Approximately 1,367 Bitcoin — worth an estimated $88.6 million — was removed from 4,585 addresses in a theft tied to a suspected random-number generation flaw in COLDCARD devices. That loss has become the lever for a follow-on phishing campaign that tricks worried owners into installing remote-access software on their Windows machines.
coldcardcompliance.com and the fake audit email
Proofpoint says the campaign uses emails sent from compliance@coldcardteamnews.com with the subject line "Hardware audit now available" and text that purports to notify recipients of "a coordinated security audit now underway across the COLDCARD device network." The message tells users that "recent findings have prompted us to verify the integrity of hardware across all revisions, and your participation is needed," and directs recipients to a supposed "Security Verification & Incident Reporting Tool" that it claims is air-gapped and will not ask for a recovery seed.
Clicking the "Access the Audit Tool" button takes recipients to coldcardcompliance.com, a site impersonating COLDCARD and presenting a "Start Hardware Audit" button to download the tool. The fake site also offers a live "Customer Service" chat feature that Proofpoint observed being used to shepherd targets through the installation.
How the Coldcard_Diagnostic_Tool.bat works
Proofpoint reported that the site downloads a batch file named Coldcard_Diagnostic_Tool.bat from a GitHub account. BleepingComputer analyzed a 25.7MB copy of that batch file and found two Base64-encoded files embedded inside it. When run, the script pretends to perform a diagnostic check but actually checks for administrator privileges and, if needed, uses PowerShell to relaunch itself with a User Account Control prompt to request elevation.
The script writes the decoded files to a randomly named directory in the Windows temp folder as setup.msi and docusign.exe, using Windows certutil to decode them. After installing setup.msi it launches docusign.exe, displays an "Installation Complete" message, and deletes the temporary directory — leaving the attacker’s components in place while presenting a benign-looking outcome to the user.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadScreenConnect installer and the activeretirementrelocation[.]com C2
BleepingComputer and Proofpoint say the setup.msi embedded in the script is not a diagnostic tool but a ConnectWise ScreenConnect installer — a remote management package that, in the attackers' hands, provides direct remote access to an infected machine. Proofpoint observed the installed ScreenConnect client connecting out to activeretirementrelocation[.]com, which the company identified as the ScreenConnect command-and-control server used by the threat actor.
The second embedded file, docusign.exe, is a legitimately signed executable that installs a DocuSign printer driver and acts as a decoy during the attack while ScreenConnect furnishes remote control. Once the attacker is connected via ScreenConnect, Proofpoint warned they could "remotely access the computer, steal data or cryptocurrency, or install additional malware," and that such access could also be used to deploy ransomware.
What Proofpoint’s chat transcripts reveal about the operation
Proofpoint shared chat transcripts in which the site operator asks targets whether they use Windows or macOS and then instructs Windows users to run the downloaded tool. When a user reported seeing a black window and a UAC prompt, the operator explained the prompt was required to begin installation and told them to click "Yes." Proofpoint believes those conversations are likely handled by real people, not an automated chatbot, enabling attackers to answer questions and pressure hesitant victims into proceeding.
What this means for COLDCARD users, security teams, and service providers
- COLDCARD users: owners who are aware of the recently disclosed device vulnerability and the 1,367 Bitcoin loss are the explicit targets of this campaign; the emails and the coldcardcompliance.com site claim the process is air-gapped and will not request recovery seeds to encourage compliance.
- Security teams and incident responders: Proofpoint’s findings tie the attack to a specific GitHub-hosted Coldcard_Diagnostic_Tool.bat, a ScreenConnect installer (setup.msi), and the activeretirementrelocation[.]com C2 — concrete artifacts observers can use to hunt for related activity and alerts in telemetry.
- Service providers and platform owners: the campaign leverages a downloadable artifact hosted on GitHub and a signed executable used as a decoy. Those platform connections and the ConnectWise ScreenConnect channel are the junctions where defenders and administrators will likely focus containment and remediation efforts.
The campaign converts a publicly discussed hardware vulnerability and a high‑profile cryptocurrency theft into a social-engineering vector that trades on fear. Proofpoint’s analysis stitches together the email sender, the impersonating website, the Coldcard_Diagnostic_Tool.bat mechanics, and the ScreenConnect connection to activeretirementrelocation[.]com — a tidy chain of evidence that also raises immediate operational questions about the repository and C2 infrastructure supporting the attack.
Original story: https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-attack-installs-remote-access-tool/




