# Fool Me Twice: How a $88.6M Bitcoin Theft Became the Perfect Phishing Bait


The first crime was the random number generation flaw that let attackers drain 1,367 Bitcoin — roughly $88.6 million — from 4,585 COLDCARD wallet addresses. The second crime started within days, and it's arguably more sophisticated: a phishing campaign that weaponizes anxious COLDCARD users' own security awareness to hand over complete remote control of their machines.


That's the double-tap Proofpoint exposed this week. And the mechanics of it deserve careful attention from anyone who thinks they're too sophisticated to fall for a phishing email.


## The Hook That Actually Works


Most phishing emails fail the smell test in the first sentence. This one doesn't — because it doesn't have to invent a threat. The threat is real, the Bitcoin is already gone, and COLDCARD users know it.


Emails land from compliance@coldcardteamnews.com with the subject line "Hardware audit now available," telling recipients that a coordinated security audit is underway across all hardware revisions and their participation is required. The emails are careful: they invoke the actual known vulnerability, they don't ask for a recovery seed, and they include a deadline (August 10) that creates urgency without triggering obvious alarm.


The language is corporate and clinical — it reads like something an actual compliance team would send in crisis mode. That's not an accident.


## Live Operators, Not Bots


The fake site coldcardcompliance.com impersonates COLDCARD's aesthetic and includes a "Customer Service" chat feature. Here's where the campaign steps up from commodity phishing to something more deliberate: Proofpoint believes real humans are staffing those chats.


When a target reported seeing an unexpected black window and an administrator prompt, an operator explained that the prompt was a necessary part of the installation process and encouraged them to click through. That level of responsiveness — interpreting a victim's specific confusion and countering it in real time — is not a chatbot. Someone is sitting there working shifts, talking anxious crypto holders into installing malware.


The cost structure of that decision tells you something about who is being targeted. You only burn human labor on live chat if the expected payout per successful compromise justifies it. COLDCARD users are, by definition, people who are serious enough about Bitcoin security to invest in hardware wallets. They likely have meaningful holdings. The math works.


## What the Batch File Actually Does


The "Start Hardware Audit" button downloads Coldcard_Diagnostic_Tool.bat from a GitHub account — 25.7MB, which is enormous for a batch file and should itself be a red flag. The size is explained by what's inside: two Base64-encoded payloads embedded directly in the script.


When executed, the batch file runs a convincing-looking fake diagnostic while doing the actual work in the background:


  • Checks for administrator privileges; if absent, relaunches itself via UAC prompt requesting elevation
  • Decodes both embedded payloads using Windows certutil into a randomly-named temp directory
  • Installs setup.msi — which is a ConnectWise ScreenConnect installer, not a diagnostic tool
  • Launches docusign.exe — a legitimately signed DocuSign printer driver executable, acting purely as visual cover
  • Displays "Installation Complete" and deletes the temp directory

  • The use of a legitimate, code-signed binary from DocuSign as a decoy is particularly sharp. It gives security tools something real to look at while the ScreenConnect installer — also legitimate software — does the actual damage. Neither binary is inherently malicious. The malice is in the assembly.


    ScreenConnect then phones home to activeretirementrelocation[.]com for command-and-control. Whoever is on the other end has full remote access to a machine that probably holds far more than a COLDCARD wallet password.


    ## The RMM-as-Malware Problem, Again


    ConnectWise ScreenConnect being abused as a backdoor is not new. Neither is TeamViewer, AnyDesk, or any other remote management tool. What these tools share is a fundamental design requirement: they must bypass many of the controls that would flag obvious malware, because that's how they do their legitimate job.


    Security teams have been wrestling with this for years. Blocking RMM tools entirely is operationally difficult for organizations that actually use them. Allowlisting specific C2 endpoints works only if you know the attacker's infrastructure in advance. Behavioral detection is improving but far from complete.


    The COLDCARD campaign is a reminder that attackers have fully internalized this gap. Why write a custom RAT when you can install a commercially licensed, digitally signed remote access tool that your victim's endpoint security has probably seen a hundred times?


    ## HackWire Analysis


    The timing of this campaign is the most important thing to understand, and most coverage is burying it.


    COLDCARD's vulnerability wasn't revealed to the public until after the theft was already complete. That means there was a window — probably very short — between public disclosure and the launch of this phishing campaign. Proofpoint's discovery suggests the attackers moved fast, almost certainly because they were waiting for exactly this moment.


    This is what threat intelligence people call second-order exploitation: the original vulnerability is the trigger event, but the real attack surface is the *human response* to that event. Security-conscious crypto holders, having just learned that a trusted hardware wallet may have been compromised, are in a psychologically primed state. They want someone to tell them what to do. A "security audit" email hits exactly that moment of receptivity.


    The pattern has precedent. After Colonial Pipeline, phishing campaigns targeting energy sector employees spiked within 72 hours. After the 2020 SolarWinds disclosure, fake remediation tools circulated. The playbook is: find a high-profile incident, identify the anxious audience it creates, and offer them what they want — which is certainty and a path forward.


    Defenders serving crypto-native communities or high-net-worth individuals should assume this is an ongoing tactic, not a one-off. The COLDCARD campaign may be finished by August 10, but the template will be reused against the next major wallet incident, the next exchange hack, or the next firmware disclosure. Blocking coldcardcompliance.com is the minimum; the real work is training users that legitimate security audits do not arrive via email with download links.


    One concrete step that matters right now: any organization advising crypto clients should issue guidance that no legitimate hardware wallet vendor will ever send an audit tool via email. Full stop. Frame it that clearly, before the next campaign exploits the same anxiety.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)