0x11a6055811a6…11a60555

ConfirmedSecurity448 vB168 sat/vB2 min decode

Coldcard Investigates Phishing Post on Its Official X Account

Coldcard is investigating how a phishing link appeared on its official X account, which has used offline 2FA since 2017, weeks after a $100M+ exploit hit 7,300 wallets.

Coldcard says it’s investigating how phishing link appeared on its X account
WitnessColdcard says it’s investigating how phishing link appeared on its X accountAI-generated

Outputs

  1. A phishing link appeared on Coldcard's official X account on Sunday and was later deleted.

  2. At least $100 million in BTC was stolen from about 7,300 wallets across three attack waves, per Galaxy Digital.

  3. A suspected fourth wave could bring total losses to roughly $130 million.

  4. July saw $247.4 million in crypto stolen, 2026's second-worst month after April's $644 million, per DefiLlama.

Coldcard, the Bitcoin-only hardware wallet maker, said a phishing link appeared on its official X account on Sunday and that it is investigating how the post was published before its deletion.

The company advised users not to visit or interact with the link in question, and reiterated that its only official website is https://coldcard.com. Coldcard said it has contacted X and is reviewing all account access, promising to share further verified updates.

The incident is complicated by the account's security posture. Coldcard said it has used offline two-factor authentication and tightly restricted access to the account since 2017. A post published despite those controls raises questions about whether the compromise involved a credential lapse, a compromised device used for posting, or a platform-level issue — questions the company has not yet answered.

Why the timing matters

The phishing post landed weeks after Coldcard suffered one of the largest Bitcoin thefts on record. At least $100 million in Bitcoin (BTC) was stolen from roughly 7,300 wallets across three confirmed attack waves, according to Galaxy Digital. The firm also identified a suspected fourth wave that could push total losses to roughly $130 million.

DefiLlama's hack tracker pegged losses tied to the Coldcard exploit at $115 million.

July ranked as the second-worst month of 2026 for cryptocurrency thefts, largely on the back of the Coldcard exploit, Cointelegraph reported earlier. Hackers stole $247.4 million in crypto during the month, according to DefiLlama data — the highest figure this year after April's $644 million.

What are the operational consequences?

A phishing link on the official account of a wallet vendor whose users are already tracing stolen funds compounds the trust problem. Attackers routinely use fake "compensation" or "migration" schemes to target victims of prior exploits, and a post from a verified corporate handle carries exactly the credibility those campaigns need.

For Coldcard, the immediate task is twofold: demonstrate that its X account — a primary crisis-communications channel since the exploit — is fully back under its control, and complete the access review it has begun. Every statement the company issues about the July incident now travels through infrastructure that has demonstrably published unauthorized content.

What happens next?

Coldcard said it will publish only verified updates, which sets a high evidentiary bar for its next disclosure. The scale of the July exploit — a suspected fourth attack wave still unconfirmed — means investigators, insurers and affected users will be watching both the company's on-chain tracing disclosures and the outcome of its review with X. Until Coldcard confirms the vector behind Sunday's post, any link or claim issued from its account should be treated as unverified.

via x.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

421 articles