Independent research. We have no relationship with Coinkite and were not engaged by anyone to write this. All findings come from public data collected on 4 August 2026.

What we did

We ran an outside scan of the impersonation surface around the incident: generating lookalike domain names and resolving them over DNS, enumerating accounts using Coldcard or Coinkite branding on eleven platforms, and tracking who contacted people who publicly reported losing money. No access to Coinkite systems, no privileged data.

116k Domain variants tested
1,527 Results reviewed across 11 platforms
10 Lookalike domains registered since 30 Jul
56,647 Followers reached by fake support accounts

Three kinds of scam came out of it. Purpose-built phishing sites using the language of Coinkite's own advisory, one of which is collecting recovery phrases as we publish. Support impersonation on X, run from aged accounts with open DMs rather than newly created ones. And a recovery-scam ring working people who had publicly said they lost money, reaching the first victim within seven hours of their post.

The rest of this is what each of those looks like up close.

Update, 6 August. An eleventh domain, coldcard-audit.com, was registered on 4 August at 22:17, after this went up. Two of the original ten, coldcardcompliance.com and audit-coldcard.com, no longer resolve. Every row below was re-checked this morning.

A live seed-phrase harvester

This is coldcard.online. It was registered on 2 August, three days after attackers began draining Coldcard wallets.

coldcard.online: a clone of the COLDCARD site with a fabricated red security advisory banner across the top.

The red bar across the top is not Coinkite's. It reads:

COLDCARD Security Advisory: Your device is at risk, click here and update right now, protect your funds now. Enter here and protect yourself →

Every link in that navigation goes to #. Home, Mk5, Q, Docs, Support, Downloads: painted on. One link works, and this is what it opens.

The MIGRATE NOW modal on coldcard.online: a 12-word BIP39 recovery phrase form presented as a firmware update step.

Twelve boxes, a 24-word toggle, and a Continue button. The page ships 24 input fields so it can take either seed length. Its own source names the endpoint:

const BACKEND_URL = window.location.origin + '/api/send-seed';

The developer left comments in Spanish. One reads El backend maneja la seguridad de las credenciales: the backend handles the security of the credentials. The credentials in question are recovery phrases belonging to people who think they are updating their firmware.

Why the advisory was easy to copy

On 30 July, attackers started draining Coldcard wallets. A firmware change from March 2021 had routed seed generation through a software PRNG instead of the hardware RNG, and roughly 1,800 BTC left user wallets over the following days.

Coinkite handled it well. Patched firmware shipped within two days. The advisory was blunt: your seed may be predictable, a firmware update will not repair a seed you already generated, move your coins to a new one now.

That advice is correct, and following it is the only way out. It also describes, step for step, what the phishing page asks you to do.

Look at what a Coldcard owner believed on 31 July. My device is unsafe. I have to act today. I will be handling my recovery phrase to fix it. Every one of those is true. Every one is also a precondition the fake page needs before it shows you twelve empty boxes.

Ten domains in five days

~24h To the first lookalike
9 of 10 In the final three days
21.3% Of all live lookalikes
6 Registrars used
Domain Registered (UTC) Registrar What we saw
coldcard-audit.com 04 Aug 22:17 Tucows Fake "Affected Device Register" · added 6 Aug
coldcardcompliance.com 31 Jul 23:50 Tucows Bot wall, no inspection · no longer resolving
coldcard.online 02 Aug 15:30 NameCheap Live seed harvester
coldcards.app 02 Aug 19:53 NICENIC Parked
coldcardwallet.info 03 Aug 02:27 NameSilo Cloaked redirect
coldcardswallet.info 03 Aug 14:12 NameSilo Same host as the line above
coldcard.tech 03 Aug 17:14 IONOS Broken TLS
audit-coldcard.com 03 Aug 23:07 Tucows Bot wall, no inspection · no longer resolving
coldcardfirmware.com 04 Aug 01:05 PublicDomainRegistry Flagged by Cloudflare
coldcard.help 04 Aug 03:06 NameSilo Bot wall, no inspection
cold-card.live 04 Aug 17:20 NICENIC Registered while we were writing

Read the names: compliance, audit, firmware, help, migrate. That is the vocabulary of Coinkite's incident response, registered by someone else and aimed at the people who read it.

31 Jul  █     1
01 Aug        0
02 Aug  ██    2
03 Aug  ████  4
04 Aug  ███   3   (and the day was not finished)

coldcardswallet.info and coldcardwallet.info were registered eleven hours apart through the same registrar and resolve to the same host, so at least two of these are one operator running siblings. cold-card.live and coldcards.app share a registrar too.

We are not the only ones who reached a conclusion about these. Cloudflare has already classified coldcardfirmware.com itself.

