Coldcard says it’s investigating how phishing link appeared on its X account
Bitcoin-only hardware wallet Coldcard said a phishing link appeared Sunday on its official X account, for which it has used offline two-factor authentication and tightly restricted access sin
A
AnonymousCryptoCompass newsroom
October 11, 2026
2 min read
NEWS
CryptoCompass editorial visual for bitcoin coverage.
Bitcoin-only hardware wallet Coldcard said a phishing link appeared Sunday on its official X account, for which it has used offline two-factor authentication and tightly restricted access since 2017.
The company said it was investigating how the post, which has since been deleted, was published from its account.
It advised users not to visit or interact with the link in question, adding that Coldcard’s only official website is https://coldcard.com.
The company has contacted @X and is reviewing all account access. Coldcard said it will share any further verified updates.
Cointelegraph reported earlier that July had emerged as the second-worst month of 2026 for cryptocurrency thefts, largely due to a Coldcard exploit.
Hackers stole $247.4 million in crypto in July, the most this year after the $644 million stolen in April, according to DefiLlama data.
The Coldcard exploit was the month’s biggest exploit, with at least $100 million in Bitcoin (BTC) stolen from 7,300 wallets across three confirmed attack waves, according to Galaxy Digital.
The company also identified a suspected fourth wave that could bring total losses to about $130 million.
DefiLlama’s hack tracker estimated losses tied to the Coldcard exploit at $115 million.
Starknet's STRK token surged more than 53% intraday to nearly $0.11, making it the standout mid-cap gainer of the weekend while Bitcoin continued trading sideways around $83,000 for roughly 3
ERC-20 Tokens Explained Through Ethereum’s Token Standards and Smart Contracts Open any Ethereum wallet, and a pattern shows up fast. Stablecoins, governance-tokens, and exchange coins all se
Ledger has confirmed that a hardware wallet belonging to one affected customer contained an unauthorized hardware implant, moving its investigation into cryptocurrency losses tied to Southeas