Community Trust ScoreLikely Real
Coldcard is in crisis mode. The Bitcoin-only hardware wallet company is investigating how a phishing link ended up on its official X account — and right now, nobody’s talking publicly about how it happened.
Why It Matters
The incident highlights ongoing vulnerabilities in the cryptocurrency ecosystem, particularly regarding the security of digital assets and the platforms used for communication. As phishing attacks become increasingly sophisticated, the potential for user trust erosion in hardware wallet providers is significant, particularly in the wake of recent losses in the sector. This situation underscores the importance of robust security measures and proactive communication from companies operating in the cryptocurrency space to safeguard user assets and maintain confidence in their products.
The post appeared on a Sunday. Coldcard said it runs offline two-factor authentication with restricted account access, a setup it’s had in place since 2017. And yet the link still got through. The post has since been deleted, and Coldcard told users to stay away from it — don’t visit it, don’t interact with it, full stop. The company’s only legitimate website, it stressed, is https://coldcard.com. Any verified updates, it said, will come through official channels.
Coldcard has reached out to X for help and is reviewing every access point on the account.
The July Exploit: Bitcoin Gone from 7,300 Wallets
The phishing incident isn’t happening in a vacuum. July was already a brutal month for Coldcard — brutal enough that it ranked as the second-worst month for crypto thefts in all of 2026. A major exploit hit the platform hard, with hackers making off with $247.4 million in crypto during that month alone. For context, the only worse month was April, when $644 million was stolen across the broader industry.
The Coldcard-specific damage from July is staggering on its own. Data from DefiLlama put the losses from the exploit at at least $100 million in Bitcoin, pulled from 7,300 wallets across three confirmed attack waves. Three waves. That’s not a single opportunistic hack — that’s a sustained, methodical operation.
DefiLlama’s hack tracker later put its estimate for the July Coldcard exploit specifically at $115 million.
And it might be worse than that. Galaxy Digital identified what it called a suspected fourth wave of attacks. If that holds up, total losses could climb to roughly $130 million. Coldcard hasn’t confirmed or disputed the fourth-wave theory. No detailed disclosure has come from the company on the full scope of the breach or exactly how attackers got in.
What Coldcard Has — and Hasn’t — Said
The company’s public response has been measured. It’s promised to share verified updates as the investigation moves forward. It’s emphasized that users should treat https://coldcard.com as the only trustworthy source for information. But specifics on the exploit mechanics? Not yet. No breakdown of which security layers failed, no timeline for when users might get answers, no word on whether affected wallets will see any kind of remediation.
That silence isn’t necessarily unusual for an active investigation. You don’t want to tip off attackers who might still be probing the system. But it leaves 7,300 wallet holders — and probably a lot more people watching from the sidelines — without much to go on.
The phishing post on X is a separate thread from the July exploit, at least as far as Coldcard has communicated publicly. Whether the two incidents share any connection — same attacker, same access vector, coordinated timing — is unclear. Coldcard hasn’t said. Probably too early to know.
What’s clear is that offline two-factor authentication, the kind Coldcard has used since 2017, didn’t stop the X account from being compromised. That’s the uncomfortable fact sitting at the center of the X investigation. Restricted access and offline 2FA are serious security measures. They’re not foolproof, apparently.
Hardware wallets occupy a specific trust position in the crypto ecosystem. People buy them precisely because they want something more secure than a software wallet or an exchange account. Coldcard has built its reputation on being Bitcoin-only and security-first. When the company itself gets hit — twice, seemingly, in the span of a few weeks — that reputation takes a hit too.
The broader crypto security picture in 2026 has been rough. July’s numbers alone — with Coldcard’s exploit as the month’s biggest single incident — put the industry on edge. April’s $644 million in total thefts was worse by raw dollar volume, but July’s concentration of losses around one platform made it feel different. More targeted. More deliberate.
Galaxy Digital’s analysis of the attack waves painted a picture of something carefully staged. Three confirmed waves, a possible fourth, all hitting the same platform, all pulling Bitcoin from wallets that presumably belonged to people who thought they were well-protected.
Coldcard’s internal review of account access is ongoing. The company is still working with X. No arrests, no suspects named publicly, no confirmed entry point for either the exploit or the phishing post.
DefiLlama’s $115 million figure for the July exploit stands as the current best estimate for losses tied directly to Coldcard’s breach.
Hub: Bitcoin price, news, and analysis
Frequently Asked Questions
What should Coldcard users do after the phishing incident on X?
Coldcard warned users not to visit or interact with the unauthorized phishing link that appeared on its X account, and said its only legitimate website is https://coldcard.com.
How much Bitcoin was stolen in the July 2026 Coldcard exploit?
At least $100 million in Bitcoin was taken from 7,300 wallets across three confirmed attack waves, with DefiLlama’s hack tracker estimating total losses at $115 million and Galaxy Digital flagging a possible fourth wave that could push losses to around $130 million.





