FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.8T -0.7%24h Vol $43.7B -6.7%Fear & Greed 61/100Alts Index 53/100
BTC.D 59.3% +0.1%Stable.D 9.4% 0%ETH.D 10.9% 0%Others.D 20.4% -0.1%
STRK$0.1146+58.58%•CHIP$0.0676+29.91%•CFX$0.0680+26.4%•TIA$0.5785+20.25%•S$0.0503+17.56%•SENT$0.0231+16.2%•CARDS$0.3172+15.25%•ZK$0.0161+14.7%•GRASS$0.7192+12.08%•BAT$0.1456+9.76%•
APEPE$0.00000129-11.27%•BP$1.115-9.2%•DRV$0.5065-7.49%•ORCA$2.358-7.19%•Q$0.0289-6.99%•PONS$0.3557-4.57%•AKE$0.0261-4.53%•KAIA$0.0533-4.5%•QNT$242.34-3.74%•LIT$3.578-3.74%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Coldcard Probes Phishing Post From Official X Account After…

      Bitcoin hardware wallet maker Coldcard is investigating how a phishing link was published from its official X account on Sunday despite what the company describes as tightly restricted access and offline two-factor authentication in place since 2017.The unauthorized post, which has since been deleted, presented itself as an urgent security warning and directed users toward a fake wallet-migration website. Coldcard told customers not to interact with the link and stressed that coldcard.com is its only official website.The company said its initial review found no corresponding login, session or access record explaining how the post appeared. It has contacted X and asked the platform to investigate while Coldcard reviews account permissions and access records.As of October 11, Coldcard has not disclosed any confirmed financial losses resulting from the phishing attempt or established who published the message.

      What Was the Phishing Post Trying to Do?

      The deleted message reportedly claimed that a new vulnerability had been found in Coldcard’s seed-generation process and instructed users to migrate their Bitcoin through a separate website.Security researchers who examined the fraudulent site found that it requested 12- or 24-word recovery phrases and optional passphrases. Anyone supplying those credentials would effectively give an attacker the information needed to recreate the wallet and control its Bitcoin.The attack therefore targeted the recovery phrase rather than exploiting the hardware wallet remotely. Coldcard’s own security guidance says users should never provide seed words, passphrases, private keys or wallet backup information through a website or support request.The method closely resembles other recent hardware-wallet phishing campaigns. In September, Trezor customers received phishing messages through the company’s legitimate email infrastructure, showing how an authentic communication channel can make a fraudulent security warning substantially more convincing.

      Investor Takeaway

      The immediate risk is social engineering, not a confirmed new Coldcard firmware flaw. A recovery phrase entered into any website should be treated as compromised.

      Why Is the Timing Particularly Sensitive for Coldcard Users?

      The phishing message exploited a credible fear because Coldcard experienced a genuine seed-generation failure only months earlier.A firmware problem dating back to 2021 weakened the randomness used to generate private keys on affected devices, allowing attackers with sufficient computing resources to reconstruct vulnerable keys and steal Bitcoin without physically possessing the wallet.The Coldcard firmware failure emerged publicly in late July, when attackers began sweeping Bitcoin from wallets whose seeds had been generated under vulnerable firmware conditions.Galaxy Research subsequently traced 1,789.28 BTC worth approximately $114.7 million across 8,865 addresses by August 25. DefiLlama currently records the Coldcard incident at about $116 million.The October phishing post therefore used language that could plausibly resemble a legitimate follow-up security warning. Users who had already been told to migrate funds after the earlier vulnerability could be more susceptible to instructions appearing on Coldcard’s verified social-media account.There is no evidence, however, that the October 11 phishing post is technically connected to the July exploit or that attackers discovered another vulnerability in Coldcard devices.

      Why Does the Missing Login Record Matter?

      Coldcard’s account-security claim makes the publication mechanism an important unresolved question. The company says the X account has used offline two-factor authentication and tightly restricted access since 2017, while its review reportedly found no matching login, session or access event associated with the phishing post.That does not establish that X itself was breached. Possible explanations can include compromised account credentials, abused sessions, authorized applications, employee access or platform-level mechanisms, and Coldcard has not identified which, if any, applies.The company has asked X to preserve relevant records and investigate. Until that process produces evidence, claims that an X administrator account or internal platform access was responsible remain unconfirmed.

      Investor Takeaway

      A verified corporate account can no longer be treated as sufficient authentication for wallet-migration instructions. Users need to verify security notices independently through the manufacturer’s website.

      What Should Coldcard Users Watch Next?

      The most important next disclosure is Coldcard’s explanation of how the unauthorized post was published. That will determine whether the incident was an isolated social-media account problem or exposed a weakness in a broader communications process.Any confirmed losses would also change the scale of the event. None have been publicly verified so far.The episode adds another layer of risk for Coldcard users after the earlier firmware failure. Galaxy’s tracing of the July thefts showed that most of the stolen Bitcoin initially remained in attacker-controlled addresses, while affected users were already being required to distinguish legitimate migration instructions from impersonation attempts.For hardware-wallet holders, that distinction is now central to self-custody security: protecting the private key is not enough if an attacker can convincingly impersonate the manufacturer and persuade the owner to surrender it voluntarily.

      Source: FinanceFeeds
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud