Coldcard, a company specializing in Bitcoin-only hardware wallets, reported that a phishing link appeared on its official X account on Sunday. The incident raised concerns given Coldcard’s longtime emphasis on security, including its use of offline two-factor authentication and tightly controlled account access procedures since 2017.
Account breach under investigation
Coldcard stated that it is currently investigating how the phishing link was posted from its verified X account. The post has now been removed. While the investigation is ongoing, the company emphasized that its only official website remains coldcard.com and warned users not to visit or engage with any other links that may appear to be from the company.
In response to the breach, Coldcard has reached out to X support and is conducting a comprehensive review of all account access records. The company has committed to sharing any further verified updates as they become available.
Users should avoid interacting with unauthorized links, and Coldcard’s only official online presence is at their website. The company is in contact with X and is auditing account access to ensure enhanced security.
The apparent compromise of a high-profile account with advanced authentication measures highlighted the ongoing vulnerability even among security-focused entities within the cryptocurrency sector. Coldcard reiterated that user vigilance is essential, particularly as cyber threats become increasingly sophisticated.
Impact of July exploits and market response
July 2026 became the second-worst month for cryptocurrency thefts this year, primarily due to a significant exploit targeting Coldcard users. According to data from DefiLlama, hackers made off with $247.4 million in digital assets during the month, behind only the $644 million stolen in April.
Galaxy Digital reported that the Coldcard-related attack accounted for the largest share, with at least $100 million in Bitcoin stolen from 7,300 wallets across three confirmed waves of attack. The company has also pointed to a suspected fourth wave of activity that could increase total losses to approximately $130 million.
DefiLlama’s hack tracker estimated the amount tied specifically to the Coldcard exploit at $115 million. The discrepancy in reported totals reflects ongoing efforts by security firms and blockchain analytics groups to precisely determine the scope of the theft.
The recurring losses underscore the persistent risk of phishing and account breaches, even for companies prioritizing robust security measures. As investigations continue, Coldcard pledged transparency with its community and ongoing audits to prevent further incidents.
Meme token market trends and risk monitoring
Amid heightened security concerns, experts have noted the importance of carefully monitoring both technical transactions and market trends, especially as meme tokens attract massive attention. In the meme token market, an internet trend can transform into millions of dollars of interest within days. According to data shared by Fomo App, a trade involving “Niu Lai”—which turned an initial $99 investment into approximately $370,000, stands out as a striking example of this activity. In this market, tracking not only prices but also the timing and token choices of investors is crucial. Fomo App brings token discovery and trading together on a single platform, featuring social feeds, investor rankings, and trade notifications. Discover Fomo App to follow the world of meme tokens alongside investor activity.
The ongoing investigation and recent losses have spurred renewed calls for heightened awareness among crypto investors and service providers alike.




