Coldcard, the Bitcoin hardware wallet built by Coinkite, is investigating a phishing post that appeared on its official X account. The post was disguised as an urgent security warning and directed users to a domain called migrate.coldcardwallet.io.
The fraudulent post appeared around 02:00 UTC on October 11, 2026, claiming there was a critical issue with seed generation in recent Coldcard firmware. Coldcard advised users not to visit or interact with the link and said it would share further updates only once verified.
Account Security Findings
After the post appeared, Coldcard conducted an internal review and found no unauthorized access or logins on the account. The company credits offline two-factor authentication, which it has used since 2017, with protecting the account.
Coldcard has requested an urgent investigation from X to determine whether the platform itself or account credentials were compromised.
Context and Timing
The phishing message referenced a security issue that had already been disclosed earlier in 2026, rather than revealing a new vulnerability. A major exploit in July and August 2026 affected Coldcard devices, resulting in the loss of over 1,700 BTC valued at approximately $100 million to $130 million.
No verified user losses have been reported in connection with the phishing post so far.
Guidance for Users
Coldcard users should not click suspicious links or move funds based on social media posts. Legitimate firmware fixes do not require entering seed phrases on websites, and any such prompt should be treated as a red flag regardless of which account it comes from.


