Short answer: On Sunday, October 11, 2026, a fake security alert appeared on the official X account of Bitcoin hardware wallet maker Coldcard, claiming a seed-generation flaw in recent firmware and urging users to "migrate" funds through a lookalike website. Coldcard deleted the post, said its only official site is coldcard.com and is investigating with X how the post was published. No verified user losses had been reported by the end of the day.
What happened
At around 02:00 UTC on October 11, a post went up on Coldcard's verified X account dressed as an urgent warning. It said a critical problem affected how recent firmware generated recovery phrases and pushed holders to move their bitcoin through a "security migration". The link led to migrate.coldcardwallet.io, a domain that does not belong to the company.
Coldcard, made by Canadian firm Coinkite, removed the post and responded on the same account:
- Do not click: users were told not to visit or interact with the link, and that coldcard.com is the only official website.
- No login found: the company said the account has used offline two-factor authentication and tightly restricted access since 2017, and its review found no matching login, session or access record for the post.
- Platform question: Coldcard contacted X and asked it to investigate whether the platform itself or account credentials were compromised. That remains an open question, not an established finding.
- Verified updates only: the company said it will publish further information only once it is confirmed.
It is not known how long the post stayed up or whether the site collected recovery phrases or served malware.
Why the fake Coldcard alert looked believable
The lure borrowed from a real event. In July 2026, Coldcard disclosed that some older firmware versions did not use the intended hardware randomness source when generating seeds, which left certain wallets guessable. Attackers then drained affected devices in several waves, a story we followed in our report on the Coldcard wallet hack.
| Estimate | Losses from the July–August firmware exploit |
|---|---|
| Galaxy Digital, three confirmed waves | At least $100 million from about 7,300 wallets |
| DefiLlama hack tracker | About $115 million |
| Galaxy Digital, with a suspected fourth wave | About $130 million |
The October 11 post did not reveal a new vulnerability; it repackaged the old one. Phishing had already been circling: on August 5, researchers at Unclone reported ten lookalike domains registered within five days of the July disclosure and 97 Coldcard- or Coinkite-branded social accounts, 34 of them posing as support staff. The difference this time is that the scam came from the brand's own verified account.
A week of hardware wallet scares
The incident follows a separate case two days earlier, when Ledger asked Southeast Asian reseller CryptoBilis to pause sales after buyers reported more than $86 million in drained wallets (see our Ledger CryptoBilis report). The two cases differ: Ledger's involves suspected tampering before devices reached customers, while Coldcard's is a social media hijack that only works if a user hands over their seed. Together they show where attackers aim now: not at the chip, but at the supply chain and at the owner.
What it means for you
- Never type a seed into a website. Coldcard's own instructions say recovery words must never be entered on another device or shared with a site or support agent. A real firmware fix does not ask for them.
- Do not move funds because of a post. Even a verified account can be hijacked. Check the official site directly before acting on any urgent alert.
- Know which firmware fix applies. Current releases are 5.6.3 for Mk4 and Mk5 and 1.5.3Q for the Q. Updating does not repair a seed created on vulnerable firmware; such wallets need a new seed and a transfer.
- If you entered your words, act fast. Move remaining funds to a wallet with a newly generated seed on a trusted device, and double-check the network and address before you send.
Key takeaways
- A phishing post went up on Coldcard's official X account at about 02:00 UTC on October 11, 2026.
- It linked to migrate.coldcardwallet.io and claimed a seed-generation bug in recent firmware.
- Coldcard says it found no unauthorized login and has asked X to investigate.
- No verified losses were reported; the July–August firmware exploit cost an estimated $100–130 million.
Phishing through hijacked accounts is one of the oldest tricks in crypto. Our guide on how to avoid crypto scams explains the patterns to watch for.
Frequently asked questions
Was Coldcard's X account hacked?
On October 11, 2026, a phishing post appeared on Coldcard's official X account and was deleted. Coldcard says it found no unauthorized login on its side and has asked X to investigate whether the platform or credentials were compromised.
Is there a new Coldcard firmware vulnerability?
Coldcard has not confirmed any new vulnerability. The fake post repackaged a seed-randomness flaw in older firmware that the company disclosed in July 2026, for which patched firmware already exists.
What should I do if I entered my Coldcard seed on the phishing site?
Treat the wallet as compromised. Generate a new seed on a trusted device and move your remaining funds to it as quickly as possible, and never enter recovery words on any website.