# COLDCARD’s Official X Account Compromised in Fake Firmware Alert

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/29863
Published: 2026-10-11T16:05:07.000Z
Updated: 2026-10-11T16:05:07.000Z
Section: Technology

> The deleted post falsely warned of vulnerabilities in Mk4, Mk5 and Q devices and directed users to a phishing website.

COLDCARD’s official X account was compromised Oct. 11 and used to promote a fake firmware-security warning that directed users to a phishing website targeting its Bitcoin hardware-wallet customers.

The post falsely claimed vulnerabilities affected COLDCARD Mk4, Mk5 and Q devices. COLDCARD deleted the message and warned users not to visit or interact with the linked site.

“We are investigating how a post containing a phishing link was published from this account. It has since been deleted. Do not visit or interact with that link,” COLDCARD said.

The company also said it had found no indication that its internal systems were breached and had contacted X support.

COLDCARD’s security guidance lists fixed firmware releases as version 5.6.0 or later for Mk4 and Mk5 devices, and version 1.5.0Q or later for Q devices. Its standard releases were listed as version 5.6.3 for Mk4 and Mk5 and version 1.5.3Q for Q as of Oct. 1.

COLDCARD is a Bitcoin hardware-wallet brand made by Coinkite. Its security guidance says firmware updates address future seed generation but do not repair an existing seed created with affected firmware.
