Consumer Rights · Scam Alert · October 11, 2026, 1:10 PM CDT
Key Facts
- Kucoin issued a new alert: Coldcard X account compromised; users warned of phishing scam
- The official X account of Coldcard, a Bitcoin hardware wallet manufacturer, was compromised.
- How it reaches victims: Website.
- Tactics the source describes: Creates false urgency.
HIGH THREAT VECTOR
Report to FBI Internet Crime Complaint Center (IC3) →
Coldcard X account compromised; users warned of phishing scam.
The official X account of Coldcard, a Bitcoin hardware wallet manufacturer, was compromised.
On October 11, 2026, attackers posted a fraudulent notice under the brand’s name, claiming a “critical firmware vulnerability” in the Mk4, Mk5, and Q models, and urging users to immediately transfer funds via a phishing website.
This post emerged amid unprecedented anxiety in the crypto community.[1]
How it unfolds, step by step
The animated infographic below details how the Coldcard phishing scheme works, step by step, using KuCoin’s investigative findings. Because the attackers deleted the fraudulent post after the initial strike, this reconstruction outlines the social hijacking and fund-draining mechanism, marking the critical red flags to watch for.
How to Protect Yourself
- Slow down. Real organizations do not require you to act within minutes or hours to avoid a penalty.
How to Verify This Yourself
Read the original alert directly at Kucoin — that page is the primary source for everything above.
References
Investigative methodology: this update was produced by scripts/scam_monitor.py from a real Kucoin alert — not a language model. The quoted text above is verbatim from the source; any message or description shown in the illustration is quoted or copied from the source itself (see its caption); when the source does not publish the scam’s wording, none is shown or invented. Protection tips are matched from a fixed keyword list, not generated per story.

