Blog

After Coldcard: phishing surge and how to migrate safely

After the July 2026 Coldcard entropy exploit, scammers ramped up fake audits and support chats. Here is how to migrate compromised seeds safely and spot the phishing wave.

WalletLab

By early August 2026, the Coldcard entropy story had a second act: phishing. Trezor, Foundation, and others warned that attackers were cloning brand sites, spoofing support emails, and walking victims through “hardware audits” that install remote-access malware or harvest seed phrases.

If you are migrating after the Coldcard advisory — or you simply hold hardware wallets and saw the headlines — this is the practical companion to our incident breakdown.

What the phishing looks like

Patterns reported after the disclosure:

  • Emails from spoofed Coldcard / vendor addresses urging a “coordinated hardware audit”
  • Cloned websites with live chat where a human coaches you to install remote-access tools
  • Messages impersonating Trezor, Foundation, Ledger, or Jade “security teams”
  • Urgency scripts: “move funds in 24 hours or they will be swept”

Legitimate vendors will not ask for your 12/24-word recovery phrase, seed QR, or PIN in chat, email, or DM. They will not send firmware as an email attachment.

Safe migration checklist

Use this if your Coldcard seed may be in the vulnerable generation window:

  1. Official advisory only — bookmark Coinkite’s security page; ignore forwarded PDFs.
  2. Update firmware from the vendor’s official site or documented GitHub release channel.
  3. New seed on fixed hardware — never reuse the old phrase on a “patched” device and assume you are done.
  4. Verify on the device screen — new receive address and wallet fingerprint before you trust a companion app.
  5. Test transaction first — small amount, confirm receipt, then move the rest in planned batches.
  6. Air-gap your process — do not type seeds into websites, Excel, password managers synced to the cloud, or “recovery helpers.”
  7. Watch the fee market — urgent migrations during a news spike can be expensive; plan batches if needed, but do not delay forever on a known-weak seed.

If you are leaving Coldcard for another bitcoin-only or multi-vendor setup, compare options in our Coldcard vs Jade Plus guide and the bitcoin-only picks.

Vendor “not affected” notes (context, not marketing)

After the exploit, Ledger, Trezor, Blockstream Jade, and Foundation published technical notes explaining why their seed-generation paths did not share Coldcard’s RNG fallback. Those statements are useful for reducing panic — they are not a reason to click a link in a DM that says “verify your Ledger after Coldcard.”

Cross-check any claim against the vendor’s own domain. When in doubt, navigate manually; do not follow the email.

Habits that survive the next advisory

  • Keep firmware current from official channels
  • Prefer clear signing / on-device review for every spend
  • Split large balances (multisig, or separate seeds for savings vs spending)
  • Practice a dry-run restore before you ever need an emergency migration
  • Use our hardware wallet safety checklist as a recurring review

Unsure which device fits after a scary week? Take the wallet finder quiz or browse best hardware wallets.

WalletLab take

Security incidents create two risks: the original flaw, and the social-engineering aftershock. Fix the seed. Ignore the fake audit. Move funds only through a process you control on hardware you trust.