Coldcard Investigates Phishing Link on X Amid Seed Generation Concerns
Key Summary
Coldcard, the Bitcoin hardware wallet provider, is investigating a phishing post on its X account that claimed a critical issue with seed generation in recent firmware. The post pointed readers to a domain called migrate.coldcardwallet.io, but the company has found no unauthorized access or logins on the account. Coldcard has asked X for an urgent investigation to determine if the platform or account credentials were compromised.
Investigation Underway
Coldcard has launched an internal review after the phishing post appeared on its X account, but found no evidence of unauthorized access or logins. The company credits offline two-factor authentication, which it has used since 2017, for protecting its users' accounts.
What Happened
The phishing post appeared on Coldcard's X account around 02:00 UTC on October 11, 2026, and claimed there was a critical issue with seed generation in recent firmware. The post pointed readers to a domain called migrate.coldcardwallet.io, which is not a verified Coldcard domain.
Expert Analysis
Coldcard's findings point to an awkward question: if the company recorded no unauthorized logins, how did the post get there? X has been asked to explain the incident.
What This Means for Bitcoin Holders
For Coldcard users, the practical guidance is simple: do not click the link, and do not move funds based on a social media post. Legitimate firmware fixes do not require entering your seed phrase on a website. Any prompt to do so should be treated as a red flag, no matter which account it comes from.
Next Steps
The key things to watch are X's findings and any verified follow-up from Coldcard. Users should remain vigilant and monitor their accounts for any suspicious activity.