Coldcard, a hardware wallet that supports only Bitcoin, reported that a phishing link was posted on its official X (formerly Twitter) account on Sunday. The post has since been removed.
The company said it uses offline two‑factor authentication and has tightly restricted account access since 2017. It is investigating how the malicious link was published and has contacted X for assistance while reviewing all account access.
Coldcard advised users not to visit or interact with the link and reminded them that its only official website is https://coldcard.com. The firm said it will share any further verified updates as the investigation progresses.
Context of recent Coldcard activity
Earlier reports indicated that July was the second‑worst month of 2026 for cryptocurrency thefts, with a Coldcard‑related exploit accounting for a large share of the losses. Hackers stole roughly $247.4 million in crypto in July, the highest amount for the year after April’s $644 million loss, according to data from DefiLlama.
The Coldcard exploit was identified as the month’s biggest single event, with at least $100 million in Bitcoin taken from about 7,300 wallets across three confirmed attack waves, according to Galaxy Digital. A suspected fourth wave could raise total losses to around $130 million, while DefiLlama’s hack tracker estimated Coldcard‑related losses at $115 million.


