Coldcard's X Account Hijacked to Push Fake Firmware Phishing Scam
Published October 11, 2026, 20:45 PKT. Based on October 11 reporting by U.Today, SpendNode and BitcoinNews on Coldcard's X account compromise, Coldcard's own statement on X, and July-September reporting by BTC Times, DART and Galaxy Research on the Coldcard entropy flaw.
One of the best-known names in Bitcoin self-custody spent Sunday fighting off a phishing attack on its own social media account. Attackers took over the official X account of Coldcard, the Bitcoin hardware wallet made by Coinkite, and published a fake notice claiming a critical firmware vulnerability affecting the Mk4, Mk5 and Q models. The post urged users to move their funds immediately through a linked phishing website, framing the move as urgent wallet migration. The company deleted the post and publicly warned its followers that the link was a scam.
The fake firmware alert that hit the Coldcard account
The unauthorized post appeared on @COLDCARDwallet on October 11, according to U.Today, SpendNode and BitcoinNews. It warned of a supposed critical vulnerability in recent Coldcard firmware and directed holders to what the outlets described as a fraudulent wallet security page with fake migration instructions. The post has since been removed from the account.
Coldcard responded with a public warning on X. The company said, "We are investigating how a post containing a phishing link was published from this account. It has since been deleted," and told users not to visit or interact with the link. It added that coldcard.com is its only official website, and promised more detail once the investigation's findings are confirmed, according to reports citing the statement.
No financial losses have been tied to the post, according to the reporting so far.
Why the scam was so convincing: it copied the July crisis
The phishing post was engineered to exploit fresh trauma. In late July 2026, Coldcard suffered what U.Today called the biggest crisis in its history: a linker error in the device firmware had routed seed generation through a weak software random number generator instead of the hardware random number generator, so new wallets were created with drastically reduced entropy. Coinkite disclosed in late July that certain Mk2 and Mk3 firmware versions generated seeds with roughly 40 bits of entropy instead of the intended 128 bits, according to BTC Times, citing the company's disclosure.
Attackers reconstructed those weak seeds offline and brute-forced the private keys without touching the devices, phishing no one. The first thefts began on July 30, 2026. DART, a digital-asset recovery organization, put later losses at more than 1,596 BTC, while Galaxy Research tracked about 1,816 BTC stolen across four waves, worth roughly $100 to $116 million at the time, according to BTC Times and other reports. Coinkite answered by urgently releasing patched firmware, versions 4.2.0 for the Mk3, 5.6.0 for the Mk4 and Mk5, and 1.5.0Q for the Q. Because a software update could not repair wallets already generated with weak seeds, users had to manually generate new seed phrases and migrate their assets, a painful process burned into the community's memory.
The October 11 scammers named exactly those patched firmware versions in their phishing post, U.Today reported, mimicking the real emergency procedure to push users into panic transfers. White-hat researchers did manage a small rescue from the July flaw: DART and independent researcher Nick Bax moved just over 50 BTC to a Wyoming trust so the funds could be returned to rightful owners, according to BTC Times.
Coldcard says its own systems show no breach
Coldcard's position is that the attackers did not get in through its own defenses. The company said its logs contained no records of unauthorized logins or sessions, and that its own credentials and its offline two-factor authentication method, which it says it has used since 2017 with tightly restricted access, remained secure, U.Today reported.
The company said it contacted X support to demand an urgent investigation. In the message cited by U.Today, Coldcard wrote, "A phishing post appeared on our account, yet we can find no corresponding login, session, or access record. Our credentials and offline 2FA remain secure." The company said the post appeared to bypass its security measures through unauthorized access at the social network level or via X's administrative panel, according to the report. X has not publicly responded yet.
The incident fits a pattern of social-channel takeovers targeting crypto brands. The hardware itself was not the attack surface this time; the trusted social channel was. Coldcard's advice stands on its own: no legitimate wallet maker asks for a recovery phrase or an immediate fund transfer through a link, and any urgent security post should be verified through the maker's official website before acting on it.
This article is news reporting and is not investment advice.
Sources
- Coldcard official statement on X (October 11, 2026), primary source confirming the phishing post, its deletion, the user warning, and the claim that no internal login or session records were found, cited via U.Today
- U.Today, "Coldcard Bitcoin Wallet Maker Compromised Again, This Time Online" (October 11, 2026), secondary source for the phishing post's contents, Coldcard's response, and the X support escalation
- SpendNode, "Coldcard's X Account Hijacked to Push a Wallet Phishing Scam" (October 11, 2026), secondary source for the incident framing and user guidance, citing BitcoinNews
- BTC Times, "White-Hat Researchers Rescue 50 Bitcoin From Coldcard Entropy Flaw" (September 2026), secondary source for Coinkite's late-July entropy disclosure, DART's loss estimates and the white-hat rescue
- DART and Galaxy Research (August-September 2026), secondary sources for the July theft waves and the ~1,600-1,816 BTC loss figures, cited via BTC Times
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
Russia Puts Crypto Miners on Lowest-Priority Power Under New Grid Rules
Russia's government adopted Resolution No. 1300 on October 6, requiring crypto mining farms, mining pools and mining infrastructure operators to accept Category 4 grid connections, the lowest reliability tier, meaning their electricity can be cut first during shortages. The Energy Ministry confirmed the change on October 9, saying miners can be disconnected without the advance coordination given to higher-priority users.
Two Wallets Accused of Gaming PaperTrade's Pricing System on Hyperliquid
On-chain observers allege two wallets are nudging Ethereum's price on Hyperliquid by about $20 million per trade, moving it 0.1 to 0.2 percent, while holding positions worth hundreds of millions on PaperTrade, which prices its synthetic trades off Hyperliquid's order book. PaperTrade's own documentation flags this best-bid-and-offer manipulation as a known protocol risk. No loss figure has been verified and PaperTrade has not publicly responded.
Triple-A Hacker Moves $12.4 Million in Ether to Tornado Cash
The attacker behind Triple-A's July treasury breach moved 4,970 ETH, worth about $12.4 million, into Tornado Cash on October 9 through 56 deposits, according to blockchain security firm Salus. The funds were consolidated from two intermediary wallets after crossing chains to Ethereum, a classic mixer-laundering pattern that lands while the mixer itself sits sanctions-free after the U.S. Treasury's March 2025 delisting.