Cloudflare's own interstitial for coldcardfirmware.com, labelled Suspected Phishing.

Four of these sit behind bot walls that refused inspection even from a residential exit. Their operators configured that deliberately, which is an odd choice for a page claiming to help users update firmware.

Aged accounts, repainted for the incident

We expected a wave of new fake support accounts. The data shows something else.

We enumerated 97 accounts carrying Coldcard or Coinkite branding, of which 34 present as company support or staff. Only one of those was created after 30 July, and it has a single follower. The accounts doing the work were registered years ago and already carried an audience:

Handle Created Followers DMs Presents as
@COLDCARDASSISTX 2022 17,030 Open COLDCARD SUPPORT, and it has never tweeted
@COLDCARDX 2010 11,962 Open COLD CARD X SUPPORT TEAM
@ColdcardxChat 2013 9,654 Open COLDCARD® Device Support
@ColdcardLiveFix 2009 7,003 Open COLDCARD LIVE SUPPORT
@pepejp1305 2012 3,522 Open "Chief Director of Customer Service"

What changed was their presentation. At least six now carry SECURITY ADVISORY ⚠️ check blogpost in their bios. That string comes from the official @COLDCARDwallet bio, which Coinkite edited for this incident. They copied the crisis response inside a week.

This is why counting fake accounts misleads you. Run the same handle search before and after the incident and you get 21, then 19. The number went down while the impersonation got worse, because the operators were not minting accounts. They were redecorating ones they already owned. During an incident, watch bios and follower reach, not registration dates.

One rule you can use today

Those 34 accounts hold 56,647 followers between them. 21 of them accept direct messages, and those 21 account for 54,824 followers, or 97% of the total reach.

The real @COLDCARDwallet and @Coinkite both have DMs closed. So any Coldcard support DM is fake, with no judgement call required.

Approaches to people who reported losses

Announcing a loss in public identifies you as a target. We pulled every reply to the two official accounts between 30 July and 4 August, kept the ones reporting a loss or a bricked device or demanding a refund, and got 189 people who had publicly identified themselves as victims.

Then we asked who replied to them.

6.5h To the first approach
189 Self-identified victims
2 Tiers in the referral chain

The approaches share a script. Sympathy, a claim of forensic skill, then a push to move somewhere private:

kindly follow me mate I've a lead on how you can recover your funds. Coldcard has really been hell of a problem to their users I got hacked losing 40k by them, luckily for me I go…

The follow request is the mechanism. Following back opens the DM channel.

Spotters work the replies and hand victims off to a handler with a better front. One handler carries 48,775 tweets and a bio invoking the FBI, and a reply in Turkish concedes the service is paid.

Some approaches came from accounts posing as Coldcard staff. @Pau_SpongeBob, 244 followers, describes itself as Senior Developer at the company. @recepkardl, 130 followers, claims to be Co-Founder & Head of Human Experience. Both have DMs open, and both told victims to message them. For comparison, the real @COLDCARDwallet account has about 67,950 followers, carries a verified badge, and does not accept DMs at all.

Spillover to other wallet brands

Across 13 crypto wallet brands we monitor continuously, none of them Coldcard, the share of newly discovered signals judged abusive went from 10.0% to 32.1% on 30 July and stayed there. The pre-incident figure was flat for the previous ten days across 1,021 signals, so this is a step rather than drift.

Foundation reported phishing emails that impersonated Foundation and cited the Coldcard incident. Trezor issued its own phishing warning. An incident at one vendor changes the risk for its competitors too.

Where the impersonation actually lives

We swept eleven platforms, not just the two that produced findings. Telegram, Instagram, YouTube, TikTok, Facebook, LinkedIn and Dailymotion returned roughly 1,400 results between them, and four carried a Coldcard or Coinkite name. Two of those four look like Coinkite's own accounts.

So the impersonation around this incident concentrated in two places: X, and newly registered domains. That is worth knowing in advance. If you are triaging a live incident with limited hours, those are the two surfaces that repay attention, and a wide multi-platform sweep is not where the threat was.

What this means if you ever publish an advisory

If you publish a breach advisory, you are also publishing a phishing script. Attackers bought domains named after Coinkite's remediation words within a day and rewrote the advisory into a form that harvests the exact thing it told users to protect.

So, for anyone who may one day send that email:

Register the remediation names now. yourbrand.help and yourbrand-audit.com cost less than one victim, and you will not have time to think about them mid-incident.

Say in the advisory which channels you will never use. Coinkite's closed DMs are a stronger protection than any warning, because it turns a judgement call into a fact.

Watch the people replying to you. The ones announcing a loss were approached within hours, and your own mentions are the cheapest place for an attacker to find them.