COLDCARD Warns of Phishing Post on Its Official X Account

COLDCARD Warns of Phishing Post on Its Official X Account

Phishing link posted from COLDCARD's official X account

Coinkite, the company behind the COLDCARD Bitcoin hardware wallet (a physical device that stores Bitcoin securely offline), announced on October 11 that a phishing link was published from COLDCARD's official X account. The post claimed an urgent COLDCARD security update and warned of a new seed-generation vulnerability. It then directed users to a lookalike website to migrate their wallets. The link has since been deleted.

How the fake migration site worked

A researcher named PortlandHODL published a technical analysis of the fake site. According to the analysis, the site copied COLDCARD's branding and asked visitors for a 12- or 24-word seed phrase and an optional passphrase. A seed phrase is a set of words used to recover the Bitcoin held in a hardware wallet. The researcher said they tested the site's code in a sandboxed environment and observed it sending the entered recovery data to an external server.

What COLDCARD confirmed

  • COLDCARD identified coldcard.com as its only official website and warned users never to enter seed words or passphrases into any website.
  • The company stated it had used offline two-factor authentication with tightly restricted access on the X account since 2017.
  • COLDCARD said its credentials and offline two-factor authentication remained secure.
  • The company contacted X to preserve logs and investigate what happened.

What remains unclear

COLDCARD said in a follow-up post that it could find no corresponding login, session, or access record for the phishing post. Neither statement specified how long the phishing post had been visible to the public or whether any funds were lost as a result. The account-access mechanism — how the post was published despite restricted credentials — remains unresolved.

The earlier firmware flaw this follows

The phishing attempt comes after a July firmware vulnerability that weakened COLDCARD seed generation. Attackers exploited that weak seed generation to regenerate private keys offline and steal funds, with roughly $114 million lost across a fourth wave of attacks. Coinkite's genuine advisory stated that a firmware update alone does not repair an existing seed. The official migration guide instructs users to install fixed firmware, generate a new seed on the device, verify the replacement wallet, and send a small test transaction before moving the remaining balance.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!