COLDCARD vulnerability what happened, and what to do
Informational only, and this site never asks for your recovery words. details

Informational only. This is independent analysis and an evidence-backed explainer, not financial, security or legal advice, and not a substitute for professional advice about your own situation. It is not affiliated with, endorsed by, or speaking for Coinkite, Block, or any other party named here. Published estimates are attributed, and differing scenarios are kept separate with their assumptions. Act on your own judgement. Editorial standards and corrections.

Do not disclose recovery material to a website, form, message or support account. This site never asks for it. Deliberate recovery on independently verified offline equipment is a separate operation. Seed-word safety.

Plain language Updated 2 Aug 2026

Scams exploiting this incident

The remediation instruction and the scam script are the same sentence. That is what makes this incident unusually easy to exploit, and it is why the usual advice to slow down conflicts with the vendor's instruction to hurry.

No code. Written to be actionable.

Why this incident is unusually easy to exploit

On 1 August Coinkite wrote: "Please treat this as urgent. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds." That is correct, and it is also, word for word, the pretext a phisher would otherwise have had to invent.

A scam usually has to manufacture a reason for you to act. Here the vendor supplied one, said it was urgent, and asked readers to spread it to people who are less online. Every element a fraudulent message needs is now legitimate background: your funds may genuinely be at risk, you may genuinely need to install firmware, you may genuinely need to move coins today, and a stranger may genuinely be trying to warn you.

The consequence is that the standard defence, slow down and verify before acting, is in direct tension with the instruction you have just been given by the party who is right about the risk. Both can be true. The way through is not to decide whether to hurry, but to hold two rules that survive being hurried: firmware comes only from the vendor download page you reached yourself, and nobody legitimate needs your recovery words.

What is documented

Two artefacts, both dated after the disclosure, both held. Everything else on this page is either anticipated, or belongs to an earlier campaign. The distinction is the whole point of the page and is kept visible in every section heading.

A dated prediction, then a dated artefact

On 31 July at about 14:59 UTC, Jameson Lopp wrote that it was "only a matter of time" before phishing mail claiming to be Coinkite security notices went out, trying to get readers to enter a recovery phrase into a malicious site. On 1 August at 18:02 UTC he quote-tweeted that post with a screenshot and the caption "The scammers have updated their playbooks."

The pair is the cleanest narrative unit available here, and it is worth stating why it is presented as a pair rather than as one story. The prediction is a warning and nothing more. The screenshot is an artefact. Read together they show a forecast followed by evidence, and they model the labelling this page applies to everything else: a warning published on 31 July does not become an event because something arrived on 1 August.

A Telegram account impersonating COLDCARD

The screenshot Lopp published shows a Telegram conversation opened by an account whose display name is "COLDCARD WALLET". The message is dated August 1 at 03:38 and reads, with the recipient's name blacked out: "Hello [redacted] Checking out on our database got you were one of our first users", followed by "I hope youre got an update about the hardware, I hope you were able to transfer your funds safely".

Telegram conversation screenshot. The header shows a contact named COLDCARD WALLET with a blue check mark, above buttons reading ADD CONTACT and BLOCK USER, and a line explaining that the blue mark is a mark for Premium subscribers. A contact card below reads COLDCARD WALLET, Not a contact, Phone number United States, Registration March 2026, and a warning reading Not an official account. Under a date divider reading August 1, one message at 03:38 reads: Hello, followed by a blacked-out name, Checking out on our database got you were one of our first users. I hope youre got an update about the hardware, I hope you were able to transfer your funds safely.
Reported by Jameson Lopp on 1 August 2026. A Telegram account using the display name "COLDCARD WALLET" messages a recipient about the incident. Telegram's own contact panel is visible above the message: the account is marked "Not a contact" and "Not an official account", the phone number is registered in the United States, the account was registered in March 2026, and the blue mark beside the name is labelled by Telegram itself as "a mark for Premium subscribers". The recipient's name is redacted in the image as published.
What makes this message hard to catch

It asks for nothing. There is no link, no attachment, no request for a recovery phrase, no form. It opens a conversation and waits. That is considerably harder to pattern-match than a seed prompt, and it defeats the advice most owners have actually internalised, because "never type your seed" cannot fire against a message that has not asked for one. Whatever the request turns out to be, it arrives later, after the account has been treated as a correspondent rather than as a stranger.

The blue mark is not verification. Telegram's own panel, visible in the same screenshot, explains that the mark denotes a Premium subscriber, which is a paid feature. In the same panel Telegram separately flags the account as "Not an official account". The platform is contradicting the impression the display name creates, in the same view, and the contradiction is easy to scroll past.

The pretext is the vendor's own. "I hope you were able to transfer your funds safely" is a paraphrase of the advisory. An owner who read the advisory has already had this thought.

What belongs to an earlier campaign, and is dated accordingly

Two items name Coinkite or COLDCARD, circulate widely, and predate this incident. They carry the highest misinformation risk on this page, because recirculating them as evidence of post-disclosure phishing is a date error that would be very easy to make in good faith.

