Coldcard X account compromised; users warned of phishing scam

icon币界网
Share
AI summary iconSummary
A crypto scam alert has been issued after the Coldcard X account was compromised on October 11, 2026. Attackers posted a fake firmware alert for Mk4, Mk5, and Q models, directing users to a phishing site. This follows a security breach in July 2026, during which a vulnerability led to the theft of 1,800 BTC. Coldcard has reported the incident to X and believes the unauthorized access occurred at the platform or administrative level.
CoinDesk reports:

The official X account of Coldcard, a Bitcoin hardware wallet manufacturer, was compromised. On October 11, 2026, attackers posted a fraudulent notice under the brand’s name, claiming a “critical firmware vulnerability” in the Mk4, Mk5, and Q models, and urging users to immediately transfer funds via a phishing website.

This post emerged amid unprecedented anxiety in the crypto community. Hackers exploited the brand’s recent severe incident to make the scam appear more credible. The post has since been deleted.

Why is this fake notice so misleading?

The reason is that, in late July 2026, Coldcard experienced its greatest crisis in history. Due to a linker error in the device's code, wallets were generated using weak entropy (randomness). Instead of using a true random number generator (TRNG), the system relied on a vulnerable software algorithm. Hackers exploited this flaw through offline brute-force attacks, directly draining funds from the affected addresses without any phishing activity.

The first wave of theft began on July 30, 2026, with total losses estimated at approximately 1,600 to 1,800 BTC (equivalent to $100 million to $130 million at prevailing prices), making it one of the largest thefts of self-custodied assets this year.

The wallet manufacturer Coinkite subsequently released patched firmware versions: 4.2.0 for Mk3, 5.6.0 for Mk4/Mk5, and 1.5.0Q for Q. However, this software update does not automatically fix existing wallets. Users must manually generate new recovery phrases and migrate their assets.

This painful operational process is exactly what the scammers mimicked on October 11, listing the exact same "patched" firmware version in their phishing posts to create panic and trick users into transferring funds to the attacker's address.

The Coldcard team has officially contacted X support to request an urgent investigation. The company stated that this post may have been published via unauthorized access at the social network level or by bypassing security measures through its admin panel.

@Support — urgent escalation requested. A phishing post has appeared on our account, but we found no corresponding login, session, or access records. Our credentials and offline 2FA remain secure. This raises concerns about potential unauthorized access at the platform or admin backend level. We have also noticed reports that administrative account access on X is being sold on dark web marketplaces, although we cannot independently verify any connection between the two. Please retain all relevant logs and immediately initiate an investigation by your security team. This appears to be a targeted, highly specific attack. — COLDCARD (@COLDCARDwallet) October 11, 2026

Developers also noted that reports have surfaced claiming that internal tool access credentials for X are being sold on dark web marketplaces; however, there is currently no independent evidence confirming a connection between the two. The risk of fund loss is likely limited to users who manually enter their 24-word seed phrases on phishing sites due to panic.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.