Coldcard enquête sur un message de phishing publié depuis…
By Abdelaziz Fathi

AI summary of the source article
Bitcoin hardware wallet maker Coldcard is investigating how an unauthorized phishing link was published from its official X account, despite claims of strict access controls and offline two-factor authentication in place since 2017. The deleted message directed users to a fraudulent wallet migration site seeking 12- or 24-word recovery phrases. Coldcard reported finding no matching login or session logs and has asked X to investigate. As of October 11, no financial losses were confirmed. The incident follows a prior firmware vulnerability disclosed in late July, which Galaxy Research linked to the theft of 1,789.28 BTC.
Why it matters
The incident demonstrates how attackers leverage verified corporate social media accounts to execute social engineering attacks on cryptocurrency holders following prior security issues.
Key facts
- A phishing link was published from Coldcard's official X account redirecting users to a fake wallet migration site seeking recovery phrases.
- Coldcard found no corresponding login or session records and asked X to investigate the incident.
- As of October 11, Coldcard reported no confirmed financial losses resulting from the phishing attempt.