Newport Exchange
Market Intelligence

COLDCARD Warns Users After Its Official X Account Posts Phishing Link

October 11, 2026 2 min readBy Crypto Daily
COLDCARD Warns Users After Its Official X Account Posts Phishing Link

COLDCARD said on October 11 that its official X account had published a phishing message, directing users toward a fake wallet-migration site. The company said it found no corresponding login, session or access record, said its credentials and offline two-factor authentication remained secure, and asked X to investigate whether access could have occurred at the platform level. COLDCARD Reports Phishing Post From Its Official X Account In its public statement at 06:07 UTC, COLDCARD described a phishing message from the @COLDCARDwallet account as unauthorised and identified the account as its official X presence.

COLDCARD said its review found no matching record of account access. It did not establish how the message was published; its request to X concerned possible platform-level access, not a confirmed explanation for the incident. Fake ‘Urgent Security Update’ Directed Users to a Migration Domain Inforex reported that, at about 02:00 UTC on October 11, a message posing as an urgent security update directed users to migrate funds through migrate.

coldcardwallet. io, a phishing destination. Deleted Post Leaves Risk of Confusion Over Migration Instructions The fraudulent post was later deleted, but COLDCARD warned that users could still confuse its fake migration instructions with an authentic security update, TokenPost reported.

The supplied reports provided no information on user losses, view counts, or further distribution. The immediate verified concern was the deceptive instruction and its potential to be mistaken for an official request from the wallet maker. X Asked to Investigate Possible Platform-Level Access COLDCARD has asked X to investigate the incident, citing the lack of a matching login, session or access record in its review.

Its statement said the company's credentials and offline 2FA were secure, while leaving the mechanism behind the account post unresolved. For now, the company has not announced a timetable or outcome for X's investigation. The phishing domain and the deleted post remain the central identifiers of the incident disclosed on October 11.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.