Coldcard said an unauthorized phishing link appeared on its official X account on Oct. 11 and asked X to investigate, months after a $100 million-plus exploit of its wallets.

A Coinkite Coldcard hardware wallet. Photo: Gareth Halfacree via Wikimedia Commons (CC BY-SA 2.0). Source
Bitcoin hardware wallet maker Coldcard said an unauthorized phishing link appeared Oct. 11 on its official X account, and the company asked X to investigate how the deleted post was published, Cointelegraph reported.
The company said it has used offline two-factor authentication with tightly restricted access on the account since 2017. It advised users not to visit or interact with the link and said its only official website is coldcard.com, according to the report.
Coldcard said it was reviewing all account access and would share further verified updates once available. The company has contacted X about the incident, Cointelegraph wrote.
The fraudulent post showed up around 02:00 UTC on Oct. 11 dressed as an urgent security warning, Crypto Briefing reported. It claimed a critical issue with seed generation in recent Coldcard firmware and pointed readers to a domain called migrate.coldcardwallet.io.
Coldcard ran an internal review after the post appeared and found no unauthorized access or logins on the account, the report said. The company credits its offline two-factor setup for that result and wants X to explain whether the platform itself or the account credentials were compromised.
No verified user losses have been tied to the post so far, Crypto Briefing noted. The message did not reveal a new firmware flaw. It referenced a security issue that had already been disclosed earlier in 2026.
That history gives the timing its weight. July emerged as the second-worst month of 2026 for crypto thefts, with hackers stealing $247.4 million, the most this year after the $644 million taken in April, according to DefiLlama figures.
The Coldcard exploit was the month biggest incident, with at least $100 million in Bitcoin taken from 7,300 wallets across three confirmed attack waves, according to Galaxy Digital, Cointelegraph reported. The company also identified a suspected fourth wave that could bring total losses to about $130 million. DefiLlama's own tracker put the July Coldcard losses at $115 million.
Crypto Briefing placed the July and August drain at more than 1,700 BTC, valued at roughly $100 million to $130 million, its report says.
That leaves the awkward question at the center of the current probe. If Coldcard recorded no unauthorized logins, how did the post reach its feed, Crypto Briefing asked. X has been asked to answer it.
For holders, the practical guidance is plain. Users should not click the link and should not move funds based on a social media post. Legitimate firmware fixes never require entering a seed phrase on a website, so any prompt to do so is a red flag no matter which account it comes from, according to the report.
The company said it would publish only verified updates, holding back anything unconfirmed while the review runs, the report adds. That matters because the fake post traded on real fear. Holders who lived through the summer drain know that wallet incidents here have meant nine-figure losses, so a message styled as an urgent seed warning can push people to act before they check the source.
The deletion limits the spread but not the questions. The post is gone from the feed, yet neither the company nor X has explained the mechanism that put it there. The internal review found no sign of unauthorized access, which points attention at the platform side, session handling, or some other path the review has not identified. The firm asked X for an urgent look at exactly that gap, and the answer will decide whether this was a one-off abuse or a weakness other accounts could face.
There is also no timeline for that answer. The firm promised verified follow-up when it has something solid, and until then users have only the standing advice: treat the official site as the single source for downloads and notices, distrust migration prompts, and leave funds where they are unless a verified notice says otherwise. The July episode showed how fast losses scale once seed material leaks, with thousands of wallets emptied across multiple waves, so caution here costs little and a wrong click can cost everything.
Coldcard said it will publish verified follow-up when it has it. X has not publicly described its findings.