1 min read
Add as a preferred source on Google

COLDCARD Says Official X Account Posted Phishing Link After Suspected Compromise

The deleted post directed users to a fake wallet migration guide. COLDCARD said its credentials and offline two-factor authentication remain secure.

Smartphone beside a hardware wallet under mixed nighttime lighting / TokenPost.ai
Smartphone beside a hardware wallet under mixed nighttime lighting / TokenPost.ai

COLDCARD’s official X account appears to have been compromised after posting a fake security notice that directed crypto users to a phishing site posing as a wallet migration guide.

The post was deleted, and COLDCARD said it found no corresponding login, session or access records. The hardware wallet maker also said its account credentials and offline two-factor authentication remain secure.

Based on those findings, COLDCARD suspects the attacker may have obtained access at the X platform or administrator level. The company has asked X’s security team to investigate urgently.

The incident creates an immediate risk for users who may mistake fraudulent migration instructions for an official COLDCARD security update.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…