COLDCARD Official Account Hit by Suspected Platform-Level Breach, Phishing Link Post Deleted
Hardware wallet manufacturer COLDCARD announced that its official X account previously shared a post containing a phishing link, which has now been deleted. The account has utilized offline 2FA since 2017 with strictly restricted access. The team has contacted the X platform and is currently auditing all account permissions, with further verification updates to be released later. COLDCARD noted that no login, session, or access logs were detected, and both credentials and offline 2FA remain secure. They suspect potential unauthorized platform-level or administrator-level access and are demanding an immediate investigation while preserving relevant logs.