Coldcard investigates phishing link posted on its X account after exploit

9 hours ago 2



Coldcard, the Bitcoin hardware wallet built by Coinkite, is investigating a phishing post that appeared on its official X account. The post was dressed up as an urgent security warning. The company told users not to visit or interact with the link. It also said it will share further updates only once they are verified. What happened on Coldcard’s X feed The fraudulent post showed up around 02:00 UTC on October 11, 2026. It claimed there was a critical issue with seed generation in recent Coldcard firmware. The post pointed readers to a domain called migrate.coldcardwallet.io. Coldcard says it ran an internal review after the post appeared. That review found no unauthorized access or logins on the account. The company credits offline two-factor authentication, which it says it has used since 2017. Coldcard has asked X for an urgent investigation. The company wants to know whether the platform itself or account credentials were compromised. No verified user losses have been reported in connection with the post so far. Why the timing matters The phishing message did not reveal any new firmware vulnerability. Instead, it referenced a security issue that had already been disclosed earli...

Read Entire Article