Coinkite Faces Criticism for Storing Customer Emails After $88M Coldcard Hack

cryptonews.ruPublicado em 2026-08-02Última atualização em 2026-08-02

Resumo

Coinkite faces renewed criticism after a vulnerability in generating random seed phrases for its Coldcard hardware wallets allowed attackers to steal over 1,000 BTC in two days. While sending warning emails to customers dating back to 2019, the company was questioned for retaining these email addresses. Coinkite cited its public policy stating emails are kept so customers can verify their other data was deleted, but did not specify a deletion timeline, only saying "for now." Co-founder Rodolfo Novak emphasized the company's commitment to privacy, offering anonymous purchases and deleting customer data after 90 days, and appealed for help contacting all potentially affected users. According to Galaxy Research, losses from the exploit had reached 1,367 BTC, worth over $88 million.

Coinkite is once again facing the wrath of its customers after a flaw in random seed phrase generation was discovered, allowing malicious actors to steal over 1,000 $BTC in the past two days.

In an effort to reach the majority of customers who may have been affected by the issue impacting a series of Coldcard hardware wallets, the company sent out warning emails about the severity of the incident to addresses associated with purchases made since 2019.

On social media, Coldcard confirmed it had contacted its customers via email and assured the authenticity of these messages.

"It wasn't easy, but we have now sent emails to all addresses we could find through our store and mailing list systems. The emails are being sent out in batches since Friday. If you received such an email, we want to confirm that it was indeed sent by Coinkite," the company explained.

When Coinkite was criticized for storing email data, it referenced its public policy, which states that email addresses provided during purchase are retained so that customers can log in and verify that their other information has been deleted. However, the company did not specify a deletion policy for this data, noting that these addresses would be stored "for now."

Despite this, Rodolfo Novak, co-founder and CEO of Coinkite, emphasized that the company does not store customer information and has no way to contact affected customers, calling for help in reaching all potentially impacted users.

In an earlier post, Novak stated that the company offers the possibility of making anonymous purchases and deletes customer data after 90 days.

"Every other month, one of our competitors has a data leak. Coinkite/COLDCARD takes this extremely seriously — like our customers, we are bitcoiners first," he emphasized at the time.

According to Galaxy Research, by 5:36 PM Eastern Time (EDT) on Saturday, the amount of damage from the incident had already reached 1,367 $BTC, amounting to over $88 million.

Perguntas relacionadas

QWhat vulnerability was recently discovered in Coldcard hardware wallets manufactured by Coinkite?

AA vulnerability in the generation of random seed phrases in Coldcard hardware wallets allowed attackers to steal funds.

QHow did Coinkite try to warn its customers about the Coldcard vulnerability?

ACoinkite sent warning emails to addresses associated with purchases dating back to 2019 to reach potentially affected customers.

QHow much was stolen according to Galaxy Research's data reported on Saturday evening EDT?

AAccording to Galaxy Research data as of Saturday evening EDT, losses had reached 1,367 BTC, worth over $88 million.

QWhy did Coinkite face criticism regarding customer data in the wake of this incident?

ACoinkite faced criticism for storing customer email addresses. The company cited its public policy stating emails are kept so customers can verify their other data was deleted, but it did not specify a deletion timeline.

QWhat contradictory statements did Coinkite's co-founder make about customer data handling?

ACo-founder Rodolfo Novak stated the company does not store customer information and lacks a way to contact affected users, yet he had previously claimed the company deletes customer data after 90 days and offers anonymous purchases.

Leituras Relacionadas

Bitcoin Boom in Full Swing: Saylor's Latest Statement Fuels Buying Speculation

MicroStrategy's Executive Chairman Michael Saylor has fueled speculation about a new Bitcoin purchase by posting "Bitcoin Drive engaged" on August 2, accompanied by the company's customary purchase tracker. This aligns with his pattern of hinting at treasury changes ahead of weekly reports. The accompanying report showed MicroStrategy's Bitcoin holdings at 843,775 BTC, with an average cost of $75,653 per coin and an unrealized loss of -$10.58B. A similar signal preceded the company's July 27 announcement, strengthening expectations for a treasury update on Monday. However, MicroStrategy's real-time ledger reflects two recent Bitcoin sales totaling 3,588 BTC, reducing holdings from 847,363 BTC to the current 843,775 BTC. The company stated these sales funded preferred stock dividends and replenished its U.S. dollar reserve. Recent reports indicate the company made no Bitcoin purchases the week ending July 26 while increasing its dollar reserve to approximately $3.75B. The company faces financial headwinds after reporting an $8.33B operating loss for Q2 2026, including an $8.32B unrealized loss on its digital assets. Management may sell up to $1.25B more in Bitcoin to meet cash obligations. The expected Monday update will reveal if the "Bitcoin Drive" signal marks a return to accumulation as MicroStrategy balances its massive Bitcoin stash against growing cash commitments.

cryptonews.ruHá 1h

Bitcoin Boom in Full Swing: Saylor's Latest Statement Fuels Buying Speculation

cryptonews.ruHá 1h

Trading

Spot
活动图片