Hardware wallet manufacturer COLDCARD stated that its official X account had previously posted a fake security announcement, directing users to a phishing website disguised as a wallet migration guide. The post has been deleted, but no corresponding login, session, or access records have been found.COLDCARD indicated that its credentials and offline two-factor authentication remain secure, leading to suspicions that the attacker may have gained X platform-level or administrative access, and has requested an urgent investigation by the X security team. The company also mentioned unverified reports of X administrator accounts being sold on the dark web, but no connection to this incident has been found.