Coldcard Company Abandons Data Deletion Policy Following $116 Million Wallet Hack
Coldcard wallet maker Coinkite is changing its customer data retention policy following a major July 2026 security breach that resulted in the theft of over $116 million in Bitcoin. The company will no longer automatically delete customer records, a reversal of its prior privacy-focused stance, citing preparation for potential legal obligations arising from the hack. The breach exploited a firmware vulnerability (version 4.0.1) present since March 2021. Security firm TRM Labs warned that any seed phrase created on a vulnerable device before patching should be considered compromised. The attack occurred in several waves, ultimately draining over 1,816 BTC from more than 5,200 addresses, making it the third-largest crypto hack of 2026. Canada was reportedly the hardest-hit region. Coinkite has publicly denied long-standing allegations that it knew about the critical flaw beforehand, pointing to its public incident history log. The hack has shaken trust in self-custody solutions within the Bitcoin community.
cryptonews.ru9h ago