Coldcard says it’s investigating how phishing link appeared on its X account
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Bitcoin hardware wallet maker Coldcard announced that a phishing link was posted on its official X account on Sunday. The company, which uses offline two-factor authentication and strictly limits account access, is investigating how the post was published and has deleted the link. Coldcard has urged users not to click the link and confirmed its official website is https://coldcard.com, while it liaises with X and reviews its account security.
Why it matters
The source highlights Coldcard’s recent security issues amid a wave of high-value crypto thefts tied to its wallets, pointing to broader risks for users. However, the article does not explicitly explain the direct market or regulatory implications of this specific phishing incident.
Key context
Coldcard wallets have been targeted in large-scale hacks in 2026, with July marking the second-worst month for crypto thefts that year due to a Coldcard exploit. This exploit resulted in at least $100 million stolen from 7,300 wallets, with a potential fourth wave increasing losses to about $130 million. Different trackers estimate Coldcard-related losses between $115 million and $130 million.
Key numbers and entities
Coldcard, X (formerly Twitter), DefiLlama, Galaxy Digital. Losses include $247.4 million stolen in crypto in July 2026, with $100 million+ linked to Coldcard exploits. July was second only to April’s $644 million in crypto thefts that year.
What remains unclear
The investigation is ongoing and it is not yet known how the phishing link appeared on Coldcard’s account or whether the breach impacted Coldcard’s internal security or user funds. No details are provided on the perpetrators, the content of the phishing link, or final security measures being implemented.