Coldcard Can't Explain How a Phishing Link Ended Up on Its Own X Account

Market Intel · Just now · Not financial advice

Coldcard's official X account posted a phishing link dressed up as a security warning. The company still can't explain how it got there.

What Coldcard Says Happened

The post is gone, and Coldcard told users not to touch the link, reminding them that coldcard.com is its only official site. The account has run on offline two-factor authentication with tightly restricted access since 2017. An internal review turned up no login, session, or access records at all.

That absence is the strange part. Coldcard suspects the attacker gained platform-level or administrator access on X rather than stealing credentials, and it has asked X to investigate urgently and preserve logs. The company also mentioned unverified reports of X admin accounts being sold on dark web markets, but said it found no link to this incident.

Why The Timing Is Awkward

This lands months after Coldcard's own hardware got hit. A March 2021 firmware build error pushed seed generation onto a weak software random number generator instead of the device's hardware entropy source, cutting key strength from 128 bits to as little as 40 on older units.

Galaxy Digital counted at least $100 million in Bitcoin taken from 7,300 wallets across three confirmed waves, with a suspected fourth pushing losses toward $130 million; DefiLlama put it near $115 million. TRM Labs' tally runs to roughly 1,816 BTC — about $116 million — from more than 5,200 addresses, the third-largest crypto hack of 2026.

What Users Should Do

Installing the patched firmware does not repair a seed that already exists, so anyone who generated one between March 2021 and the fix should treat it as compromised and migrate to a brand-new wallet.

The broader lesson is about trust channels. A verified badge and two-factor authentication mean little if the platform itself is the weak link, and when a wallet vendor's own account gets turned against its users, verifying through the domain you already know beats clicking anything in a post.[unverified]

↑ Back to top