Bitcoin hardware wallet manufacturer Coldcard announced it is investigating the publication of a phishing link on its official X account. The company stated that the post, which has since been deleted, appeared on Sunday and was published from an account protected by offline two-factor authentication and tightly restricted access since 2017. Coldcard advised users not to interact with the link and confirmed that https://coldcard.com remains its only official website. The firm has contacted X support and is reviewing all account access logs to determine how the breach occurred.

This security incident follows a significant exploit earlier in 2026. In July, hackers stole at least $100 million in Bitcoin from 7,300 wallets across three confirmed attack waves targeting Coldcard devices, according to Galaxy Digital. A suspected fourth wave could raise total losses to approximately $130 million, while DefiLlama estimated losses tied to this specific exploit at $115 million. July emerged as the second-worst month for cryptocurrency thefts in 2026, with $247.4 million stolen overall, trailing only April’s $644 million loss.