1 min read
Add as a preferred source on Google

COLDCARD’s Official X Account Compromised in Fake Firmware Alert

The deleted post falsely warned of vulnerabilities in Mk4, Mk5 and Q devices and directed users to a phishing website.

Mentioned assets
Hardware wallet beside a smartphone showing a warning screen / TokenPost.ai (mono)
Hardware wallet beside a smartphone showing a warning screen / TokenPost.ai (mono)

COLDCARD’s official X account was compromised Oct. 11 and used to promote a fake firmware-security warning that directed users to a phishing website targeting its Bitcoin hardware-wallet customers.

The post falsely claimed vulnerabilities affected COLDCARD Mk4, Mk5 and Q devices. COLDCARD deleted the message and warned users not to visit or interact with the linked site.

“We are investigating how a post containing a phishing link was published from this account. It has since been deleted. Do not visit or interact with that link,” COLDCARD said.

The company also said it had found no indication that its internal systems were breached and had contacted X support.

COLDCARD’s security guidance lists fixed firmware releases as version 5.6.0 or later for Mk4 and Mk5 devices, and version 1.5.0Q or later for Q devices. Its standard releases were listed as version 5.6.3 for Mk4 and Mk5 and version 1.5.3Q for Q as of Oct. 1.

COLDCARD is a Bitcoin hardware-wallet brand made by Coinkite. Its security guidance says firmware updates address future seed generation but do not repair an existing seed created with affected firmware.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…