Coinkite is once again facing the wrath of its customers after a flaw in random seed phrase generation was discovered, allowing malicious actors to steal over 1,000 $BTC in the past two days.
In an effort to reach the majority of customers who may have been affected by the issue impacting a series of Coldcard hardware wallets, the company sent out warning emails about the severity of the incident to addresses associated with purchases made since 2019.
On social media, Coldcard confirmed it had contacted its customers via email and assured the authenticity of these messages.
"It wasn't easy, but we have now sent emails to all addresses we could find through our store and mailing list systems. The emails are being sent out in batches since Friday. If you received such an email, we want to confirm that it was indeed sent by Coinkite," the company explained.
When Coinkite was criticized for storing email data, it referenced its public policy, which states that email addresses provided during purchase are retained so that customers can log in and verify that their other information has been deleted. However, the company did not specify a deletion policy for this data, noting that these addresses would be stored "for now."
Despite this, Rodolfo Novak, co-founder and CEO of Coinkite, emphasized that the company does not store customer information and has no way to contact affected customers, calling for help in reaching all potentially impacted users.
In an earlier post, Novak stated that the company offers the possibility of making anonymous purchases and deletes customer data after 90 days.
"Every other month, one of our competitors has a data leak. Coinkite/COLDCARD takes this extremely seriously — like our customers, we are bitcoiners first," he emphasized at the time.
According to Galaxy Research, by 5:36 PM Eastern Time (EDT) on Saturday, the amount of damage from the incident had already reached 1,367 $BTC, amounting to over $88 million.





