Skip to content

InvestIndependently confirmed3 publishers2 min readPublished

COLDCARD's X account posted a phishing link despite offline two-factor protection since 2017

COLDCARD says its official X account posted a phishing link on October 11, despite offline two-factor protection the wallet maker has used since 2017. With no explanation yet from COLDCARD or X, a security alert seen on social media is worth acting on only once the maker's own website repeats it.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying COLDCARD's X account posted a phishing link despite offline two-factor protection since 2017
Generated illustration
Phishing post targeted holders; X asked to check access Who the October 11 phishing post on COLDCARD's official X account reaches and how, based on COLDCARD statements reported by crypto.news.

Four actors. Bitcoin holders: fake post told them to move Bitcoin via a site impersonating COLDCARD. COLDCARD: found no matching login, session or access record. X: asked to probe possible internal or admin access and keep records. Customers: told coldcard.com is the only official site.

Phishing post targeted holders; X asked to check access
WhoHowKindClaim
COLDCARD Bitcoin holdersFake post told them to move their Bitcoin through a migration on a site impersonating COLDCARDexposure8
COLDCARDFound no login, session or access record matching the post published from its accountcontradiction6
XAsked by COLDCARD to investigate possible access via internal systems or admin privileges and keep access recordsexposure7
COLDCARD customersCOLDCARD names coldcard.com as its only official websitedecision4

What happened

  • The post warned of a supposed flaw in recovery-phrase generation in newer firmware and told holders to move their Bitcoin through a migration on a site impersonating COLDCARD.
  • COLDCARD deleted the post and warned customers not to open the link or follow any of its instructions.
  • COLDCARD told X Support it could find no login, session or access record matching the post, and asked the platform for help.
  • No verified financial losses have been reported, and COLDCARD has not said how long the post stayed up or how many people visited the site.

Why it matters

  • exposure If COLDCARD's suspicion about access through X's internal or administrative tools is borne out, no vendor's own two-factor setup protects what its account publishes on the platform.
  • decision COLDCARD responded by naming coldcard.com as its only official site; every custody firm that posts security notices on X now has to tell customers where a notice must be confirmed before coins move.
  • constraint A genuine firmware warning from COLDCARD would now arrive on a feed that has carried a fake one, so its real notices on X will carry less weight until the access route is found.

The fake warning imitated the posts the account normally carries. COLDCARD ordinarily uses its verified X account for security notices, firmware releases and product information [5], so a firmware alert from that handle looks like routine company business to the people who follow it. The company has not confirmed any new firmware vulnerability tied to the post [14]. Nobody has independently established whether the linked site collected recovery phrases or distributed malicious software [15].

"We are investigating how a post containing a phishing link was published from this account," COLDCARD said [9]. Its initial review found its credentials and offline authentication measures still secure [10]. Taken with the missing login record, that finding means the post came through some route other than COLDCARD's own sign-in, if both hold up [18].

The company has not said whether its investigation found a compromised employee account, an abused integration or another method [16]. Each points to a different fix. A staff login or a connected app with posting rights would put the failure inside COLDCARD's own setup. Either would be hard to reconcile with its account of tightly restricted access [2]. The other route is one COLDCARD raised itself, according to an October 11 report by TechFlow: access through X's internal systems or administrative privileges, with a request that X investigate and preserve the records [7]. The company raised that as a possibility. It is not an established finding, and no verified evidence identifies who published the message [12]. Reports on the incident also referred to alleged advertisements for X administrator accounts on underground marketplaces, and COLDCARD has not connected them to its post [17].

We think the conclusion for customers is the same under every explanation in play. An integration or a staff account would mean a firm with offline two-factor protection since 2017 [2] still left a publishing route its own controls did not cover. Access through X's internal tools would mean no account holder's controls mattered at all. The counter-thesis is that this was one firm's lapse. If the cause turns out to be a forgotten app with posting rights, other custody providers can close the same gap by checking their own permissions, and the wider case would rest on a platform risk this incident did not prove. What would change our view is X showing that the post came through a session COLDCARD could have seen and stopped.

What to watch

  • Whether X's review of the preserved access records shows the post went out through its internal or administrative tools, as COLDCARD suggested.
  • COLDCARD's promised follow-up once it verifies its findings, and whether it names a staff account or a third-party integration as the route.
  • Any verified report of holders losing Bitcoin through the fake migration site.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence58

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 50%
Investor
Investor 27%
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Bitcoin hardware wallet manufacturer COLDCARD launched an investigation after an unauthorized phishing message appeared on its official X account on October 11, directing users toward a fraudulent wallet security website; the company confirmed the incident and deleted the post.

  2. [2]

    COLDCARD said its official X account has relied on offline two-factor authentication with tightly restricted access since 2017.

    ReportedSupportedSource: COLDCARD statement, via crypto.news3 sources— create a free account to open themView cited source
  3. [3]

    COLDCARD deleted the post and warned customers against opening the suspicious link or following its instructions.

Sources

3 independent publishers whose own reporting we read for this story.

  1. cointelegraph.com

    1 article · October 11, 2026

    Coldcard says it’s investigating how phishing link appeared on its X account
  2. crypto.news

    1 article · October 11, 2026

    COLDCARD warns Bitcoin users about phishing scam on X
  3. cryptobriefing.com

    1 article · October 11, 2026

    Coldcard investigates phishing link posted on its X account after exploit

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories