Independent DeFi security desk · Status: operationalMethodology & corrections · Submit an incident
DeFi Safety · Fact checked

Coldcard investigates phishing link posted on its X account after exploit

The incident underscores the critical need for vigilance against phishing threats and highlights potential vulnerabilities in social media security.

This article may contain affiliate links. Commercial relationships are disclosed in the affiliate policy.

DeFi Safety — illustration keyed to this article's identifier. Source documents are listed under Sources and are not reproduced here.

What happened

The incident underscores the critical need for vigilance against phishing threats and highlights potential vulnerabilities in social media security.

Reported details

  • Coldcard Probes Phishing Post From Official X Account After $115M Wallet Exploit    FinanceFeeds
  • The incident underscores the critical need for vigilance against phishing threats and highlights potential vulnerabilities in social media security.
  • The company says it found no matching login record. A researcher found the fake migration site was built to collect wallet recovery phrases.

Why this matters

Coldcard investigates sits on the regulatory side rather than the structural side: the useful question is which dated rule, if any, follows this notice, and who wrote it. A rule that is not published yet changes nothing about who may act today, so treat the pending text as pending rather than as settled.

Evidence boundary

The scope is limited to what the linked reports state, and where two of them diverge both positions are recorded without either being picked in advance.

What to verify

Before acting on Coldcard investigates, read the dated rule text itself rather than a summary of it, and note which agency wrote it and whether the comment period is still open.

Sources and editorial check time

This information is educational and is not financial, legal, or tax advice.

Sources