COLDCARD warned Bitcoin users on October 11 after a phishing link appeared in a post from its official X account, turning a familiar security-information channel into a potential route to fraudulent instructions.
In a company statement embedded in crypto.news reporting, the hardware-wallet maker said it was investigating how the message had been published and that it had since been deleted. It told users not to visit or interact with the link and identified coldcard.com as its official website.
The warning concerns a social-media post. It is not confirmation that a new defect in COLDCARD devices or firmware allowed someone to take users' Bitcoin. The account incident and the security of a customer's signing keys are separate questions.
The message borrowed the authority of a trusted account
Crypto.news reported that the unauthorized message presented itself as a security update and pointed readers toward a fraudulent migration process. The important risk was the instruction to act on a link carrying the wallet maker's apparent authority, not merely the appearance of an unfamiliar account impersonating the brand.
The company statement says its account has used offline two-factor authentication and tightly restricted access. Those controls describe its security arrangements; they do not explain how this particular post appeared. The mechanism remains under investigation, and a completed account-forensics finding has not been established in the reviewed evidence.
Direct access to the original X statement was unavailable during our checks. The company warning was reviewed through its embedded post in accessible reporting, with the October 11 incident separately described by other publications. That limits what can be asserted about subsequent account activity or the progress of an investigation.
A recovery phrase is spending authority, not a support credential
Our self-custody guide explains why a recovery backup must be treated differently from an ordinary account password. For conventional key-based wallets, usable recovery material can recreate signing authority on another compatible device. A legitimate-looking web page does not change that consequence.
A hardware device and a backup are therefore different security boundaries. Keeping the device physically safe does not protect a phrase voluntarily entered into an untrusted interface. Conversely, a deceptive social-media post does not demonstrate that every device bearing the brand has been compromised.
A hypothetical request to confirm a shipping address and a request to enter wallet-recovery words are not equivalent. The first concerns account or contact information. The second may hand over authority to assets. Treating both as routine customer-service verification obscures the larger risk of the latter.
Deletion does not turn the original instruction into a safe one
Removing a post reduces its continued distribution from that account, but does not authenticate screenshots, reposts or links already copied elsewhere. Users encountering a purported urgent migration notice need to verify the instruction through the manufacturer's established information channels rather than rely solely on the account name attached to it.
The reviewed warning does not establish verified user losses or a completed explanation for the unauthorized publication. It also does not justify connecting this incident to any earlier device-security issue without separate evidence. Today's confirmed reporting concerns the phishing message, its removal and the manufacturer's warning against following it.
