Coldcard investigates phishing link posted from its official X account
Coldcard is investigating how a post directing users to a fake migration site appeared on its official X account, despite maintaining offline two-factor authentication since 2017.

Hardware wallet maker Coldcard is investigating after a phishing link was published from its official X account, urging users not to interact with the fraudulent message. The post, which has since been deleted, impersonated an urgent security update warning of a critical seed generation vulnerability in newer firmware and directed users to a fake migration domain. Coldcard reminded users that its only official website is coldcard.com.[1][2][4][6]
According to Coldcard, the account has used offline two-factor authentication with tightly restricted access since 2017. The company stated that its credentials and 2FA remain secure and that no unauthorized logins were detected. Coldcard said it contacted X, is reviewing all account access, and plans to share verified updates as the investigation continues.[2][3][4][6]
The incident follows earlier security challenges for the wallet maker. According to Galaxy Research, a Coldcard firmware flaw led to the theft of 1,789 BTC from user wallets starting July 30, an incident commentators Lark Davis and Crypto Banter noted resulted in roughly $100 million in stolen Bitcoin.[2][4][5]
Key facts
- Coldcard deleted a phishing post published from its official X account that impersonated an urgent security update about a seed vulnerability.
- Coldcard warned users not to visit the link and affirmed that coldcard.com is its only official website.
- Coldcard stated that its X account has used offline 2FA with tightly restricted access since 2017.
- The company reported its credentials and 2FA remain secure, with no unauthorized logins detected.
- Coldcard contacted X and is reviewing all account access.
- Galaxy Research reported that a prior Coldcard firmware flaw led to the theft of 1,789 BTC from user wallets starting July 30.
Sources · 6 sources
- CT
Coin TelegraphArticle ·
Coldcard says it’s investigating how phishing link appeared on its X account Company advised users not to visit or interact with the link in question and said it will share any further verified updates.
Open source - CB
Coin Bureau@coinbureauPost on X ·
🚨JUST IN: COLDCARD says a phishing link was posted from its official X account despite offline 2FA with tightly restricted access since 2017. The deleted post posed as an “URGENT COLDCARD SECURITY UPDATE” urging users with affected seeds to “begin a careful migration now.” COLDCARD says it has contacted X and is reviewing all account access. Previously, a COLDCARD firmware flaw led to the theft of 1,789 BTC from user wallets starting July 30, per Galaxy Research.
Open source - BC
Bitcoin.com News@BitcoinNewsPost on X ·
🚨 JUST IN: Coldcard's official X account pushed a phishing scam disguised as an urgent wallet security warning. The company says its credentials and 2FA remain secure, with no unauthorized logins detected, raising fresh questions about how the fraudulent post got through. https://t.co/TrTcKUQUtl
Open source - LD
Lark Davis@LarkDavisPost on X ·
WARNING: COLDCARDwallet confirmed a phishing post was published from their official account (now deleted). It impersonated an urgent security update about a new seed vulnerability and directed users to a fake migration site. This comes on the heels of the entropy bug earlier this year that led to over $100M in Bitcoin being stolen. Stay safe. Always verify independently. Never enter your seed on any website.
Open source - CB
Crypto Banter@crypto_banterPost on X ·
🚨COLDCARD ACCOUNT POSTED A PHISHING LINK! @COLDCARDwallet says a post with a phishing link went out from their official account. They deleted it and are investigating how it happened. They say their offline 2FA has been locked down since 2017. This is the same maker that had a seed bug drain roughly $100 million in $BTC in July.
Open source - CO
Cointelegraph@CointelegraphPost on X ·
🚨 JUST IN: Hardware wallet maker COLDCARD says a phishing link was posted from its official X account, despite the account using offline 2FA with tightly restricted access since 2017. https://t.co/hNzzZ0Mf96
Open source