The June 2026 paper campaign

Around 23 June 2026 a physical letter impersonating Coinkite was reported first-hand with a photograph. The letter used a post-quantum firmware-upgrade pretext and carried a 30 June deadline. On 24 June Coinkite published a response, "Paper spam attempts", which states that Coinkite would never send a paper letter, that the mail is a scam to steal coins, that Coinkite deletes customer data including physical addresses after 120 days, and that it uses no external customer-relationship tooling. Coinkite attributes the targeting data to aggregated leaks from other companies and says an audit of its own servers found no reason to suspect a breach. Some people reporting the letters inferred a Coinkite data leak. Coinkite denies a breach. Both positions are recorded here and neither is adopted.

This is a separate event, five weeks before the entropy disclosure. Presenting the June letter as post-disclosure phishing is a date error. As of 2 August 2026 this archive has found no evidence of a fresh letter wave posted after 30 July, and the postal lag discussed under risk 7 below means an absence of reports this week would not settle the question either way.

The generic "do not open links from wallet brands" warning

A general warning about links in messages purporting to come from wallet brands has circulated since about 22 July 2026. No artefact of it and no attribution for it are held here, it predates the 30 July disclosure, and it is not specific to this incident. It is recorded so that its recirculation is not mistaken for a report of something new.

What vendors warned about, which is not the same as what happened

On 31 July and 1 August, three vendors of competing hardware or software published scam guidance alongside their statements about this incident. Everything in this section is a warning. None of it is a report that the described thing occurred, and none of it should be cited as one.

Blockstream

capture →

Jade, published 31 July 2026

  • Any email carrying a firmware update is hostile, whoever the sender appears to be.
  • Never type your recovery phrase into a website, form, or "checker" tool.
  • We will never DM you first, and we will never ask for your recovery phrase.
  • Scams need you to act before you check.

Foundation

capture →

Passport, published 31 July 2026

  • Pressure to act quickly, and anyone saying your funds are at risk and they can help.
  • Offers of a "recovery service".
  • Requests to verify a seed somewhere.
  • People claiming to be Foundation or Coinkite staff.
  • Requests to share your screen or install remote-access software.
  • Search results and sponsored links for wallet software.

Wizardsardine

capture →

Liana, published 1 August 2026

  • Scams "will multiply in the coming days".
  • Do not install software found in a hurry, and do not buy a device from an unknown seller.
  • Never act on an unprompted direct message offering help.
  • Expect fake "recovery services" offering to get stolen coins back for a fee.

Foundation's enumeration is the most complete of the three, and the only one that names impersonation of Coinkite staff by a competitor's support channel as a thing its own users should expect. Blockstream's is the only one that treats emailed firmware as categorically hostile rather than as something to check. Wizardsardine's is written in the predictive tense throughout: scams "will multiply", and readers should "expect" fake recovery services.

A commercial interest worth stating plainly

KeychainX, a paid wallet-recovery firm, warns on its incident page that any service promising to recover already-swept Bitcoin for a fee is "a second scam aimed at people already harmed by the first". The warning is sound and matches what other parties say. It is also published by a company that sells paid recovery, and the page says so. The distinction it draws is between recovering a lost key and reversing a completed spend, which cannot be done by anyone. That commercial context is stated here because it bears on how the advice reads, not because it makes the advice wrong.

Ranked by risk, given the shape of this incident

Ordered by how well each vector fits this specific incident, not by how common it is in general. The ranking is this archive's judgement from the incident's structure and the held record, and the status column keeps observed and anticipated apart.

1

Firmware-update email or message carrying a download link

Anticipated. No artefact of a fake COLDCARD firmware build or download page is held here.

This is the one vector that defeats the standard heuristic outright. The lure is "install this", not "type your words", so a reader who has correctly learned never to enter a recovery phrase has no rule that fires. The vendor has told everyone to update, so an update instruction is expected rather than suspicious.

Firmware comes from the vendor download page reached by a link you already had, and is checked against the vendor's documented signature or hash process. Blockstream is the only party in the held record to name this class squarely.

2

Impersonated support on Telegram, X, Discord or email

Documented. One artefact, published 1 August 2026.

Observed, and structurally favoured twice over. Coinkite runs a real Telegram group, so the channel itself is plausible rather than absurd. And because Coinkite deletes customer physical addresses after 120 days, it genuinely cannot reach most owners directly, so there is no legitimate outreach against which a fake can be compared.

Treat any unsolicited approach about your wallet as hostile regardless of display name, badge or profile picture. Platform badges are not identity checks.

3

"Am I affected?" checker tools

Anticipated, and named by Blockstream and Foundation. No malicious checker is held here.

The question that defines this incident for an owner has no easy self-service answer, and that gap is exactly what a malicious checker fills. A reader who cannot resolve their own exposure will look for something that resolves it for them.

Affectedness is answerable from the firmware version and the generation method alone. Any tool that asks for a recovery phrase, an extended private key or an extended public key to answer it is hostile by construction, whatever its author intended.

4

Emergency migration assistance or screen sharing

Anticipated.

