Hardware wallet manufacturer COLDCARD confirmed its official X account posted a phishing link before the tweet was deleted. The company stated the account has utilized offline two-factor authentication and strictly restricted access since 2017, with no login, session, or access records found during an internal review. COLDCARD suspects the breach resulted from platform-level compromise or unauthorized administrator access rather than credential theft. The team has contacted X to demand an immediate investigation and log preservation while reviewing all account permissions, with a verification update expected soon.