UToday • October 11th 2026, 10:22 AM
Coldcard Bitcoin Wallet Maker Hit by Targeted Phishing Scam
Key Summary
The official X account of Coldcard, a Bitcoin hardware wallet manufacturer, was compromised through a phishing scam. Attackers claimed a critical firmware vulnerability, urging users to move their funds to a fake website. Despite Coldcard's secure systems, the post bypassed security measures, raising concerns about unauthorized platform-level access.
Please see our real time news feed on our Home Page
Background
Coldcard experienced a major crisis in late July 2026 due to a linker error in the device code, generating wallets with weak entropy. Hackers cracked the wallets offline through brute-force attacks and drained addresses.The Latest Incident
On October 11, 2026, a phishing post appeared on Coldcard's X account, claiming a critical firmware vulnerability affecting Mk4, Mk5, and Q models. The post urged users to move their funds immediately through a fake website. However, the Coldcard team found no evidence of a breach in their systems.Investigation
Coldcard representatives stated that the post bypassed security measures through unauthorized access at the social network level or via its administrative panel. The company is demanding an urgent investigation and has contacted X support. Reports suggest that access to X's internal tools is being sold on darknet markets, but no independent evidence has confirmed a connection.Risks and Consequences
The risk of losing funds likely applies only to users who panicked and manually entered their 24-word seed phrases on the phishing page. Coldcard emphasizes the importance of preserving all relevant logs and conducting a thorough investigation by the security team.Conclusion
The incident highlights the ongoing threat of phishing scams in the cryptocurrency space. It is crucial for users to remain vigilant and cautious when interacting with online platforms and to never enter sensitive information without verifying its authenticity.#Bitcoin#US#Crypto#SEC#Darknet