Hardware Wallet Manufacturer COLDCARD Claims Its Official X Account Previously Posted Phishing Links, Now Deleted
Hardware wallet manufacturer COLDCARD claims that its official X account previously posted a message containing phishing links, which has now been deleted, and suspects unauthorized access at the platform level.
COLDCARD stated in a post on its official account that the message contained links to phishing websites disguised as wallet migration guides, which have been deleted, and warned users not to visit, with the official website being coldcard.com. The account has used offline 2FA since 2017 and strictly limited access.
The team has contacted the X platform, is reviewing all account permissions, and will release further verification updates. COLDCARD stated that no corresponding login, session, or access records were found, and that credentials and offline 2FA remain secure, leading to suspicions that unauthorized posting may have been achieved through X platform-level or administrator privileges.
The company has requested an urgent upgrade from X support, asking the security team to immediately investigate and preserve relevant logs, stating that this is a targeted attack. They also mentioned unverified reports of X administrator accounts being sold on the dark web, but have not confirmed any connection to this incident.
The phishing post contained false security announcements claiming to have discovered critical vulnerabilities in firmware seed generation and guiding users for "cautious migration." COLDCARD is a manufacturer of hardware wallets specifically for Bitcoin, emphasizing air-gapped and physical signature security.
As a result of the incident, users may transfer assets to phishing sites due to false official announcements, with funds and trust shifting from official channels to attackers; hardware wallet users face short-term pressure to verify sources, while the attack path relying on platform administrator privileges makes social platform security a key risk point.
Source: Public Information
ABAB AI Insight
COLDCARD, developed by Coinkite, has long positioned itself as a Bitcoin-specific air-gapped hardware wallet, emphasizing seed generation, physical confirmation, and offline signing to combat risks associated with software wallets and exchange custody; historically, it has been linked to losses of tens of millions to over a hundred million dollars in Bitcoin due to entropy defects and firmware issues, leading to subsequent phishing activities.
In terms of capital pathways, attackers guide users to phishing domains by forging official security announcements, attempting to obtain seeds or transfer funds; platform resources are used for investigation and log preservation, while the trust in social platforms as official communication channels is exploited. The motivation is to utilize high-trust official accounts to bypass user vigilance, directly targeting self-custodied user assets.
This is similar to other cases where official accounts of crypto projects have been hijacked to post false migration or security updates, and is akin to phishing targeting traditional banks or exchange customer service; the current self-custody and hardware wallet sector is transitioning from device-level security to the security of communication channels and platform permissions, with official accounts becoming a new attack surface.
Essentially, this represents a reconstruction of the industry chain: the security boundary of hardware wallets extends from the device itself to the social platform publishing channels, with the mechanism being that offline 2FA and credential security cannot defend against platform administrator-level access, allowing attackers to post highly credible phishing content without needing to compromise devices, thus shifting the risk of the self-custody industry chain from key management to third-party platform trust and log auditing, prompting users and manufacturers to increase independent cryptographic verification channels.
ABAB News · Cognitive Laws
Offline 2FA cannot stop the hands of platform administrators.
Official announcements can be the highest form of phishing.
The boundaries of self-custody ultimately hinge on third-party accounts.