
Bitcoin hardware wallet manufacturer COLDCARD has launched an investigation after an unauthorized phishing message appeared on its official X account on October 11, directing users toward a fraudulent wallet security website before the company deleted the post.
Summary
- COLDCARD confirmed its official X account published a phishing link, which the company later deleted.
- The fake post reportedly claimed firmware vulnerabilities and directed Bitcoin holders toward fraudulent migration instructions.
- COLDCARD said it uses offline two factor authentication and restricted account access dating to 2017.
- The company contacted X after finding no matching login or session records, according to reports.
- No verified financial losses or confirmed explanation for the account incident have been publicly established.
COLDCARD confirmed the incident in a public statement, warning customers against opening the suspicious link or following its instructions. The company said its account had used offline two-factor authentication and restricted access since 2017, while investigators were examining how the post appeared. COLDCARD has contacted X and is reviewing account access records to establish what happened.
The manufacturer emphasized that its only official website is coldcard.com and said it would publish further information after verifying the findings.
COLDCARD warns users after fake Bitcoin security post
The suspicious message appeared on COLDCARD’s verified X account, which the company ordinarily uses to communicate security notices, firmware releases and product information.
According to reports published on October 11, the unauthorized post presented itself as an urgent warning about a supposed vulnerability affecting recovery phrase generation in newer wallet firmware. The message reportedly instructed customers to move their Bitcoin holdings through a security migration process and directed them to a website impersonating COLDCARD.
Security observers identified the link as a phishing attempt designed to persuade wallet owners to follow fraudulent instructions. The exact operation of the website, including whether it collected recovery phrases or distributed malicious software, has not been independently established.
The company subsequently deleted the post and issued a public warning against visiting the linked website. In its statement, COLDCARD said, “We are investigating how a post containing a phishing link was published from this account.” It instructed customers not to interact with the website while its security review continued.
The warning specifically concerns the unauthorized social media message. The company has not confirmed a new firmware vulnerability associated with the phishing post. COLDCARD has not disclosed how long the fraudulent message remained visible or how many users may have visited the website before its removal.
No verified reports establishing direct financial losses from the October 11 phishing attempt were identified in the reviewed sources.
COLDCARD questions how its X account was accessed
Following the removal of the phishing post, COLDCARD began examining its account security and contacted X for assistance.
The company said its official account has relied on offline two-factor authentication with tightly restricted access since 2017. In a subsequent message addressed to X Support, COLDCARD reportedly stated that it could not identify a login, session or access record corresponding to the unauthorized publication.
The manufacturer maintained that its credentials and offline authentication measures remained secure based on its initial review.
According to an October 11report by TechFlow, COLDCARD raised concerns about the possibility of unauthorized access involving X’s internal systems or administrative privileges. The company reportedly requested that X investigate the incident and preserve relevant access records.
However, a platform-level compromise remains a possibility raised by COLDCARD, not an established finding. There is no verified evidence identifying the individual or group responsible for publishing the message.
Reports concerning the incident referred to alleged advertisements offering X administrator accounts on underground marketplaces. COLDCARD did not establish any connection between those claims and the phishing post.
The manufacturer has not announced whether the investigation uncovered a compromised employee account, an abused integration or another method of unauthorized publication. X has not publicly confirmed a platform-level breach connected to the COLDCARD incident in the sources reviewed. The company said additional verified updates would be shared through its official communication channels.
Phishing warning follows COLDCARD’s earlier firmware security incident
The new phishing warning comes several months after COLDCARD disclosed a separate security issue involving how certain devices generated Bitcoin wallet recovery phrases. In July 2026, the manufacturer identified a firmware problem that had affected the randomness used to generate recovery information.
According to COLDCARD’s official security record, some previous firmware versions did not use the intended hardware randomness source when creating wallet seeds. The company released corrected firmware for supported devices and instructed affected customers to follow its official recovery and migration procedures.
Earlier reporting on the COLDCARD Bitcoin wallet security failure linked the weakness to cryptocurrency thefts involving wallets created with insufficiently random recovery information.
A separate analysis of the COLDCARD firmware vulnerability discussed estimated losses of approximately $116 million connected to the original security problem. Those historical estimates are separate from the October 11 phishing incident.
The manufacturer said its current recommended standard firmware versions are 5.6.3 for Mk4 and Mk5 devices and 1.5.3Q for the Q model. COLDCARD’s published documentation explains that installing corrected firmware does not automatically repair a recovery phrase generated using vulnerable older software. Customers with affected recovery phrases must follow the appropriate replacement process described in the official guidance.
The October phishing message reportedly used concerns about firmware security to encourage another wallet migration.
However, COLDCARD has not linked the social media incident to a new vulnerability in those corrected firmware releases. The distinction is important to the company’s official guidance: the earlier seed-generation issue was documented, while the October 11 message was identified as unauthorized and potentially malicious.
Earlier research found fake COLDCARD websites and support accounts
Independent researchers had documented attempts to impersonate COLDCARD after the original firmware problem became public.
On August 5, cybersecurity research group Unclone reported finding ten lookalike domains registered within five days of the July security disclosure. Its investigation examined impersonation activity across websites, social media accounts and customer support channels.
Researchers identified fraudulent websites using language similar to the company’s legitimate security advisory.
Some pages reportedly attempted to collect recovery information from users who believed they were following official instructions. Unclone examined 97 accounts using COLDCARD or Coinkite-related branding across social platforms.
Among them, 34 presented themselves as company support representatives or employees. The researchers found that several impersonation accounts had existed for years before adopting COLDCARD-related branding, allowing them to appear more established than newly created scam profiles.
One fraudulent support account had approximately 17,000 followers at the time of the investigation. The research identified attempts to contact users who had publicly discussed missing Bitcoin or wallet security problems.
In some cases, attackers reportedly presented fraudulent migration instructions as assistance for people responding to the original firmware warning. COLDCARD’s current official setup instructions state that recovery words and backup passwords must never be entered into another device or exposed through websites and support messages.
The manufacturer advises customers to verify firmware downloads and use the device’s own security procedures when generating or replacing wallet recovery information. Its October 11 statement reaffirmed that coldcard.com is the company’s only official website.
COLDCARD said it had contacted X and would continue reviewing account access while preparing further verified information about the unauthorized phishing post.


Leave feedback about this