Published

Technology and Scienceupdated 1h ago2 min read

Coldcard Investigates Phishing Link Posted From Its Official X Account

This article is an automated aggregation of coverage from news outlets. Our editorials offer in-depth analysis curated by the NewsCord team.

Phishing link appeared on Coldcard's official X account and was deleted. Company used offline 2FA; no unauthorized logins detected.

Coldcard Investigates Phishing Link Posted From Its Official X Account
Image: TradingView

Phishing on Coldcard X

Coldcard said it was investigating how a phishing link appeared on its official X account, and the company advised users not to visit or interact with the link in question. Coldcard told users that its only official website is https://coldcard.com while it reviewed account access after the phishing post was deleted.

Coldcard said it was investigating how the post, which has since been deleted, was published from its account. Coldcard also said it has used offline two-factor authentication and tightly restricted access since 2017, and it contacted @X as part of the review.

Image from bitcoin.es
Image: bitcoin.es
Reporting for this sectionCointelegraphCrypto Briefing

No logins, X review

Coldcard said it ran an internal review after the post appeared and that the review found no unauthorized access or logins on the account. Coldcard said it asked X for an urgent investigation and wanted to know whether the platform itself or account credentials were compromised.

Coldcard said it could not identify a login, session or access record corresponding to the unauthorized publication, and it maintained that its credentials and offline authentication measures remained secure. Coldcard also warned that the phishing message did not reveal any new firmware vulnerability, and it referenced a security issue that had already been disclosed earlier in 2026.

Reporting for this sectionCrypto Briefinghttps

Broader theft context

Cointelegraph tied the incident to a wider theft backdrop, saying July had emerged as the second-worst month of 2026 for cryptocurrency thefts, largely due to a Coldcard exploit. Cointelegraph reported that hackers stole $247.4 million in crypto in July, after $644 million stolen in April, and it said the Coldcard exploit was the month’s biggest exploit with at least $100 million in Bitcoin stolen from 7,300 wallets across three confirmed attack waves.

Galaxy Digital estimated a suspected fourth wave that could bring total losses to about $130 million, while DefiLlama’s hack tracker estimated losses tied to the Coldcard exploit at $115 million. Coldcard said no verified user losses had been reported in connection with the post so far, and it said it would share further verified updates only once they are verified.

Reporting for this sectionCointelegraphCrypto Briefing