The official X account of hardware wallet manufacturer Coldcard (@COLDCARDwallet) posted a phishing link on October 11, 2026, before the post was removed. The post contained a fake message disguised as an emergency alert regarding a firmware vulnerability in the recovery phrase generation process. The attacker directed the account’s followers to a spoofed website mimicking the official coldcard.com domain to harvest sensitive user data.
What makes the incident unusual is that Coldcard claimed its account security was never breached from the user end.
Coldcard stated that its social media account has had offline two-factor authentication (2FA) enabled with strict access controls since 2017. An internal audit of company logs found no suspicious login sessions or unauthorized access from any devices under its management. Seeing that the vulnerability did not originate from its own systems, the Coldcard team contacted X to urge an investigation into alleged abuse of administrator access rights within the social media platform.
Another finding supported the suspicion: Coldcard identified underground market advertisements selling X administrator accounts, although any direct connection to this incident has not been officially confirmed. The company reiterated that its only official domain is coldcard.com, and no confirmed financial losses have been reported from the October 11 attack.
Fake Alert Tactics and Past Firmware Vulnerabilities
The attacker’s choice to focus on firmware exploited long-standing concerns among wallet owners. In July 2026, a Coldcard firmware bug caused an estimated $115 million to $130 million in losses, according to Galaxy Digital data, due to non-random seed phrase generation, impacting 7,300 wallets.
Threats facing hardware wallet users were also highlighted by Lookonchain’s findings regarding an investor who held crypto assets untouched for eight years. Just a month after moving the funds to a new wallet, the victim lost 59 ETH worth $146.8k to the CryptoBillis Ledger Drainer - an unrelated case that illustrates the persistent risk of wallet drainer attacks in the hardware wallet ecosystem.
Official Firmware Versions and Protection Measures
To avoid fake download traps, Coldcard specified that the currently recommended firmware is version 5.6.3 for Mk4 and Mk5 models, and version 1.5.3Q for the Q model. Device owners are advised to verify updates directly through the official coldcard.com portal without ever clicking links from social media channels.
For crypto holders, the incident serves as a clear warning: a verification badge on social media does not guarantee that an emergency instruction is trustworthy. When an announcement demands your recovery phrase or prompts a sudden patch download, direct verification via the official website remains your final line of defense.
Reported via Cointelegraph.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




