coinkite's response is held and denies a breach, and neither position is adopted
Evidence → captured 3 Aug 2026
- V19 Verified · contested
Coinkite's 7 August 2026 statement that automated 120-day blanking is temporarily suspended, and that customers wanting the standard policy applied should contact the support address
Source Coinkite, 'Update on Customer Data Retention', as captured; the displayed publication date moved from 6 to 7 August between two captures of the blog index
Evidence → captured 7 Aug 2026
- R20 Reported · contested
The generic pre-disclosure wallet-brand link warning
Source unthocks's captured r/Bitcoin post, published 22 July 2026, warns against messages claiming a hardware wallet is compromised; it is a community warning, not evidence of a COLDCARD-specific post-disclosure event
Evidence → captured
- V21 Verified · contested
That Blockstream, Foundation, Wizardsardine and Trezor published the scam guidance summarised below, on the dates shown
Source Held captures of each vendor's published statement; the guidance is predictive, while Trezor separately reports an increase in phishing attempts without publishing a specimen or count
Evidence → captured 5 Aug 2026
- R22 Reported · contested
KeychainX's statement that paid recovery of already-swept coins is a second scam, and its own commercial position
Source KeychainX reference page, as captured; KeychainX identifies itself on the page as a wallet-recovery firm that sells paid recovery, which bears on how the advice reads without making it wrong
Evidence → captured
- R23 Reported · contested
The community descriptions of a paid-recovery and identity-harvesting pattern in the captured loss thread
Source Comments dated 5 August 2026 in the captured r/Bitcoin thread on a 0.7 BTC loss; assertions by named posters about a pattern, with no instance evidenced, and not adopted here
Evidence → captured 6 Aug 2026
- U24 Unverified · contested
The assertion that swept funds can be clawed back
Source Comment by DeepAd8888 dated 6 August 2026 in the captured r/coldcard thread on device disposal; the comment gives no mechanism and nothing else in this archive supports or refutes it as of a 15 August 2026 recheck
Evidence → captured 6 Aug 2026
- V25 Verified · contested
That no scam, phishing or impersonation guidance appears in the held captures of the COLDCARD advisory as of 15 August 2026
Source Held captures and unchanged index polls of the advisory through 15 Aug 2026 searched for scam, phishing and impersonation text; the absence is of published text, and is not a claim about anything Coinkite may have communicated elsewhere
Evidence → captured 1 Aug 2026
- R26 Reported · contested
The reported Swan Bitcoin withdrawal-pause email
Source Stacker News thread quoting the email, captured 4 Aug 2026; the email text is the poster's exhibit and is not verified against Swan
Evidence → captured 4 Aug 2026
- V27 Verified · contested
The existence and stated content of the law firm's claimant page
Source Stoltmann Law claimant-intake page, published 31 Jul 2026, held as a capture
Evidence → captured 4 Aug 2026
- U28 Unverified · contested
The emailed Trezor advisory screenshot that a recipient classified as a phishing attempt
Source The specific phishing-classified screenshot is not held in this archive as of a 15 August 2026 recheck; a genuine Trezor incident email is captured separately at reddit-trezor-user-alert-email and Trezor's own posts state the same not-affected scope
Evidence → captured