The official X account of Coldcard, a prominent cryptocurrency hardware wallet manufacturer, was compromised on October 11, 2026. Hackers posted a fraudulent announcement claiming that critical firmware vulnerabilities affected its Mk4, Mk5, and Q models. Users were directed to urgently relocate their assets to a phishing page, which was later removed.
Past Security Crisis Heightens Susceptibility
The effectiveness of this fake alert can be attributed to a significant security incident Coldcard experienced at the end of July, which increased user sensitivity. Due to a critical flaw in the device’s firmware, some wallets were produced with weak entropy, using a breakable software algorithm instead of a true random number generator. This allowed attackers to drain wallets through offline brute force attacks without resorting to phishing techniques.
The initial wave of theft began on July 30, 2026, with total losses estimated between 1,600 and 1,800 BTC. At the time, these assets were valued between $100 million and $130 million, marking one of the largest individual custodian incidents of the year.
The Coldcard team stated that no unauthorized sessions or logins were detected in their records, and the credentials and offline two-factor authentication used since 2017 remained secure.
Attackers Mimicked Real Update Numbers
Following the July crisis, wallet manufacturer Coinkite urgently rolled out version 4.2.0 for Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for the Q model. However, these updates did not automatically secure existing wallets. Users had to generate new seed phrases and manually transfer assets to new wallets.
The phishing attempt on October 11 mirrored this process. Attackers used the same revised version numbers to make the fake announcement appear credible, thereby targeting panic-stricken users to transfer their funds to addresses controlled by the hackers.
In such volatile times, tracking price movements, security alerts, and critical technical developments on a single screen becomes crucial. In a market where a single Federal Reserve decision or an unexpected altcoin listing can change everything in seconds, hopping between different applications for charts, news, and portfolio tracking often results in financial loss. Savvy traders are now turning to tools like CryptoAppsy, which consolidates real-time charts, smart price alerts, asset-specific news, and crucial macroeconomic data in one place without the hassle of account creation.
Company Reaches Out to X Management
Coldcard representatives reported no evidence of their systems being breached in the recent incident and have formally requested an urgent investigation from the X support team. The management suspects that the unauthorized post might have bypassed security measures either through unsanctioned access on the social network side or via the platform’s management panel.
The company believes the post could only have bypassed its security layers through unauthorized access at the social network level or management panel.
Developers also noted reports of internal X tool access methods being sold on dark markets. However, no independent evidence directly linking this to the recent incident has yet been confirmed.
Currently, the primary risk appears limited to users who, in a panic, enter their 24-word seed phrases into the fraudulent page. The company’s statements suggest that rather than an automatic on-chain draining mechanism, the attackers exploited user error through social engineering tactics.



