COLDCARD Investigates Phishing Post on Official X Account

COLDCARD is investigating an unauthorised phishing post published on its official X account on October 11. The deleted message falsely claimed there was an urgent Bitcoin wallet firmware vulnerability and urged users to move funds through the fraudulent domain migrate.coldcardwallet.io. COLDCARD says coldcard.com is its only official website and warns users not to visit the link. The hardware wallet maker says its account has used offline two-factor authentication and restricted access since 2017. Its initial review found no matching login, session or access records, and the company says its credentials and offline two-factor authentication remain secure. COLDCARD has asked X to investigate, but has not established how the post was published. The phishing message referred to a previously disclosed recovery-phrase generation issue. COLDCARD has not linked the incident to a new firmware vulnerability. No verified user losses have been reported, and the investigation is ongoing. Bitcoin traders and wallet users should verify security notices through official channels rather than social media links.
Neutral
The incident does not currently point to a new Bitcoin vulnerability, and there are no verified reports of user losses. COLDCARD says its account protections remain secure, while the cause of the unauthorised post is still under investigation. This limits the direct case for a sustained effect on BTC prices. In the short term, the phishing alert could prompt caution among wallet users and add some security-related concern, but it is unlikely to materially affect Bitcoin trading absent evidence of broader compromise or losses. Longer term, confirmed theft, a newly identified wallet flaw or wider account-security failures could weigh on confidence and create selling pressure. For now, the reported facts suggest a contained social-media incident rather than a change in Bitcoin’s fundamentals.