The vendor has instructed owners to move funds under time pressure, and moving funds is the part of the operation people are least practised at. An offer to walk you through it lands on a real need.

Remote-access and screen-sharing software has no role in a migration. Foundation names both explicitly.

5

"Recovery services" for wallets already drained

Anticipated. Named by Foundation, Wizardsardine and KeychainX.

A swept wallet cannot be unswept, which makes the promise unfalsifiable at the moment of sale and the target maximally motivated.

An on-chain spend does not reverse. Fees paid to recover it buy nothing.

6

Search advertisements and sponsored links for firmware downloads

Anticipated. Named by Foundation.

Search demand for the download page spiked with the advisory, and paid placement sits above the result people wanted.

Reach the download page from a link you already held, or by typing the address, and check it before downloading.

7

Physical mail

Anticipated for this wave. The June campaign is documented and is a separate event.

A proven playbook already exists against this customer population: a paper campaign impersonating Coinkite ran in June 2026 with a firmware-upgrade pretext, and Coinkite responded to it publicly. Postal lag matters for how this page should be read. A wave posted during the week of the disclosure would not begin arriving until the middle of August.

Coinkite states it would never send a paper letter. That statement predates this incident and still applies.

The one rule that settles risk 3

Whether this incident affects you is answerable from two facts: the firmware version installed when the seed was generated, and how the seed was created. Neither is secret, and neither is a recovery phrase. It follows that any checker asking for a recovery phrase, a private key or an extended private key is hostile by construction, because it is asking for material that cannot contribute to the answer.

An extended public key does not grant spending authority by itself, but it exposes wallet structure, balances and history to whoever receives it, so submitting one to an unknown site has a privacy cost even when the site is honest. The triage on the front page asks only the category questions, and the source of every tool this archive has examined is catalogued on code published around this incident.

An absence in the vendor response

As of 2 August 2026, Coinkite has published no scam or phishing guidance alongside the entropy advisory, and the advisory itself contains no text about impersonation, checker tools or which contact channels are official. This is stated as an absence observed in the held captures, and it is worth recording precisely because Coinkite demonstrably publishes this kind of guidance: it did so on 24 June, in detail, for the paper campaign. No motive is attributed here, the advisory has been revised repeatedly since 30 July, and this is a statement about what the held captures contain on a given date rather than a characterisation of the vendor's conduct.

Legitimate activity that resembles a scam

Three things reported during this week look like fraud patterns and, on the evidence held, are not fraud. They are named here so that a reader primed by everything above does not report a legitimate party, and so that the pattern itself can be described without accusing anybody. In each case the behaviour pattern is the subject, not the party.

Swan Bitcoin's withdrawal-pause email

Swan Bitcoin is reported to have emailed customers on 31 July pausing withdrawals to wallets labelled as COLDCARD and asking recipients to reply to the email. That is a legitimate company taking a protective measure. It is also, structurally, an unsolicited email about your wallet, sent during a crisis, that asks you to respond to it, which is the exact shape of the thing this page tells you to distrust. Both readings are correct at once. The safe response to any message of this shape, legitimate or not, is to reach the company through a channel you already had rather than by replying.

A law firm's victim-acquisition page

A law firm is reported to be running a page recruiting affected owners as potential claimants. The page self-labels as advertising. Client solicitation after a mass loss event is ordinary legal marketing and is not a scam. It is separated here from the "recovery service" pattern at risk 5, which promises to reverse a completed spend. A legal claim against a counterparty and a promise to retrieve coins from the chain are different offers, and only the second is impossible.

An emailed "Trezor Advisory" screenshot

Around 2 August a recipient posted a screenshot of an email presented as a Trezor advisory and classified it as a phishing attempt. That classification is the recipient's, it has not been confirmed by Trezor, and this archive holds no capture of the message. Internal inconsistencies in the screenshot have been noted by others. This archive does not adjudicate it, and it is recorded here only so that it is not repeated as an established case.

What to do with all of this

The two rules below are the ones that survive being in a hurry, which is the condition the vendor has asked you to be in. Everything else on this page is context for why they matter more this week than usual.

  • Firmware comes from the vendor download page you reached yourself, by a link you already held or by typing the address, and is checked with the vendor's documented signature or hash process. Not from an email, a message, a search advertisement or a helpful stranger.
  • Nobody legitimate needs your recovery words, and no checker needs them to answer whether you are affected. Deliberate entry into an offline signer you chose and verified yourself is a different operation, set out on seed-word safety.

If a message reaches you that fits any pattern above, the useful response is not to argue with it. Close it, and reach the company through a channel you already had. If you have already disclosed recovery material, the ordered steps are on seed-word safety, and the migration guidance is on moving funds from an affected seed.

Next: Protecting seed words during incident response what exposure assessment actually requires, and what to do after an unsafe disclosure

Evidence and calculations are scoped beside the claims they support. Device-state attack-cost scenarios are compared in what an attack costs, with each source's assumptions written out. Where sources disagree, their scenarios are kept separate. If something here is wrong, say so.