Coinkite, the developer of the Coldcard wallet which was hacked in July in a major security incident causing $116 million in damages, has informed its users of significant changes to how their data will be stored ahead of potential legal obligations.
A notice, redistributed on the Coldcard X account early Friday morning, detailed that Coinkite will cease automatically deleting customer records. This statement is a reversal of the company's position, directly linked to a firmware vulnerability that led to the theft of over $100 million in Bitcoin from the company's hardware wallets starting July 30, 2026.
How does Coinkite handle user records?
Coinkite confirmed it will alter its processing of client data "in connection with the security incident made known on July 30, 2026." However, prior to this statement, the company regularly deleted customer records, except for their email addresses and countries of residence.
The change in the standard payment processing procedures for the Coldcard Wallet is part of what the company called preparation for "legal obligations" arising from the theft.
In its statement, the company did not specify exactly what information it plans to store or for how long it will be stored going forward.
Nevertheless, this marks the latest major departure from the principle of prioritizing privacy and self-custody of assets, a mantra for Bitcoin Maxis for decades.
What happened with Coldcard?
The revision of Coinkite's data retention policy came after one of the most serious security incidents this year, which exploited a vulnerability in firmware version 4.0.1 released by the company in March 2021.
As company TRM Labs warned, given the severity of the security vulnerability, installing the patched firmware only protects future wallets. Any seed phrase created on a vulnerable Coldcard card between March 2021 and the time of installing the patch should be considered unsafe.
To date, Cryptopolitan has reported four waves of attacks starting July 30, when the vulnerability was first discovered.
The first attack wave drained about 594 $BTC, worth nearly $38 million at the time, from approximately 500 wallets within 25 minutes. Galaxy Research company tracanother three waves over the next four days. As of this report, the stolen assets amount to 1816 $BTC from over 5200 addresses.
TRM calls this the third-largest crypto hack of 2026, a year in which the industry has already lost over $1.2 billion from 276 incidents.
Coinkite refutes claims that "they knew"
As losses mounted, so did accusations that Coinkite had concealed the defect for years. The company is publicly correcting this situation.
In response to a comment by Jack Mallers on August 7, COLDCARD wrote that "there was no weak entropy fallback," arguing that the weak pseudorandom number generator, called Yasmarang, was a built-in universal MicroPython generator featured in the source code, not a Coinkite fallback.
Separately, on August 5, reports emerged that a 2021 "Rabbit Hole Recap" episode, often cited as evidence of prior knowledge of the issue, discussed a different bug, not the random number generator problem. On Coinkite's own incident history page, 23 security-related events dating back to 2019 are listed, a point the company has repeatedly made to critics.
Canada hardest hit
Geographic factors influenced the scale of the damage. Cryptopolitan reported that about 25% of attributed losses trac to wallet owners in Canada, with the United States and Thailand also significantly affected, according to Chainalysis data linking wallet address databases to likely regions.
Chainalysis explained Bitcoin's spread in Canada by early adoption and influencer campaigns that promoted Coldcard in the local market.
The ripple effects are felt everywhere. A CoinMarketCap weekly analysis review states that the hack has undermined trust in self-custody and pushed some towards exploring AI-assisted Bitcoin custody solutions, having scanned 150 repositories to date.
end-content





