Coldcard is confronting another security controversy after its official X account published a phishing link on Oct. 11, 2026, falsely warning customers about a critical firmware vulnerability. The company deleted the post and insists its credentials and two-factor authentication remain secure. The incident follows July’s devastating seed-generation failure, which reportedly exposed thousands of wallets and resulted in estimated losses exceeding $100 million.
Coldcard X Account Hit by Phishing Scam After $100M Fiasco

Key Takeaways
- Coldcard’s official X account published a phishing link on Oct. 11, prompting an investigation.
- Despite the fraudulent post, Coldcard says its credentials and offline two-factor authentication remain secure.
- The incident follows Coldcard’s July firmware disaster, which reportedly resulted in more than $100 million in losses.
Coldcard’s Security Nightmare Deepens as Phishing Post Appears on Official X Account
Coldcard has another security headache on its hands, and this one arrived through its own social media account. Early Sunday, Oct. 11, a fraudulent post appeared on the hardware wallet manufacturer’s official X account, warning customers about a supposed seed-generation vulnerability and directing them to a phishing website.
The message was eventually deleted, but the episode raises an uncomfortable question about how attackers managed to publish it in the first place. Coldcard claimed its account credentials and offline two-factor authentication remain intact, while its internal investigation has uncovered no corresponding unauthorized login or session.
A Convincing Warning With a Dangerous Destination
The fraudulent message appeared around 2 a.m. UTC and presented itself as an urgent Coldcard security update. It claimed that recent firmware contained a critical vulnerability affecting seed generation and instructed customers to migrate their wallets immediately.
The post referenced several Coldcard hardware models and directed users to a deceptive website that used Coldcard’s name. Its wording was particularly troublesome because it borrowed credibility from a genuine security disaster that struck the company earlier this year.

Community members quickly sounded the alarm, and Coldcard eventually pulled the message. Around 5:46 a.m. UTC, the company acknowledged the incident and warned customers against interacting with the suspicious link. Coldcard stated:
“We are investigating how a post containing a phishing link was published from this account. It has since been deleted.”
The company emphasized that coldcard.com is its only official website and said its account has operated with offline two-factor authentication and tightly restricted access since 2017.
Coldcard Presses X for Answers
The plot thickened roughly 20 minutes later when Coldcard publicly requested an urgent investigation from X Support. The manufacturer maintained that its security review had uncovered no evidence of unauthorized account access.
“A phishing post appeared on our account, yet we can find no corresponding login, session, or access record,” the company explained.
Coldcard raised concerns about possible platform-level or administrative access, although that explanation remains unverified. The troubled hardware wallet manufacturer also referenced reports of X administrative credentials being offered on darknet markets, but acknowledged that no connection to its incident had been established.

For now, the mystery centers on how a fraudulent message reached an account whose owners insist their normal security controls were never breached. No confirmed financial losses have been attributed specifically to Sunday’s phishing attempt.
July’s $100 Million Disaster Returns to Haunt Coldcard
The timing couldn’t be much worse. In July, Coldcard confronted a serious firmware defect that reportedly allowed attackers to reconstruct vulnerable wallet seeds and steal an estimated 1,600 to 1,800 bitcoin, worth approximately $100 million to $130 million at the time.
The underlying problem reportedly dated to March 2021 and involved defective seed generation that produced substantially less randomness than intended. Attackers exploited that weakness by testing potential recovery phrases offline rather than compromising the physical devices.
Coldcard subsequently issued firmware fixes and instructed affected customers to migrate their funds into newly generated wallets. Sunday’s phishing attempt exploited precisely that concern, dressing a malicious website in the language of legitimate security guidance.
Transparent Cases and Angry Customers
The latest incident also follows a contentious Oct. 9 social media post promoting Coldcard’s transparent hardware cases as protection against physical tampering. Coincidently the social media post came out after it was discovered that Ledger devices may have been tampered with by third-party suppliers or somewhere along the supply chain.

Critics blasted the timing, arguing that transparent plastic and tamper-evident packaging offered little protection against the software defect responsible for July’s losses. Several members of the crypto community considered the post tasteless, tone deaf, and done with no shame. Some customers and observers have also accused Coldcard and co-founder Rodolfo Novak of blocking critics and purported victims on X.
Now the company faces another round of scrutiny, this time over the integrity of its official communications. Coldcard continues to direct customers exclusively to its legitimate website for firmware updates and wallet migration instructions.
The latest episode leaves a particularly awkward contradiction hanging over the manufacturer. A company built around keeping private keys beyond the reach of online attackers has found itself investigating how its own trusted communication channel became a vehicle for a phishing scam.
A five-year-old Coldcard software flaw may have allowed an attacker to reconstruct private keys and sweep more than 1,100 bitcoin,…
Read Now: Was AI Responsible for Finding the Coldcard Security Flaw?
















