Coldcard Probes Phishing Post From Official X Account After…
By Abdelaziz Fathi

AI summary of the source article
Bitcoin hardware wallet maker Coldcard is probing how an unauthorized phishing post appeared on its official X account, despite offline two-factor authentication and restricted access in place since 2017. The now-deleted post presented a fake security warning instructing users to migrate Bitcoin via a fraudulent site that prompted for 12- or 24-word recovery phrases. Coldcard found no login, session, or access record explaining the incident and requested that X investigate. As of October 11, no financial losses have been confirmed, though the incident follows a separate firmware vulnerability from July that resulted in the theft of approximately $114.7 million to $116 million in Bitcoin.
Why it matters
The incident shows how attackers leverage verified corporate social media accounts to conduct social engineering attacks aimed at stealing hardware wallet recovery phrases.
Key facts
- Coldcard's official X account published an unauthorized phishing link directing users to a fake wallet-migration site requesting recovery phrases.
- Coldcard's internal review found no corresponding login, session, or access record for the post, prompting the firm to ask X to investigate.
- As of October 11, Coldcard has not disclosed any confirmed financial losses resulting from the phishing attempt.