1 min read
Add as a preferred source on Google

Coldcard Deletes Phishing Post After More Than $100 Million in Losses

The fake firmware warning appeared Saturday night and directed users to a malicious website. Coldcard reported no confirmed financial losses from the phishing post.

Mentioned assets
Hardware wallet beside a smartphone displaying a blurred webpage / TokenPost.ai (mono)
Hardware wallet beside a smartphone displaying a blurred webpage / TokenPost.ai (mono)

Coldcard deleted a phishing post from its official X account after the message falsely warned of a firmware vulnerability and directed customers to a malicious website, adding a new security concern for the Bitcoin hardware-wallet maker.

The post appeared at about 10 p.m. ET on Oct. 10 (0200 UTC Oct. 11) and urged users to move funds. Coldcard acknowledged the incident at about 1:46 a.m. ET on Oct. 11 (0546 UTC), told customers not to use the link and said it was investigating how the message was published.

Coldcard said it found no corresponding unauthorized login, session or access record. The company also said it has used offline two-factor authentication and restricted account access since 2017. No financial loss has been confirmed from the phishing post.

The incident follows a July firmware flaw that weakened seed generation, allowing attackers to reconstruct vulnerable private keys offline. The confirmed theft reached 1,596 Bitcoin (BTC) from about 7,300 addresses across three attack waves and 14 smaller incidents, exceeding $100 million in losses.

Coldcard’s security guidance says affected users must generate new seeds and migrate their funds. Installing fixed firmware protects future seed generation but does not repair a wallet created with a vulnerable seed.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…