If you own a COLDCARD hardware wallet and got an email about a mandatory "security audit" of your device, with a deadline and a tool to download, stop. That email is a scam, and the "audit tool" it wants you to run quietly hands a stranger remote control of your computer, and access to your crypto.
The attackers are exploiting real fear. A genuine flaw in some COLDCARD wallets was recently tied to a roughly $88.6 million Bitcoin theft, so an urgent "we need to verify your device" message feels plausible. That is exactly why this crypto wallet phishing campaign works. Here is how it unfolds, and the one step that stops it before anything reaches your machine.
Key takeaways
A phishing campaign impersonates COLDCARD with fake "security audit" emails, exploiting fear from a real Bitcoin theft to pressure wallet owners into acting.
The email links to a fake COLDCARD website that tells you to download a "hardware audit tool." That tool is malware.
The download installs ConnectWise ScreenConnect, a real remote-access tool, giving the attacker control of your computer to steal crypto and data or deploy ransomware.
The fake site even has a live chat with real operators who walk you through running the file and clicking "Yes" on the security prompt.
The reliable defense is at the page and the download: don't trust a fake COLDCARD site, and know what a file is before it runs. Haven flags the fake site and pauses the download so you can decide.
What the scam looks like
Security researchers at Proofpoint uncovered the campaign, reported by BleepingComputer. The emails come from a lookalike address (compliance@coldcardteamnews.com) with a subject like "Hardware audit now available." The message claims a coordinated security audit is underway across all COLDCARD devices and that your participation is required, with a hard deadline.
It is carefully written to lower your guard. It says the process is "air-gapped" and promises it will never ask for your recovery seed, the exact reassurance a careful crypto user wants to hear. Then it points you to an "Access the Audit Tool" button.
That button opens a fake COLDCARD website (coldcardcompliance.com) that looks like the real thing and tells you to click "Start Hardware Audit" to download the tool. The site even includes a live "Customer Service" chat. Researchers believe real people, not a bot, staff it, asking whether you are on Windows or Mac and coaching hesitant victims through each step, including telling them to click "Yes" on the Windows security prompt that appears.
What actually happens if you run it
The "Start Hardware Audit" button downloads a file named Coldcard_Diagnostic_Tool.bat. It is not a diagnostic tool.
When you run it, it puts on a show, pretending to scan your device, while in the background it checks whether it has administrator rights. If it does not, it uses a Windows security prompt to ask for them (this is the "click Yes" step the chat operator pushes you through). Once it has permission, it quietly unpacks two hidden files: a decoy (a real, signed DocuSign printer driver that makes things look legitimate) and the actual payload, an installer for ConnectWise ScreenConnect.
ScreenConnect is a genuine remote-management tool that IT teams use to operate computers from afar. In the attacker's hands, it becomes a back door. Once it is installed and phoning home to their server, they can remotely control your computer, browse your files, drain your cryptocurrency, install more malware, or deploy ransomware. You see an "Installation Complete" message and think the audit is done. It is not. A stranger now has the keys.
The cruel twist: the email promised it would never ask for your recovery seed, and technically it does not. It does not need to. With remote control of your machine, the attacker can take what they want directly.
Why crypto users are the perfect target
Hardware-wallet owners are careful people, which is what the attackers weaponize. A message about a device security audit, arriving right after a real, headline-making wallet theft, hits exactly the right nerve. The promise that it will not ask for your seed phrase is designed to satisfy the one rule every crypto user knows, so you let your guard down on everything else.
And the payoff is high. Unlike a stolen password you can reset, stolen cryptocurrency is usually gone for good. That is why attackers are willing to staff a live chat with real operators to personally talk victims through the install.
The moment that matters: the fake page and the download
However convincing the email and the live chat are, the whole scheme depends on two things: getting you onto a fake COLDCARD page, and getting you to download and run a file from it. A real hardware-wallet company does not run mandatory "audits" that require installing a diagnostic tool on your computer, and its real site is its official domain, not a lookalike like coldcardcompliance.com.
The problem is that a lookalike domain is easy to miss when the branding is perfect, a countdown is ticking, and a helpful "support agent" is reassuring you in a chat window. That is the moment a browser-security layer is built for.
How Haven helps
This is the kind of scam Haven is designed for, and it helps at the two moments that matter.
First, Haven flags the fake site for you. It analyzes the actual page in front of you, not just how it looks or how you got there, so when a page imitates COLDCARD on a lookalike or unverified domain, Haven warns you that it is not the real, verified site, before you click download.
Second, on unverified sites, Haven pauses downloads so you can see what is about to land on your device. Instead of "Coldcard_Diagnostic_Tool.bat" quietly saving and running, you get a moment to see what it actually is and decide, rather than discovering later that it installed remote-access software.
To be clear about scope: Haven works in your browser, at the page and the download. It flags fake and unverified sites and pauses downloads there. It is not antivirus, and it does not scan a file's contents, block the ScreenConnect install once it starts, or remove software that is already on your machine. Its job is to stop you from reaching that point, by catching the fake page and giving you a beat before anything lands. If you are unsure about a link in an email, you can also paste it into Haven's free link checker.
How to protect yourself and your crypto
A few habits shut this down:
Treat any unsolicited "security audit," "device verification," or "urgent action required" message about your wallet as a scam until proven otherwise.
Never download a "diagnostic" or "audit" tool for a hardware wallet. Legitimate hardware wallets do not require you to install software on your computer to "verify" the device.
Go to the vendor's real website by typing the address yourself or using a bookmark, and confirm any claimed advisory there. Do not use the link in the email.
Never click "Yes" on a Windows security (UAC) prompt for a program you were told to run by a stranger, including a chat "support agent."
Never enter your recovery seed anywhere, and remember that malware can steal crypto without ever asking for it.
If you already ran a tool like this, disconnect the computer from the internet, move your crypto to a new wallet from a separate clean device, and get help from a trusted professional. Assume the machine is compromised.
The brand and the excuse will change, a wallet audit today, an exchange verification tomorrow. The move underneath stays the same: borrow a trusted name, manufacture urgency, and get you onto a fake page and a bad download. Slow down at the page and the download, and it falls apart.
About Haven
Haven is a browser extension that helps you make safer trust decisions online, before a scam can cost you anything. It works at the moment you are about to click a link, enter your password, or download a file, flagging fake and impersonated login pages, suspicious links, and lookalike sites, and pausing downloads on unverified sites so you can see what is about to land on your device. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of you, so it can catch brand-new and convincing fakes that other tools miss.
Haven is free for individual use. For teams, Haven Business and Have Managed extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.

