Four-hour briefing
Fintech Briefing —
What changed in fintech over the last 4 hours
Pulse: Hardware wallet tampering and social channel phishing dominate digital asset security this cycle.
Top Stories
- Coldcard Investigates Unexplained Phishing Message on Official X Account
Coldcard is investigating a phishing post published from its official X account directing users to a fraudulent wallet-migration website. No login records explain the post, and no financial losses have been confirmed.
Why it matters: The incident shows how attackers leverage verified corporate social media accounts to conduct social engineering attacks aimed at stealing hardware wallet recovery phrases.
- Fraudulent Coldcard Post Targeted User Recovery Seed Phrases
Coldcard is investigating a phishing message posted from its official X account that prompted users to migrate Bitcoin via a fraudulent site, attempting to steal 12- or 24-word recovery phrases.
Why it matters: The incident demonstrates how attackers leverage verified corporate social media accounts to execute social engineering attacks on cryptocurrency holders following prior security issues.
- Ledger Probe Detects Hardware Implant in Reseller Device
Ledger confirmed finding an unauthorized physical implant in a customer device purchased through reseller CryptoBilis. The reseller halted all inventory sales across Southeast Asia, while onchain investigators estimate potential losses across cryptocurrencies may exceed $86 million.
Why it matters: The incident demonstrates that supply-chain tampering at an authorized reseller can bypass hardware wallet protections before a user even generates their recovery phrase.
Since the last briefing
- · 3 new major stories
- · Crypto remains the most-covered topic
- · 1 story has multi-source coverage
Sources
FinanceFeeds