Coldcard Wallet Hit by Phishing Scam, Investigation Underway
Key Summary
Coldcard, a popular Bitcoin-only hardware wallet, is investigating how a phishing link appeared on its X account, despite using offline two-factor authentication and restricting access since 2017. The company has advised users not to visit or interact with the link, and is reviewing all account access.
Incident Report
Coldcard has reported a phishing link appeared on its X account, despite the company's rigorous security measures. The link was published on the account, which has been offline for two-factor authentication since 2017.
Investigation
The company is investigating how the link was published and is advising users not to visit or interact with it. Coldcard has contacted X and is reviewing all account access to determine the extent of the breach.
Context
This incident highlights the importance of security measures in protecting against phishing attacks. Coldcard's use of offline two-factor authentication and restricted access has been compromised, and the company must take steps to rectify the situation.
Industry Implications
The Coldcard exploit is part of a larger trend of cryptocurrency thefts, with July being the second-worst month of 2026 for crypto thefts. The incident serves as a reminder for users to remain vigilant and take steps to protect themselves against phishing attacks.
Conclusion
Coldcard's investigation into the phishing link is ongoing, and the company will share any further verified updates. In the meantime, users are advised to exercise caution and only interact with Coldcard's official website.