Coldcard Bitcoin Wallet X Account Hacked as Attackers Push Fake Security Alert
0
0

In Brief:
- Hackers compromised Coldcard’s official X account and posted a fraudulent firmware warning directing Bitcoin wallet users toward a phishing website.
- The phishing campaign exploited Coldcard’s previous firmware vulnerability, which reportedly caused substantial Bitcoin losses and required affected users to migrate funds.
- Coldcard found no evidence of internal system breaches and requested an X investigation, while potential phishing losses remain unconfirmed.
Bitcoin hardware wallet manufacturer Coldcard has warned users about a phishing attack involving its compromised official X account. Attackers used the account to publish a fraudulent security warning targeting owners of several Coldcard wallet models.
On October 11, hackers claimed that a critical firmware vulnerability affected the Mk4, Mk5, and Q devices. The fraudulent announcement directed users to a phishing website and urged them to move their Bitcoin immediately.
Coldcard subsequently removed the post and confirmed that unauthorized parties had accessed its social media account. The incident raised security concerns because attackers referenced an earlier vulnerability involving the company’s hardware wallets.
Also Read: Cardano (ADA) Flashes Death Cross as Price Faces Risk of Further Decline
Hackers Exploit Previous Coldcard Firmware Vulnerability to Target Bitcoin Holders
The phishing campaign closely resembled security instructions Coldcard issued during a major wallet vulnerability in July 2026. That incident involved a software linking error that weakened the randomness used to generate wallet credentials.
Consequently, attackers could potentially reconstruct vulnerable wallet credentials through offline brute-force attacks without obtaining users’ recovery phrases through phishing.
Reports estimated that the earlier security failure resulted in losses ranging between 1,600 and 1,800 BTC. The estimated financial damage reached approximately $100 million to $130 million at the time.
Coinkite, Coldcard’s manufacturer, responded by releasing firmware updates designed to address the underlying security weakness. These included version 4.2.0 for Mk3 devices and version 5.6.0 for Mk4 and Mk5 wallets.
The company also released version 1.5.0Q for its Q hardware wallet model. Importantly, installing the updated firmware did not automatically secure wallets generated with potentially compromised randomness.
Affected users needed to create new recovery phrases and transfer their Bitcoin into newly generated wallets. Attackers exploited these earlier instructions by referencing the same firmware versions in their fraudulent announcement. Their message presented the phishing website as an emergency security measure, potentially encouraging users to disclose sensitive wallet information.
Coldcard Denies Internal Security Breach as X Account Investigation Begins
Coldcard maintained that its internal systems showed no evidence of unauthorized access during the October 11 incident. According to the company, security logs contained no suspicious login records or unauthorized account sessions.
The manufacturer also reported that its credentials and offline two-factor authentication procedures remained secure. Coldcard has used its offline authentication approach since 2017 to protect account access.
Meanwhile, the company contacted X support and requested an investigation into how attackers gained control of its account. Coldcard suggested that unauthorized platform-level access or administrative tools could explain the incident.
Developers also referenced reports concerning the alleged sale of X internal access tools on underground markets. Nevertheless, investigators have not established any verified connection between those reports and the Coldcard account compromise. The company has not confirmed whether users entered their recovery phrases into the fraudulent website or suffered financial losses.
Conclusion
The October 11 compromise exposed Coldcard users to a phishing campaign built around the manufacturer’s previous security incident. Investigators have yet to establish the access method or determine whether attackers successfully obtained users’ Bitcoin recovery phrases.
Also Read: Shiba Inu Selling Pressure Eases as Exchange Netflows Drop to 65 Billion SHIB
The post Coldcard Bitcoin Wallet X Account Hacked as Attackers Push Fake Security Alert appeared first on 36Crypto.
0
0
Securely connect the portfolio you’re using to start.





