| **Metric** | **Value** | **Source** |
|---|---|---|
| Total crypto market cap | $2.79T | CoinGecko (14:00 UTC) |
| 24h volume | $44.0B | CoinGecko (14:00 UTC) |
| 24h market cap change | -2.68% | CoinGecko (14:00 UTC) |
| BTC dominance | 59.7% | CoinGecko (14:00 UTC) |
| ETH dominance | 10.9% | CoinGecko (14:00 UTC) |
News · Security
ColdCard’s Official X Account Phished for Wallet Recovery Phrases
By CoinBatmi Newsroom · · 3 min read
ColdCard’s verified X account was compromised on October 11, 2026, with a phishing post targeting users to reveal wallet recovery phrases. The fake migration announcemen…
ColdCard’s verified X account was compromised on October 11, 2026, with a phishing post targeting users to reveal wallet recovery phrases. The fake migration announcement, posted under the official handle, directed users to a spoofed website designed to harvest seed phrases.
On-chain analysis confirms the site was built to collect sensitive recovery information, a common attack vector in hardware wallet phishing campaigns.
The phishing site mimicked ColdCard’s official migration tool, a legitimate feature for users upgrading hardware wallets. However, the URL and domain did not match ColdCard’s verified infrastructure. ColdCard has not yet confirmed whether the account was hijacked or if verification tokens were spoofed.
The company’s response team is investigating the incident but has not disclosed the number of affected users or the extent of seed phrase exposure.
The attack follows a pattern seen in previous phishing campaigns, where threat actors exploit social engineering to trick users into revealing private keys or recovery phrases. ColdCard’s official statement emphasized that no matching login records were found for the fake post, suggesting the compromise may have involved stolen credentials or verification tokens.
The company has not yet provided a timeline for account recovery or additional security measures.
Users are advised to verify all migration prompts via the official ColdCard website or direct communication channels. ColdCard’s official X account has since been secured, but the incident shows the ongoing risk of phishing attacks targeting hardware wallet users.
The company has not yet disclosed whether additional security measures, such as multi-factor authentication (MFA) or account lockouts, will be implemented.
The incident raises questions about the security of ColdCard’s verification process and the potential for future phishing attempts. While ColdCard has not yet provided a detailed breakdown of the attack, the use of a spoofed migration tool suggests a targeted effort to exploit user trust in the official brand.
Users are encouraged to remain vigilant and avoid clicking on unsolicited links, even from verified accounts.
ColdCard’s response team is currently investigating the incident to determine the scope of the breach and the number of affected users. The company has not yet disclosed whether additional security measures will be implemented to prevent future incidents.
However, the incident is a reminder of the importance of verifying all communication channels and avoiding phishing attempts.
The attack highlights the ongoing risk of phishing attacks in the crypto space, particularly for users of hardware wallets. ColdCard’s official statement emphasizes the need for users to remain vigilant and to verify all communication channels before revealing sensitive information.
The company has not yet provided a timeline for account recovery or additional security measures, but users are advised to take precautions to protect their seed phrases.
Research and market information only — not financial advice.