The X account of Bitcoin hardware wallet maker Coldcard was compromised on October 11, 2026, when attackers posted a fake notice claiming a critical vulnerability affecting Mk4, Mk5, and Q models. The scam exploited a previous crisis: in late July 2026, a linker error in device code generated wallets with weak entropy, allowing hackers to steal approximately 1,600 to 1,800 BTC, worth $100 to $130 million at the time. The fraudsters mimicked the legitimate firmware migration procedure by listing the exact same patched firmware versions to trigger panic and redirect funds to their addresses. Coldcard found no evidence of a breach in its own systems and attributed the compromise to unauthorized access at the X platform level or through its administrative panel.
Source: Read the original article

