Coldcard's X Account Compromised to Push Fake Bitcoin (BTC) Alert for Mk4, Mk5 and Q
AI SummaryAI
- Coldcard's official X account posted a phishing firmware alert on October 11, 2026, for Mk4, Mk5 and Q devices.
- The fake advisory reused July's patched versions: 4.2.0 for Mk3, 5.6.0 for Mk4 and Mk5, 1.5.0Q for Q.
- Coldcard's July entropy flaw cost an estimated 1,600 to 1,800 BTC, roughly $100 million to $130 million.
- Security researchers traced at least 7,300 compromised wallets to the July Coldcard flaw.
Coldcard's X Account Compromised
The official X account of Bitcoin hardware wallets maker Coldcard was hijacked on Sunday, October 11, 2026, and used to publish a phishing post in the brand's name. The message claimed that a critical firmware vulnerability affected the Mk4, Mk5 and Q devices and pressed users to move their assets immediately through a link that routed to a fake page. The post has since been deleted, and the company opened an internal investigation. In a statement, Coldcard said the account has run on offline two-factor verification since 2017 and carries tightly restricted access, yet it could not fully rule out that the account was breached. It confirmed that coldcard.com remains the only official website and warned holders not to visit or interact with the shared link. The firm said it has contacted X support, is reviewing all account access permissions and will publish findings once the investigation concludes. Notably, the company reported no evidence of unauthorized entry into its own systems, and it believes the post could only have gone out through unauthorized access at the social network level or through the platform's admin panel. The scheme targeted the cold wallet holdings of device users rather than exchange balances, and the Bitcoin price itself was not the vector; the fake page was built to harvest recovery credentials. The compromised handle, @coldcardwallet, has long been the brand's primary public channel, which is precisely what made a single fraudulent post so dangerous.
Attackers Reused July's Patch Numbers
The fake advisory drew its credibility from a real crisis that hit Coldcard in late July. A binder error in the device code left some wallets generated with weak entropy, falling back on a breakable software algorithm instead of the genuine random number generator. The first theft wave began on July 30, 2026, and the total loss is estimated at 1,600 to 1,800
Bitcoin (BTC), worth roughly $100 million to $130 million at the time, one of the largest individual custody failures of the year. Security researchers traced at least 7,300 compromised wallets to the flaw, with three confirmed attack waves taking over $100 million and a suspected fourth pushing the total to about $130 million. Industry-wide on-chain data placed July's theft across the sector at $247.4 million, the second-worst month after April's $644 million, and the Coldcard flaw was the month's largest single incident. Coinkite, Coldcard's maker, responded with emergency releases: version 4.2.0 for the Mk3, 5.6.0 for the Mk4 and Mk5, and 1.5.0Q for the Q model. Those updates did not automatically secure existing wallets; users had to generate a new seed phrase and move their funds to fresh wallets by hand. Sunday's phishing attempt copied that exact process, quoting the same corrected version numbers in its fake announcement so that panicked users would move their coins to addresses controlled by the attackers. The incident also lands in a wider run of hardware wallet failures: in late September, Ledger devices compromised through a Southeast Asian distributor's supply chain led to more than $86 million in thefts, with the company asking anyone who bought a device within 90 days to migrate their assets.
No On-Chain Drain This Time
Our reading of the two incidents is that the October 11 attack is a fundamentally different threat from July's flaw. There is no automated on-chain drain mechanism at work here; the exposure is limited to users who personally typed their 24-word recovery phrase into the fake page, which points to a social-engineering play rather than a technical exploit. Coldcard's own statement supports that framing, and its suggestion that the post bypassed its security layers through platform-side access or an admin panel matches reports that tools reaching X's internal systems have circulated on dark markets, though no verified connection to this incident has been established. The practical takeaway stands regardless of how the account was taken: any announcement about firmware updates, software downloads or urgent wallet moves should be verified directly on the manufacturer's official site, never through a link posted on social media.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

