Coldcard says it’s investigating how phishing link appeared on its X account
Bitcoin hardware wallet provider Coldcard is investigating how a phishing link appeared on its official X account, despite using robust security measures since 2017. Users have been advised not to interact with the malicious link.
Intelligence analysis by Gemini 2.5 Flash

Coldcard, a prominent Bitcoin hardware wallet company, is probing a security breach on its official X (formerly Twitter) account, where a phishing link was posted. This incident follows a significant exploit earlier in 2026 that saw millions in Bitcoin stolen from Coldcard users, raising renewed concerns about the security of its public communication channels.
Imagine you have a super-safe piggy bank for your digital money, called Coldcard. Someone sneaky managed to put a fake sign on their official message board (like a school bulletin board) telling people to go to a bad website. Coldcard is now trying to figure out how that fake sign got there, especially since they have really strong locks on their message board. This is extra worrying because earlier this year, a lot of money was already stolen from people using Coldcard, like someone picked the locks on many piggy banks at once.
Analysis
The recent appearance of a phishing link on Coldcard's official X account has sent ripples of concern through the cryptocurrency community, particularly given the company's prior security incidents. Coldcard, a well-regarded Bitcoin-only hardware wallet manufacturer, stated that it is actively investigating how the malicious post was published. The company emphasized that its X account has been secured with offline two-factor authentication and tightly restricted access since 2017, suggesting a sophisticated breach or an internal lapse. Users were immediately warned against visiting or interacting with the fraudulent link, and Coldcard reiterated that its sole official website is https://coldcard.com. The firm has also initiated contact with X's support team and is conducting a comprehensive review of all account access logs. This proactive, albeit reactive, response is crucial for maintaining user trust in a sector where security is paramount.
Coldcard
Coldcard's immediate response to the phishing incident on its X account involved deleting the malicious post and issuing a clear warning to its user base. The company's assertion of having robust security measures, including offline two-factor authentication and restricted access since 2017, indicates that the breach was unexpected and potentially complex. The investigation is focused on understanding the vector of attack, whether it was an internal compromise, a sophisticated social engineering tactic, or a vulnerability within the X platform itself. For a hardware wallet provider, whose core business is securing digital assets, any compromise of its official communication channels can severely erode user confidence. The company's commitment to sharing verified updates is a positive step towards transparency, which is vital in rebuilding and maintaining trust within the crypto ecosystem.
July 2026
This latest security scare comes on the heels of a much larger and more damaging exploit that affected Coldcard users in July 2026. That month emerged as the second-worst for cryptocurrency thefts in 2026, largely attributed to the Coldcard exploit. According to Cointelegraph, hackers managed to steal at least $100 million in Bitcoin from approximately 7,300 wallets across three confirmed attack waves. Galaxy Digital's analysis further suggested a potential fourth wave, which could push total losses to an estimated $130 million. This prior incident highlights a pattern of security challenges for Coldcard, making the current phishing link incident particularly alarming. The cumulative impact of these events could lead to a re-evaluation of security protocols not just by Coldcard, but by other hardware wallet providers and users alike.
DefiLlama
The financial impact of the July 2026 Coldcard exploit was significant, with DefiLlama data indicating that $247.4 million in crypto was stolen that month, making it the highest figure after April's $644 million. DefiLlama's hack tracker specifically estimated losses tied to the Coldcard exploit at $115 million, underscoring the scale of the attack. These figures from reputable data aggregators like DefiLlama provide a critical, independent perspective on the severity of the security breaches affecting the crypto space. The consistent reporting of such incidents by platforms like Cointelegraph, citing data from sources like DefiLlama and Galaxy Digital, helps to inform the community about ongoing threats and the financial consequences of security lapses. This transparency is essential for users to make informed decisions about their digital asset security practices.
Key points
- A phishing link appeared on Coldcard's official X account, prompting an immediate investigation by the company.
- Coldcard stated its X account has used offline two-factor authentication and restricted access since 2017.
- Users were advised not to visit or interact with the malicious link, with Coldcard confirming its only official website is coldcard.com.
- The incident follows a major Coldcard exploit in July 2026, which resulted in at least $100 million in Bitcoin being stolen.
- DefiLlama data estimated losses from the July exploit at $115 million, contributing to a significant month for crypto thefts.
Coldcard's swift investigation into the phishing link incident could lead to the identification and patching of any vulnerabilities, ultimately strengthening their security protocols and communication channels. This proactive approach, coupled with transparency, might help restore user confidence and prevent similar incidents in the future.
The repeated security incidents, including a major exploit earlier in 2026 and now a phishing link on its official X account, could severely erode user trust in Coldcard's ability to secure digital assets and communications. This could lead to users migrating to alternative hardware wallets, potentially impacting Coldcard's market position and reputation.



