HomeCrypto NewsCrypto Hacks & CrimeColdcard Says a Phishing Link Was Posted From Its Official X Account...

Coldcard Says a Phishing Link Was Posted From Its Official X Account and It Is Still Investigating How

Coldcard, the bitcoin-only hardware wallet made by Coinkite, says a phishing link was published from its official X account on Sunday 11 October 2026. It said: “We are investigating how a post containing a phishing link was published from this account.” [1] The post has been deleted. Whether anyone lost money is not known.

Spotted via @COLDCARDwallet on X. Users were already warning about it, including @PortlandHODL at 06:15 BST.

Last updated: Sunday 11 October 2026, 11:46 BST.

What Coldcard confirmed

Confirmed (Coldcard’s own posts on X). At 06:46 BST it told users “Do not visit or interact with that link” and said “COLDCARD’s only official website is coldcard.com”. The account “has used offline 2FA with tightly restricted access since 2017”, it said, and “We have contacted @X and are reviewing all account access” [1].

At 07:07 BST it told X Support it could “find no corresponding login, session, or access record”, that its “credentials and offline 2FA remain secure”, and that this “raises concern about unauthorized platform-level or administrative access” [2]. That is a concern, not a finding; Coldcard has not said how the post was published.

What outlets report

Reported (not confirmed by Coldcard). CryptoDaily, citing Inforex, says the post posed as an urgent security update and pointed to migrate[.]coldcardwallet[.]io [3]. It is written defanged on purpose: do not visit it. The Defiant says a researcher found the fake site was built to collect wallet recovery phrases [4]; crypto.news says how the site worked “has not been independently established” [5]. Coldcard’s posts do not name the address. Cointelegraph repeats Coldcard’s statement and adds no domain or time [7].

What is not known

  • When it went up, or for how long. CryptoDaily says about 02:00 UTC (03:00 BST) [3]; the earliest user reactions TSN found on X are from about 06:00 BST [6]. Coldcard has not said.
  • How it happened. Coldcard is investigating.
  • Whether anyone lost funds. No source reports a loss.
  • Whether any device or firmware is involved. No source says so.

What to do

TSN’s general advice, for any hardware wallet:

  • Never type your seed phrase (recovery words) into any website, app or message.
  • Do not follow “security update” or “migrate your funds” links in posts, even from an official account. Type the address yourself; Coldcard says coldcard.com is its only official site.
  • If you already entered a seed phrase or followed the instructions, treat that seed as exposed: create a new wallet with a new seed and move your coins. Coldcard has not issued guidance on this incident.

The Bottom Line

Coldcard confirms a phishing post went out from its account. Cause, timing and losses are unconfirmed.

Sources

  1. Coldcard (@COLDCARDwallet), X post, 11 October 2026, 06:46 BST (05:46 UTC), read in full via the X API (primary statement). https://x.com/COLDCARDwallet/status/2109158742197440912
  2. Coldcard (@COLDCARDwallet), X follow-up to @Support, 11 October 2026, 07:07 BST (06:07 UTC), read via the X API (Coldcard’s own words on the missing login record). https://x.com/COLDCARDwallet/status/2109163908707578236
  3. CryptoDaily, Karim Daniels, “COLDCARD Warns Users After Its Official X Account Posts Phishing Link”, 11 October 2026 (reported: Inforex’s time and domain; the article calls the 06:07 UTC follow-up the “public statement”). https://cryptodaily.co.uk/2026/10/coldcard-x-account-phishing-link
  4. The Defiant, “COLDCARD Warns of Phishing Post on Its Official X Account”, 11 October 2026 (reported; only the standfirst loaded, so the researcher is not named here). https://thedefiant.io/news/security/coldcard-warns-of-phishing-post-on-its-official-x-account
  5. crypto.news, Olivia Stephanie, “COLDCARD warns Bitcoin users about phishing scam on X”, 11 October 2026 (reported; says no verified losses and the site’s operation is not independently established). https://crypto.news/coldcard-warns-bitcoin-users-about-phishing-scam-on-x/
  6. Early user warnings on X before Coldcard’s statement, checked via the X API 11 October 2026: @bergealex4 (06:02 BST) https://x.com/bergealex4/status/2109147577723802086 ; @jevidon (06:09 BST) https://x.com/jevidon/status/2109149295568204047 ; @hodlstack (06:14 BST) https://x.com/hodlstack/status/2109150740077842773 ; @PortlandHODL (06:15 BST) https://x.com/PortlandHODL/status/2109150950833397797
  7. Cointelegraph, Michael Millard, “Coldcard says it’s investigating how phishing link appeared on its X account”, 11 October 2026 (matches Coldcard’s own posts; read in full). https://cointelegraph.com/news/coldcard-says-its-investigating-how-phishing-link-appeared-on-its-x-account
  8. coldcard.com and blog.coinkite.com, checked 11 October 2026 about 11:40 BST: no notice about this incident found.

Related stories

Share this story

Latest stories

More in this category

Latest stories

Free TSN tools: AI funding tracker, DePIN scorecard, AI agent cost calculator and more.