Newsroom
11 October, 2026 / News / AI / Tags: coldcard, firmware, phishing, official, post

Hardware wallet maker Coldcard is probing how a phishing link appeared on its verified X account Sunday, warning users to avoid the deleted post amid ongoing security reviews
Bitcoin-only hardware wallet manufacturer Coldcard confirmed that a phishing link was published from its official X account on October 11, 2026. The company deleted the post and launched an investigation into how it appeared, stressing that its account has relied on offline two-factor authentication and tightly restricted access since 2017.
Coldcard advised users not to visit or interact with the unauthorized link. The firm stated that its only official website is coldcard.com and said it has contacted X support while reviewing all account access records. Initial checks found no corresponding login, session, or access entries matching the post.
The message on the verified account presented itself as an urgent security notice. It reportedly referenced concerns about firmware vulnerabilities affecting recovery phrase generation and directed users toward a website that impersonated Coldcard with fraudulent wallet migration instructions.
Security researchers identified the link as a phishing attempt. Coldcard has not confirmed any new firmware vulnerability tied to the post and has not disclosed how long the message remained visible or how many users may have clicked through before removal. No verified reports of financial losses directly resulting from this specific incident have emerged.
Based on the absence of matching access records and the security of its credentials and offline authentication, Coldcard has raised the possibility of unauthorized access involving X platform systems or administrative privileges. The company requested that X investigate and preserve relevant records. No confirmed explanation for the post has been established, and X has not publicly confirmed any platform-level issue connected to the event.
The phishing warning arrives months after Coldcard disclosed a firmware issue in July 2026. Certain previous firmware versions failed to use the intended hardware randomness source when generating wallet recovery seeds. The company released corrected firmware and instructed affected users to follow official recovery procedures.
That earlier problem contributed to significant thefts. Galaxy Digital reported that at least $100 million in Bitcoin was stolen from approximately 7,300 wallets across three confirmed attack waves, with a suspected fourth wave that could raise the total to about $130 million. Separate tracking estimated losses tied to the Coldcard exploit at $115 million.
July 2026 ranked as the second-worst month for cryptocurrency thefts that year, with $247.4 million stolen overall, trailing only the $644 million recorded in April. The Coldcard-related activity accounted for the largest share of the July losses.
Current recommended firmware versions are 5.6.3 for Mk4 and Mk5 devices and 1.5.3Q for the Q model. Installing updated firmware does not automatically fix recovery phrases generated under vulnerable older software; users must complete the official replacement process.
Following the July disclosure, independent researchers documented multiple attempts to impersonate Coldcard. One investigation identified ten lookalike domains registered within days of the announcement, along with numerous social media and support accounts using related branding. Some fraudulent support profiles had existed for years before adopting Coldcard-related identities and had accumulated substantial followings.
Attackers have previously contacted users discussing wallet issues and offered migration guidance that sought recovery information. Coldcard’s official guidance continues to stress that recovery words and backup passwords must never be entered into other devices or shared through websites or support messages. Users are directed to verify firmware downloads exclusively through official channels and to rely on the device’s built-in security procedures.
Coldcard has pledged to share further verified updates through its official channels as the review of the X account incident continues.









