Coldcard Says a Phishing Link Was Posted From Its Own X Account

A post telling Bitcoin holders to move their coins appeared on Coldcard's verified X account on Sunday, and the hardware wallet maker says it still cannot explain how. The message claimed a flaw in the way newer firmware generates recovery phrases, then sent readers to a migration site impersonating the company. Coldcard deleted the post and told customers not to open the link. It has asked X to investigate and to preserve the account's access records. No losses had been confirmed by the end of 11 October.
The account, @COLDCARDwallet, is the one Coinkite uses for firmware releases and security notices. crypto.news carried the company's statement on Sunday morning, FinanceFeeds and Crypto Briefing in the afternoon. The three accounts agree on the sequence. They also agree on what is missing from it.
"We are investigating how a post containing a phishing link was published from this account. It has since been deleted," the company said.
What the message asked for
The deleted post presented itself as an urgent security warning. It described a vulnerability in recovery-phrase generation in newer firmware, and instructed holders to run their coins through a migration process on a separate site. FinanceFeeds reported that researchers who examined that site found it requesting 12- or 24-word recovery phrases and optional passphrases, which would give an attacker everything needed to rebuild the wallet elsewhere.
No other outlet read here confirms that finding. crypto.news said plainly that the site's operation, including whether it collected phrases or served malware, has not been independently established. Coldcard has not disclosed how long the post stayed up, or how many people followed it. The company has also not confirmed any new firmware vulnerability behind the claim.
A review that turned up nothing
Coldcard says the account has used offline two-factor authentication with tightly restricted access since 2017. Crypto Briefing reported that the company's internal review found no unauthorized access or logins; crypto.news put the same finding as no identifiable login, session or access record matching the publication. Neither is a finding about X's own systems.
TechFlow reported on Sunday, in an account read here through crypto.news, that Coldcard raised the possibility of unauthorized platform-level or administrative access. That is the company's hypothesis, not an established fact. FinanceFeeds listed compromised credentials, abused sessions, authorized applications and employee access among the other open explanations. X has publicly confirmed none of them.
Why this lure fits these customers
The warning was plausible because the real thing happened in July, when Coldcard disclosed that some earlier firmware had not used the intended hardware randomness source when generating wallet seeds. The defect dated to 2021. Galaxy Research traced 1,789.28 BTC, about $114.7 million, across 8,865 addresses by 25 August; DefiLlama records the same incident at roughly $116 million. The two totals do not reconcile, and we could not establish which supersedes which.
Customers were told then to migrate, which is exactly what Sunday's post told them to do again. Coldcard's documentation says installing corrected firmware does not repair a phrase generated under the vulnerable software, so replacing the phrase is still the only remedy. The recommended releases are 5.6.3 for Mk4 and Mk5 devices and 1.5.3Q for the Q.
What X has to answer
Impersonation has followed the firmware disclosure since the summer. The research group Unclone reported on 5 August, in an account read here only through crypto.news, that ten lookalike domains were registered within five days of the July notice, and that of 97 accounts using Coldcard or Coinkite branding it examined, 34 presented themselves as company staff. A fake account is one problem. A real one is another. In September, phishing messages reached Trezor customers through that company's own email infrastructure, and the lesson held: an authenticated channel makes a fraudulent warning far harder to dismiss.
The mechanism behind Sunday's post is the disclosure that matters now. Until X produces it, a verified manufacturer account is no longer sufficient authentication for an instruction to move coins.
Read also: Coinkite Tells Coldcard Users to Migrate as a Third Sweep Lands