Coldcard Investigates Phishing Link Posted on Its X Account
Bitcoin hardware wallet manufacturer Coldcard is investigating how an unauthorized phishing link was published on its official X account over the weekend, the company confirmed on Sunday. The post, which has since been deleted, appeared despite Coldcard's longstanding use of offline two-factor authentication and tightly restricted account access, practices the company said it has maintained since 2017. Coldcard advised users not to visit or interact with the link and emphasized that its only official website is coldcard.com. The firm has contacted X and is reviewing all account access logs to determine how the breach occurred, promising to share further verified updates.
The incident comes at a sensitive time for Coldcard, which is still dealing with fallout from a major July exploit that Galaxy Digital identified as the largest crypto theft of the month. Hackers stole at least $100 million in Bitcoin from approximately 7,300 wallets across three confirmed attack waves, with a suspected fourth wave potentially bringing total losses to around $130 million. DefiLlama's hack tracker estimated the July losses tied to the Coldcard exploit at $115 million, contributing to July becoming the second-worst month of 2026 for cryptocurrency thefts, behind only April's $644 million total.
The phishing post adds another reputational challenge for the hardware wallet provider as it works to reassure customers about the security of its devices. Hardware wallets are generally considered one of the safest ways to store cryptocurrency, with Coldcard specifically marketing its air-gapped signing capabilities and open-source firmware. The account compromise on X, however, demonstrates that even security-focused firms remain vulnerable to social media-based attacks that can trick followers into connecting wallets to malicious sites.
Users who may have interacted with the deleted post are urged to check their wallets for any unauthorized transactions and revoke suspicious approvals immediately. Coldcard reiterated that it will never distribute support links, firmware updates, or wallet connections through X posts and that all legitimate communication occurs through its official website and verified channels.
Read Full Article at CoinTelegraph →