Coldcard launches probe into suspicious phishing link posted from official X account
The wallet manufacturer has warned customers against clicking the suspicious link and promised to provide additional confirmed information as it becomes available.

Hardware wallet manufacturer Coldcard, which specializes in Bitcoin-only solutions, reported on Sunday that a malicious phishing link was posted through its verified X account, despite the platform having offline two-factor authentication measures and strictly limited access controls in place since 2017.
According to the company's statement, an investigation is currently underway to determine the method by which the post, which has now been removed, managed to be published through its official account.
The firm issued a warning to its user base, urging them to avoid clicking on or engaging with the suspicious link, while emphasizing that https://coldcard.com remains the sole legitimate website for Coldcard.
The wallet manufacturer has reached out to @X regarding the incident and is conducting a comprehensive review of all account access permissions. According to Coldcard's statement, the company will distribute any additional verified information as the investigation progresses.
Earlier reporting from Cointelegraph indicated that July had become the second-most damaging month of 2026 in terms of cryptocurrency theft, with a Coldcard security breach contributing significantly to the losses.
During July, malicious actors managed to steal $247.4 million worth of cryptocurrency, making it the year's second-highest theft total following April's record of $644 million stolen, based on data compiled by DefiLlama.
The security breach affecting Coldcard users represented July's most significant exploit, resulting in the theft of no less than $100 million in Bitcoin (BTC) from approximately 7,300 individual wallets throughout three confirmed waves of attacks, as documented by Galaxy Digital.
Galaxy Digital's research team also pinpointed a potential fourth attack wave that could push the aggregate losses to approximately $130 million.
According to DefiLlama's comprehensive hack tracking system, the estimated financial impact associated with the Coldcard security exploit reached $115 million.