COLDCARD said a phishing message published through its official X account on October 11 falsely claimed a critical firmware vulnerability in its Mk4, Mk5 and Q hardware wallets and directed users to a fraudulent migration site. BitcoinNews characterized the incident as a compromise of the company's social-media account, while COLDCARD said its review found no unauthorized login, session or access record and asked X to investigate. The deleted post copied firmware details from an earlier 2026 weak-entropy flaw that enabled offline attacks on affected wallets and was estimated to have drained 1,600 to 1,800 BTC. No verified losses have been linked to the October phishing post, which did not indicate a breach of COLDCARD devices or firmware. Users who entered a recovery phrase, connected a wallet or approved a request through the malicious link were advised to move assets to a newly generated wallet.