Security Incident Overview
Bitcoin hardware wallet producer COLDCARD is currently probing a recent security incident wherein an unauthorized phishing communication was disseminated through its verified X account on October 11. This misleading message directed users to a fraudulent website regarding wallet security before it was subsequently removed by the company.
Company Response
In response, COLDCARD issued a cautionary notice, discouraging customers from engaging with the dubious link or adhering to the messages it contained, which purportedly claimed a vulnerability affecting the generation of recovery phrases in newer firmware.
COLDCARD stated that it has employed offline two-factor authentication and kept account access tightly regulated since 2017. An investigation is underway to ascertain how this unauthorized post appeared. The company has initiated contact with X to review access logs and analyze any security breaches. COLDCARD reiterated the importance of its official website, coldcard.com, and reassured users that any further developments will be shared once confirmed.
Phishing Message Details
The phishing message, which was presented as an urgent advisory on a potential flaw in the wallet’s software, instructed users to transfer their Bitcoin through a misleading security procedure, all while steering them to a fake COLDCARD site.
Cybersecurity experts quickly recognized the link as a phishing scheme aimed at tricking users into revealing sensitive information. As of now, it remains unclear if the rogue site was gathering recovery phrases or distributing harmful software. The company’s communication made it clear that it has not authenticated any new firmware vulnerabilities associated with this incident.
Financial Impact and Security Measures
Despite the concerns raised, independent sources have yet to confirm that users suffered financial losses due to the phishing attempt. Following the incident, COLDCARD began a thorough review of its account security while collaborating with X to ensure comprehensive analysis. Initial assessments suggested that there was no record of login activity that would account for the unauthorized posting, reinforcing COLDCARD’s confidence in its security measures.
Potential Internal Breach
On the same day as the post, COLDCARD expressed its worries regarding the potential for unauthorized access that could involve X’s internal systems, requesting that the platform conduct its investigation and safeguard pertinent access data. However, it is crucial to note that a platform-level breach remains a hypothesis rather than a substantiated finding, as the identity of those responsible for the phishing message remains unconfirmed and unverified.
Context of Vulnerabilities
Contextually, this warning arises months after COLDCARD acknowledged past vulnerabilities in its firmware that influenced the generation of Bitcoin wallet recovery phrases, which had previously been connected to significant security failings in the cryptocurrency space. In July, a problem was identified where certain devices failed to utilize an appropriate source of randomness for recovery information, leading to potential thefts amounting to approximately $116 million.
Though its current firmware, versions 5.6.3 for Mk4 and Mk5 models and 1.5.3Q for the Q model, are deemed secure, COLDCARD reminds users that simply installing new firmware does not rectify issues stemming from previous, flawed software. Users must implement the company’s prescribed recovery steps to address any vulnerabilities in their recovery phrases created by earlier firmware versions.
Call for Vigilance
In light of this recent phishing attempt, which exploited concerns about recovery phrase generation, COLDCARD emphasized the need for vigilance among users, instructing them to refrain from entering sensitive information on any unverified websites. Reports have indicated a rise in phishing attempts targeting COLDCARD users following earlier disclosures about vulnerabilities.
Cybersecurity group Unclone had uncovered several fraudulent domains mimicking COLDCARD shortly after the initial firmware issues were publicized, as attackers attempted to exploit user fears and misinformation. Therefore, COLDCARD stresses the importance of verifying the authenticity of all communications and strictly following its official channels to maintain security, reminding that their sole legitimate website is coldcard.com.