Hardware wallet maker Coldcard is dealing with two incidents at once, and the second one is feeding on the first. Attackers first exploited a random-number-generation flaw across several Coldcard models and firmware versions to drain roughly 1,367 Bitcoin, worth about $88.6 million, from 4,585 addresses. Then, according to researchers at Proofpoint, a phishing campaign moved in behind it, sending emails from [email protected] under the subject line “Hardware audit now available,” telling recipients that the real incident now requires them to verify their device through a coordinated audit. The email links to a cloned site, coldcardcompliance.com, that walks victims into installing a remote access tool. Total phishing-related losses tied to the broader campaign are now approaching $130 million. Neither domain is coldcard.com, and that detail is the whole story.
The Attack in Plain Terms
The lure works because the premise is true. Coldcard really did suffer a security incident, so an email claiming a “coordinated hardware audit” lands on recipients primed to take it seriously rather than dismiss it as generic phishing noise. Clicking the audit link leads to coldcardcompliance.com, a convincing clone of the real site, complete with a “Start Hardware Audit” button and, notably, a live chat widget. Proofpoint assesses that the chat is staffed by real people, not a bot, who ask victims whether they run Windows or macOS and then talk hesitant users through downloading and running a GitHub-hosted batch file. That file installs ScreenConnect, a legitimate remote access tool abused here to hand attackers a live session on the victim’s machine, with everything that implies for stolen cryptocurrency, stolen data, or a ransomware deployment down the line.
Why DMARC Never Enters the Picture
This is the detail worth sitting with. DMARC protects a domain by telling receiving mail servers what to do with messages that fail SPF or DKIM alignment for that exact domain. It is domain-specific by design, and that design is correct: coldcard.com enforcing a strict DMARC policy does nothing to stop mail sent from coldcardteamnews.com, because that is a different domain entirely, one Coldcard does not own and has no authority to publish a policy for. Every authentication check a receiving server runs on that message passes cleanly, not because the attacker beat DMARC, but because DMARC was never asked the question. A domain owner can enforce p=reject perfectly and still watch a lookalike domain send convincing, fully “authenticated” phishing under a name close enough to pass a distracted glance.
The Blind Spot This Exposes
This is the same structural gap that has shown up behind lookalike-domain campaigns against password managers and maritime shipping firms in prior months, but the Coldcard case sharpens it, because the attackers did not need to invent a pretext. They borrowed one that was already true and already circulating in the news, which is exactly the kind of lure that survives security awareness training built around “does this sound too good to be true.” A real incident followed by a real-sounding remediation email is a harder pattern to flag than an unsolicited prize notification, and DMARC, SPF, and DKIM have nothing to say about a domain that was never theirs to protect in the first place.
Closing that gap requires a different toolset: monitoring domain registrations and certificate transparency logs for names that resemble your brand, watching for spikes in lookalike traffic during and immediately after any real incident, and treating post-incident communications as a specific, elevated-risk category that gets its own verification channel, not just an inbox notice.
What This Means for Your Program
Register and monitor lookalike variations of your primary domain, especially during and after any real security incident. Attackers watch for genuine news to weaponize, and the window between an incident disclosure and a matching phishing campaign is now measured in days, not weeks.
Set up domain and certificate transparency monitoring, not just DMARC aggregate reports. DMARC tells you who is sending mail claiming to be your exact domain. It tells you nothing about a domain that merely looks like yours, and that gap is exactly where campaigns like this one live.
Establish a verified, out-of-band channel for any post-incident communication before you need one. If customers cannot easily confirm that an “audit” or “remediation” request is genuine without clicking a link in the email itself, attackers will exploit that uncertainty every time you have real news to share.
Treat live chat widgets on look-alike sites as a specific red flag to include in user training. A staffed chat that pressures hesitant visitors is a strong signal of a targeted, well-resourced campaign, not a mass-blast scam, and it deserves specific mention alongside generic phishing warnings.
The Takeaway
DMARC did not fail here, because it was never in the fight. The phishing domain sat entirely outside what coldcard.com’s policy could ever reach, which is exactly why domain authentication has to be paired with active monitoring for the lookalikes sitting just outside its boundary. A brand’s real trust perimeter is bigger than the one DMARC alone can enforce, and attackers know it.
Excello Mail gives you continuous visibility into your DMARC enforcement and every source authorized to send under your domain, so you always know what your own authentication is actually protecting, and where its edges are. Sign up for free to Excello Mail and see exactly who is sending as you, all the time.