InvestIndependently confirmed3 publishers2 min readPublished
COLDCARD's X account posted a phishing link despite offline two-factor protection since 2017
COLDCARD says its official X account posted a phishing link on October 11, despite offline two-factor protection the wallet maker has used since 2017. With no explanation yet from COLDCARD or X, a security alert seen on social media is worth acting on only once the maker's own website repeats it.
The Investor · Invest desk

Four actors. Bitcoin holders: fake post told them to move Bitcoin via a site impersonating COLDCARD. COLDCARD: found no matching login, session or access record. X: asked to probe possible internal or admin access and keep records. Customers: told coldcard.com is the only official site.
- exposure COLDCARD Bitcoin holders Fake post told them to move their Bitcoin through a migration on a site impersonating COLDCARD, claim 8
- contradiction COLDCARD Found no login, session or access record matching the post published from its account, claim 6
- exposure X Asked by COLDCARD to investigate possible access via internal systems or admin privileges and keep access records, claim 7
- decision COLDCARD customers COLDCARD names coldcard.com as its only official website, claim 4
| Who | How | Kind | Claim |
|---|---|---|---|
| COLDCARD Bitcoin holders | Fake post told them to move their Bitcoin through a migration on a site impersonating COLDCARD | exposure | 8 |
| COLDCARD | Found no login, session or access record matching the post published from its account | contradiction | 6 |
| X | Asked by COLDCARD to investigate possible access via internal systems or admin privileges and keep access records | exposure | 7 |
| COLDCARD customers | COLDCARD names coldcard.com as its only official website | decision | 4 |
What happened
- The post warned of a supposed flaw in recovery-phrase generation in newer firmware and told holders to move their Bitcoin through a migration on a site impersonating COLDCARD.
- COLDCARD deleted the post and warned customers not to open the link or follow any of its instructions.
- COLDCARD told X Support it could find no login, session or access record matching the post, and asked the platform for help.
- No verified financial losses have been reported, and COLDCARD has not said how long the post stayed up or how many people visited the site.
Why it matters
- exposure If COLDCARD's suspicion about access through X's internal or administrative tools is borne out, no vendor's own two-factor setup protects what its account publishes on the platform.
- decision COLDCARD responded by naming coldcard.com as its only official site; every custody firm that posts security notices on X now has to tell customers where a notice must be confirmed before coins move.
- constraint A genuine firmware warning from COLDCARD would now arrive on a feed that has carried a fake one, so its real notices on X will carry less weight until the access route is found.
The fake warning imitated the posts the account normally carries. COLDCARD ordinarily uses its verified X account for security notices, firmware releases and product information [5], so a firmware alert from that handle looks like routine company business to the people who follow it. The company has not confirmed any new firmware vulnerability tied to the post [14]. Nobody has independently established whether the linked site collected recovery phrases or distributed malicious software [15].
"We are investigating how a post containing a phishing link was published from this account," COLDCARD said [9]. Its initial review found its credentials and offline authentication measures still secure [10]. Taken with the missing login record, that finding means the post came through some route other than COLDCARD's own sign-in, if both hold up [18].
The company has not said whether its investigation found a compromised employee account, an abused integration or another method [16]. Each points to a different fix. A staff login or a connected app with posting rights would put the failure inside COLDCARD's own setup. Either would be hard to reconcile with its account of tightly restricted access [2]. The other route is one COLDCARD raised itself, according to an October 11 report by TechFlow: access through X's internal systems or administrative privileges, with a request that X investigate and preserve the records [7]. The company raised that as a possibility. It is not an established finding, and no verified evidence identifies who published the message [12]. Reports on the incident also referred to alleged advertisements for X administrator accounts on underground marketplaces, and COLDCARD has not connected them to its post [17].
We think the conclusion for customers is the same under every explanation in play. An integration or a staff account would mean a firm with offline two-factor protection since 2017 [2] still left a publishing route its own controls did not cover. Access through X's internal tools would mean no account holder's controls mattered at all. The counter-thesis is that this was one firm's lapse. If the cause turns out to be a forgotten app with posting rights, other custody providers can close the same gap by checking their own permissions, and the wider case would rest on a platform risk this incident did not prove. What would change our view is X showing that the post came through a session COLDCARD could have seen and stopped.
