MobbleOpen in Mobble ⇢
Business · Cryptocurrency · published 2026-10-11 · via Bitcoin Haber

Coldcard X Account Compromised in Phishing Scam

Image via Bitcoin Haber
Image via Bitcoin Haber

Coldcard's official X account was compromised on October 11, 2026, and hackers posted false claims about firmware vulnerabilities in its Mk4, Mk5, and Q models. The fraudulent alert directed users to a phishing page and mimicked real update version numbers from Coinkite's July response. That earlier incident involved weak entropy in some wallets and led to thefts estimated at 1,600 to 1,800 BTC, worth $100 million to $130 million at the time.

Expanded Detail

Coldcard’s official X profile was taken over on 11 October 2026. The intruders falsely warned that firmware flaws affected Mk4, Mk5 and Q devices, then sent users toward a fraudulent site. That page was subsequently taken down.

The hoax echoed a July 2026 problem: flawed randomness in some wallets let attackers drain funds offline, with losses put at 1,600–1,800 BTC, then worth $100m–$130m. Coinkite’s later releases—4.2.0 for Mk3, 5.6.0 for Mk4/Mk5 and 1.5.0Q for Q—required fresh seed phrases and manual transfers. The fake alert reused those version numbers.

Context

This incident may deepen distrust in social media announcements from crypto firms, especially among hardware-wallet owners who already faced the July losses. Users could become more cautious about urgent security alerts, seed-phrase requests, and links, potentially reducing phishing success. It may also pressure platforms and manufacturers to strengthen account protections and verification. The broader public impact may be limited to those holding or trading bitcoin, though it could add to perceptions of crypto security risk.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Bitcoin Haber →
Related stories
Coldcard probes fake firmware alert posted from its X account · Cryptocurrency
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Coldcard’s X Account Hijacked; Users Misled with Fake Security Alert.” Browse more stories.