COLDCARD Warns Bitcoin Users After Phishing Post Appears on Verified X Account

Daily Feed
COLDCARD Warns Bitcoin Users After Phishing Post Appears on Verified X Account

COLDCARD warns Bitcoin users after phishing post on verified X account

A phishing post posing as a wallet-security warning appeared on COLDCARD’s verified X account, urging Bitcoin holders to move their funds through a purported migration process. The company said it deleted the post and warned users not to follow its link. How the post was published and what the linked site did remain unknown.

  • COLDCARD said the post was unauthorized and told customers to avoid the linked site.
  • No cause, responsible party, or confirmed impact has been established.
  • A separate, documented seed-generation flaw does not prove the post’s claim of a new vulnerability.

What COLDCARD said about the post

The post reportedly claimed that newer wallet firmware had a vulnerability affecting recovery-phrase generation. It urged users to move their Bitcoin through a migration process on a website impersonating COLDCARD. The company said the post was unauthorized, removed it, and warned customers not to visit the site or follow its instructions.

COLDCARD said it was investigating how the post appeared on its account:

“We are investigating how a post containing a phishing link was published from this account.”

According to reports, COLDCARD told X Support that its initial review found no matching login, session, or access record. The company also said it had used offline two-factor authentication since 2017, along with restricted account access. Offline two-factor authentication is a second account-verification step managed offline. Those reported safeguards do not explain how the post was published or rule out unauthorized access through another route.

TechFlow reported that COLDCARD raised the possibility of unauthorized access involving X systems or administrative privileges. That possibility has not been confirmed, and no responsible party has been identified. Reports dated the post October 11, but did not specify the year. Its timing relative to a separate firmware disclosure dated July 2026 therefore cannot be established.

It is also unclear what the linked site did. Available reporting does not establish whether it collected recovery phrases, distributed malicious software, or did something else. COLDCARD has not disclosed how many people saw the post, how long it remained online, or whether anyone acted on it. The available information does not confirm any losses from this phishing attempt.

The seed-generation flaw was a separate issue

COLDCARD’s Security Status page describes a separate flaw in the randomness used to generate some wallet seeds. A seed is the secret from which a wallet’s keys are derived. If it is not unpredictable enough, an attacker may be able to reproduce the keys without remotely taking over the hardware wallet.

COLDCARD says some earlier firmware did not use the intended hardware-randomness source. Its advisory covers seeds created on affected firmware across Mk4, Mk5, and Q devices, as well as older models. The company says the issue with the Mk2 and Mk3 generation path is more severe.

The company lists these releases as containing the fix: 4.2.0 for Mk2 and Mk3; 5.6.0 or later for standard Mk4 and Mk5 firmware; 1.5.0Q or later for standard Q firmware; 6.6.0X or later for Mk4 and Mk5 Edge; and 6.6.0QX or later for Q Edge. For standard firmware, its current recommended versions are 5.6.3 for Mk4 and Mk5, and 1.5.3Q for Q. Check COLDCARD’s current guidance for your exact device and firmware version.

Updating firmware corrects future seed generation, but it does not repair a seed created while affected firmware was in use. Owners of an affected seed should follow COLDCARD’s official replacement guidance. The company’s page says attackers in the July 2026 incident regenerated the corresponding private keys offline and stole funds. The available information does not provide a complete victim ledger. That documented issue is separate from the unauthorized X post, which COLDCARD has not linked to a new flaw in corrected firmware.

How to handle suspicious wallet warnings

COLDCARD identifies coldcard.com as its official website. If a security warning urges you to move funds, go directly to a known official address instead of relying on a link in a post or direct message. Never enter recovery words on a website or give them to someone claiming to be support.

COLDCARD also recommends checking firmware against its published SHA-256 hash and signed signatures.txt file. A hash can confirm that a file matches a trusted reference, while a valid signature helps verify that the release is authentic. Neither check repairs an affected seed or proves that software is free of defects.

Key questions and answers

  • Was the X post linked to a new firmware vulnerability?

    No connection has been established. The seed-generation flaw is a separate, documented issue.

  • How did the post appear on COLDCARD’s account?

    The method and responsible party remain unknown. COLDCARD reportedly found no matching login, session, or access record in its initial review, but that does not explain how the post was published.

  • Did the linked site steal recovery phrases or Bitcoin?

    Its behavior is unknown, and available reporting does not confirm losses from the October phishing attempt.

  • Does updated firmware fix a seed generated on affected software?

    No. The update corrects future seed generation. Owners of an affected seed must follow COLDCARD’s replacement guidance.

  • What should users do with suspicious migration instructions?

    Do not visit the linked site or enter recovery words. Verify security guidance through COLDCARD’s official channels.

A hardware wallet cannot protect recovery information its owner is tricked into handing over. Until COLDCARD’s investigation explains how the post appeared, claims about an X compromise or the site’s capabilities remain unconfirmed. See coverage of the reported seed vulnerability and unverified $112 million claim.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog