THE SCAM
The urgent security update that steals your wallet.
A post on the official X account of Coldcard — the company that makes a popular Bitcoin hardware wallet — warned users about a critical security flaw in recent firmware. It said users had to move their funds right away, using the link in the post. That link opened a fake “wallet security” website asking people to migrate their money.
It wasn’t Coldcard’s post at all. The company deleted it, said its own records show no intruder ever logged into the account, and asked X to investigate how the post got published. Real post or fake one, the trap was identical: a scary security message plus a link to click in a hurry.
THE RED FLAG
It came from the company’s own official account — that’s exactly why it works. People trust posts from brands they know, so scammers put the most effort into looking like the brand — or into taking over the real account. Even Coldcard itself admits it can’t yet explain how the post was published.
Coldcard told users to ignore the link and pointed them back to coldcard.com, its only official site. A real security fix doesn’t arrive as a panicked social media post demanding you move money through a link, no matter whose logo is on it.
THE RULE
Never move money, install an update, or enter your recovery phrase through a link in a social media post — even when it comes from an account you trust, because trusted accounts get hijacked.
If a post says your money is at risk, stop. Go to the company’s real website yourself — type the address, don’t click — and check for the news there. The post is the rumor; the official site is the fact.
(Source: Coldcard’s public statement on X, October 11, 2026; reported by crypto.news and TradingView)
SIGN-OFF
That's today's red flag. One scam, one red flag, one rule — pass it to someone who clicks first and asks questions later.
Got a scam text or a sketchy email? Send it via the contact page — the best ones make future red flags.