Coldcard investigates phishing link posted on its X account after exploit

Photo: Tima Miroshnichenko / Pexels

Coldcard investigates phishing link posted on its X account after exploit

The Bitcoin hardware wallet maker says no unauthorized logins were recorded and has asked X to look into how a fake firmware alert appeared on its feed

Coldcard, the Bitcoin hardware wallet built by Coinkite, is investigating a phishing post that appeared on its official X account. The post was dressed up as an urgent security warning.

The company told users not to visit or interact with the link. It also said it will share further updates only once they are verified.

What happened on Coldcard’s X feed

The fraudulent post showed up around 02:00 UTC on October 11, 2026. It claimed there was a critical issue with seed generation in recent Coldcard firmware.

The post pointed readers to a domain called migrate.coldcardwallet.io.

Coldcard says it ran an internal review after the post appeared. That review found no unauthorized access or logins on the account.

Advertisement

The company credits offline two-factor authentication, which it says it has used since 2017.

Coldcard has asked X for an urgent investigation. The company wants to know whether the platform itself or account credentials were compromised.

No verified user losses have been reported in connection with the post so far.

Why the timing matters

The phishing message did not reveal any new firmware vulnerability. Instead, it referenced a security issue that had already been disclosed earlier in 2026.

A major exploit in July and August 2026 drained over 1,700 BTC from affected devices, valued at approximately $100M to $130M.

Coldcard’s findings point to an awkward question. If the company recorded no unauthorized logins, how did the post get there? That is the part X has been asked to explain.

What this means for Bitcoin holders

For Coldcard users, the practical guidance is simple. Do not click the link, and do not move funds based on a social media post.

Legitimate firmware fixes do not require entering your seed phrase on a website. Any prompt to do so should be treated as a red flag, no matter which account it comes from.

For now, the key things to watch are X’s findings and any verified follow-up from Coldcard.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Coldcard investigates phishing link posted on its X account after exploit
Coldcard investigates phishing link posted on its X account after exploit

The Bitcoin hardware wallet maker says no unauthorized logins were recorded and has asked X to look into how a fake firmware alert appeared on its feed

Share

Add us on Google

Photo: Tima Miroshnichenko / Pexels

Coldcard, the Bitcoin hardware wallet built by Coinkite, is investigating a phishing post that appeared on its official X account. The post was dressed up as an urgent security warning.

The company told users not to visit or interact with the link. It also said it will share further updates only once they are verified.

What happened on Coldcard’s X feed

The fraudulent post showed up around 02:00 UTC on October 11, 2026. It claimed there was a critical issue with seed generation in recent Coldcard firmware.

The post pointed readers to a domain called migrate.coldcardwallet.io.

Coldcard says it ran an internal review after the post appeared. That review found no unauthorized access or logins on the account.

Advertisement

The company credits offline two-factor authentication, which it says it has used since 2017.

Coldcard has asked X for an urgent investigation. The company wants to know whether the platform itself or account credentials were compromised.

No verified user losses have been reported in connection with the post so far.

Why the timing matters

The phishing message did not reveal any new firmware vulnerability. Instead, it referenced a security issue that had already been disclosed earlier in 2026.

A major exploit in July and August 2026 drained over 1,700 BTC from affected devices, valued at approximately $100M to $130M.

Coldcard’s findings point to an awkward question. If the company recorded no unauthorized logins, how did the post get there? That is the part X has been asked to explain.

What this means for Bitcoin holders

For Coldcard users, the practical guidance is simple. Do not click the link, and do not move funds based on a social media post.

Legitimate firmware fixes do not require entering your seed phrase on a website. Any prompt to do so should be treated as a red flag, no matter which account it comes from.

For now, the key things to watch are X’s findings and any verified follow-up from Coldcard.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.