What to watch
- Whether X's review of the preserved access records shows the post went out through its internal or administrative tools, as COLDCARD suggested.
- COLDCARD's promised follow-up once it verifies its findings, and whether it names a staff account or a third-party integration as the route.
- Any verified report of holders losing Bitcoin through the fake migration site.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence58
Perspective Coverage
3 publishers- Builder
- Builder 23%
- Operator
- Operator 50%
- Investor
- Investor 27%
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Bitcoin hardware wallet manufacturer COLDCARD launched an investigation after an unauthorized phishing message appeared on its official X account on October 11, directing users toward a fraudulent wallet security website; the company confirmed the incident and deleted the post.
- [2]
COLDCARD said its official X account has relied on offline two-factor authentication with tightly restricted access since 2017.
ReportedSupportedSource: COLDCARD statement, via crypto.news3 sources— create a free account to open themView cited source - [3]
COLDCARD deleted the post and warned customers against opening the suspicious link or following its instructions.
- [4]
COLDCARD said its only official website is coldcard.com.
ReportedSupportedSource: COLDCARD statement, via crypto.news3 sources— create a free account to open themView cited source - [5]
COLDCARD ordinarily uses its verified X account to communicate security notices, firmware releases and product information.
- [6]
In a message addressed to X Support, COLDCARD reportedly said it could not identify a login, session or access record corresponding to the unauthorized post, and the company contacted X.
ReportedSupportedSource: crypto.news, citing reports3 sources— create a free account to open themView cited source - [7]
According to an October 11 report by TechFlow, COLDCARD raised concerns about possible unauthorized access involving X's internal systems or administrative privileges and asked X to investigate and preserve relevant access records.
ReportedSupportedSource: TechFlow, as reported by crypto.news3 sources— create a free account to open themView cited source - [8]
The unauthorized post reportedly presented itself as an urgent warning about a supposed vulnerability affecting recovery phrase generation in newer wallet firmware and instructed customers to move their Bitcoin holdings through a security migration process on a website impersonating COLDCARD.
ReportedSupportedSource: crypto.news, citing reports published October 112 sources— create a free account to open themView cited source - [9]
"We are investigating how a post containing a phishing link was published from this account."
ReportedSupportedSource: COLDCARD statement, quoted by crypto.news3 sources— create a free account to open themView cited source - [10]
COLDCARD maintained that its credentials and offline authentication measures remained secure based on its initial review.
ReportedSupportedSource: COLDCARD, via crypto.news3 sources— create a free account to open themView cited source - [11]
COLDCARD said it would publish further information after verifying its findings.
ReportedSupportedSource: COLDCARD, via crypto.news3 sources— create a free account to open themView cited source - [12]
A platform-level compromise is a possibility raised by COLDCARD, not an established finding, and there is no verified evidence identifying who published the message.
- [13]
No verified reports of direct financial losses from the October 11 phishing attempt were identified, and COLDCARD has not disclosed how long the message remained visible or how many users visited the website.
- [14]
COLDCARD has not confirmed a new firmware vulnerability associated with the phishing post.
- [15]
The exact operation of the phishing website, including whether it collected recovery phrases or distributed malicious software, has not been independently established.
- [16]
COLDCARD has not announced whether the investigation uncovered a compromised employee account, an abused integration or another method of unauthorized access.
- [17]
Reports concerning the incident referred to alleged advertisements offering X administrator accounts on underground marketplaces; COLDCARD did not establish any connection between those claims and the phishing post.
- [18]
If COLDCARD's initial review is right that its credentials and offline authentication were secure, and it found no matching login, session or access record, then the post was published through some route other than COLDCARD's own sign-in.
Sources
3 independent publishers whose own reporting we read for this story.
- cointelegraph.comColdcard says it’s investigating how phishing link appeared on its X account
1 article · October 11, 2026
- crypto.newsCOLDCARD warns Bitcoin users about phishing scam on X
1 article · October 11, 2026
- cryptobriefing.comColdcard investigates phishing link posted on its X account after exploit
1 article · October 11, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.