COLDCARD X Account Hijacked to Push Fake Migration Site Targeting Seed Phrases
A phishing post on COLDCARD's compromised X account directed users to a fraudulent wallet-migration domain designed to harvest recovery phrases. COLDCARD confirmed the attack targeted users rather than its internal systems and has requested an investigation from X.
A phishing post appeared on COLDCARD's official X account on October 11, directing users to a fraudulent wallet-migration domain engineered to harvest recovery phrases. COLDCARD confirmed the account was compromised and has formally requested an investigation from X.
The fake site, identified and analyzed by an independent security researcher, was purpose-built for one task: collecting the 12- or 24-word seed phrases that serve as the master keys to any cryptocurrency wallet. Anyone who entered their recovery phrase on that domain effectively handed an attacker complete, irrevocable control over their funds.
COLDCARD moved quickly to contain the damage. In a public statement, the company confirmed it "found no matching login record" for the fraudulent migration attempt, a detail that matters structurally. It means the attack did not originate from inside COLDCARD's own infrastructure. The compromise almost certainly occurred through credential theft, SIM swapping, or social engineering directed at X's support staff rather than a breach of the company's internal systems. COLDCARD's wallets, firmware, and backend operations appear unaffected.
That distinction is cold comfort for any user who clicked the link and entered their phrase. A seed phrase exposed is a wallet emptied, regardless of whether the hardware device itself was ever touched.
"COLDCARD said a phishing post from its official X account sent users to a fake wallet-migration domain, prompting a request for an X investigation."
COLDCARD, via statement
The attack follows a well-worn playbook. Hijacking a trusted brand's social media account and using it to push fake migration or setup pages has become one of the more reliable vectors against hardware wallet users specifically, because those users tend to be security-conscious enough to own a hardware wallet but may still extend undue trust to what appears to be an official channel. The cognitive trap is deliberate: a "wallet migration" prompt sounds plausible, even routine, and the urgency implied by such posts pushes users to act before they verify.
Hardware wallet manufacturers are high-value targets for exactly this reason. COLDCARD, which builds Bitcoin-only signing devices with a reputation for paranoid security defaults, commands a loyal and technically sophisticated user base. That same user base is likely to hold significant balances, making the potential payoff for attackers considerable.
Social media account compromises targeting crypto companies have accelerated over the past several years. The attack surface is not the blockchain itself but the human layer around it: support staff, authentication flows, and the implicit trust users extend to verified accounts. X's own security record on this front has drawn sustained criticism, and COLDCARD's request for a platform-level investigation puts that record back under scrutiny.
The immediate practical takeaway is straightforward. No legitimate wallet manufacturer, COLDCARD included, will ever ask users to enter a seed phrase on a website. Migration prompts, urgent security notices, and links to unfamiliar domains posted on social media should be treated as suspect by default, regardless of the account they appear to come from. Verify URLs directly against official documentation before taking any action, and treat any prompt to input a recovery phrase online as an attack until proven otherwise.
COLDCARD's rapid public disclosure likely limited the damage. The window between a phishing post going live and users being warned is where losses accumulate, and a fast response compresses that window. Whether X's investigation yields anything actionable remains an open question, but the incident is a clear reminder that the security model of a hardware wallet only holds if the off-chain information layer around it is treated with equal care.



