Bitcoin hardware wallet manufacturer Coldcard announced it is investigating the publication of a phishing link on its official X account. The company stated that the post, which has since been deleted, appeared on Sunday and was published from an account protected by offline two-factor authentication and tightly restricted access since 2017. Coldcard advised users not to interact with the link and confirmed that https://coldcard.com remains its only official website. The firm has contacted X support and is reviewing all account access logs to determine how the breach occurred.
This security incident follows a significant exploit earlier in 2026. In July, hackers stole at least $100 million in Bitcoin from 7,300 wallets across three confirmed attack waves targeting Coldcard devices, according to Galaxy Digital. A suspected fourth wave could raise total losses to approximately $130 million, while DefiLlama estimated losses tied to this specific exploit at $115 million. July emerged as the second-worst month for cryptocurrency thefts in 2026, with $247.4 million stolen overall, trailing only April’s $644 million loss.
The compromise of an account secured by offline two-factor authentication and restricted access since 2017 raises critical questions about operational security protocols within hardware wallet firms. While the immediate threat was a phishing link rather than a direct device vulnerability, the incident undermines user confidence in the isolation measures designed to protect high-value assets. It suggests that even entities with long-standing security practices may face sophisticated social engineering or internal access control failures that bypass traditional digital safeguards.
For institutional adoption and market structure, repeated security breaches involving major hardware wallet providers create friction in the custody ecosystem. The prior July exploit, which resulted in substantial Bitcoin losses, already highlighted vulnerabilities in supply chain or firmware integrity. This subsequent social media compromise indicates a broader pattern of operational risk that extends beyond technical code to human and procedural factors. Stakeholders must monitor whether Coldcard’s investigation reveals systemic weaknesses in their communication channels, as trust in these infrastructure providers is foundational to secure self-custody solutions.


