Coldcard Company Abandons Data Deletion Policy Following $116 Million Wallet Hack

cryptonews.ru發佈於 2026-08-07更新於 2026-08-07

文章摘要

Coldcard wallet maker Coinkite is changing its customer data retention policy following a major July 2026 security breach that resulted in the theft of over $116 million in Bitcoin. The company will no longer automatically delete customer records, a reversal of its prior privacy-focused stance, citing preparation for potential legal obligations arising from the hack. The breach exploited a firmware vulnerability (version 4.0.1) present since March 2021. Security firm TRM Labs warned that any seed phrase created on a vulnerable device before patching should be considered compromised. The attack occurred in several waves, ultimately draining over 1,816 BTC from more than 5,200 addresses, making it the third-largest crypto hack of 2026. Canada was reportedly the hardest-hit region. Coinkite has publicly denied long-standing allegations that it knew about the critical flaw beforehand, pointing to its public incident history log. The hack has shaken trust in self-custody solutions within the Bitcoin community.

Coinkite, the developer of the Coldcard wallet which was hacked in July in a major security incident causing $116 million in damages, has informed its users of significant changes to how their data will be stored ahead of potential legal obligations.

A notice, redistributed on the Coldcard X account early Friday morning, detailed that Coinkite will cease automatically deleting customer records. This statement is a reversal of the company's position, directly linked to a firmware vulnerability that led to the theft of over $100 million in Bitcoin from the company's hardware wallets starting July 30, 2026.

How does Coinkite handle user records?

Coinkite confirmed it will alter its processing of client data "in connection with the security incident made known on July 30, 2026." However, prior to this statement, the company regularly deleted customer records, except for their email addresses and countries of residence.

The change in the standard payment processing procedures for the Coldcard Wallet is part of what the company called preparation for "legal obligations" arising from the theft.

In its statement, the company did not specify exactly what information it plans to store or for how long it will be stored going forward.

Nevertheless, this marks the latest major departure from the principle of prioritizing privacy and self-custody of assets, a mantra for Bitcoin Maxis for decades.

What happened with Coldcard?

The revision of Coinkite's data retention policy came after one of the most serious security incidents this year, which exploited a vulnerability in firmware version 4.0.1 released by the company in March 2021.

As company TRM Labs warned, given the severity of the security vulnerability, installing the patched firmware only protects future wallets. Any seed phrase created on a vulnerable Coldcard card between March 2021 and the time of installing the patch should be considered unsafe.

To date, Cryptopolitan has reported four waves of attacks starting July 30, when the vulnerability was first discovered.

The first attack wave drained about 594 $BTC, worth nearly $38 million at the time, from approximately 500 wallets within 25 minutes. Galaxy Research company tracanother three waves over the next four days. As of this report, the stolen assets amount to 1816 $BTC from over 5200 addresses.

TRM calls this the third-largest crypto hack of 2026, a year in which the industry has already lost over $1.2 billion from 276 incidents.

Coinkite refutes claims that "they knew"

As losses mounted, so did accusations that Coinkite had concealed the defect for years. The company is publicly correcting this situation.

In response to a comment by Jack Mallers on August 7, COLDCARD wrote that "there was no weak entropy fallback," arguing that the weak pseudorandom number generator, called Yasmarang, was a built-in universal MicroPython generator featured in the source code, not a Coinkite fallback.

Separately, on August 5, reports emerged that a 2021 "Rabbit Hole Recap" episode, often cited as evidence of prior knowledge of the issue, discussed a different bug, not the random number generator problem. On Coinkite's own incident history page, 23 security-related events dating back to 2019 are listed, a point the company has repeatedly made to critics.

Canada hardest hit

Geographic factors influenced the scale of the damage. Cryptopolitan reported that about 25% of attributed losses trac to wallet owners in Canada, with the United States and Thailand also significantly affected, according to Chainalysis data linking wallet address databases to likely regions.

Chainalysis explained Bitcoin's spread in Canada by early adoption and influencer campaigns that promoted Coldcard in the local market.

The ripple effects are felt everywhere. A CoinMarketCap weekly analysis review states that the hack has undermined trust in self-custody and pushed some towards exploring AI-assisted Bitcoin custody solutions, having scanned 150 repositories to date.

end-content

熱門幣種推薦

相關問答

QWhat significant policy change did Coinkite announce regarding user data, and what prompted this change?

ACoinkite announced it will stop automatically deleting customer records, a reversal of its previous data retention policy. This change is directly linked to the July 2026 security breach where over $116 million in Bitcoin was stolen due to a firmware vulnerability, and is part of the company's preparation for potential legal obligations stemming from the hack.

QWhat was the technical root cause of the Coldcard wallet hack, and what makes the vulnerability particularly severe?

AThe hack exploited a vulnerability in the version 4.0.1 firmware released by Coinkite in March 2021. The severity lies in the fact that installing a patched firmware only protects future wallets. Any seed phrase generated on a vulnerable Coldcard device between March 2021 and the moment of patching is considered compromised and unsafe.

QWhat has been the total reported impact of the Coldcard hack in terms of stolen Bitcoin and the number of affected wallets?

AAccording to the article, the stolen funds amount to 1,816 BTC from over 5,200 wallet addresses, making it the third-largest crypto hack of 2026 at the time of reporting.

QHow did Coinkite respond to allegations that the company had known about the security flaw for years?

ACoinkite publicly refuted these claims. The company stated that the weak pseudo-random number generator (Yasmarang) was a built-in universal generator from MicroPython present in the source code, not a Coinkite backdoor. It also pointed to its public incident history page listing 23 security events since 2019, arguing that a 2021 episode cited by critics referred to a different bug, not this random number generator issue.

QWhich country was reported to be the most affected by the hack, and what were the cited reasons for this?

ACanada was reportedly the most affected country, with about 25% of the attributed losses traced to wallet owners there. Chainalysis explained this prevalence by Canada's early adoption of Bitcoin technology and influencer campaigns that promoted Coldcard in the local market.

你可能也喜歡

XRP活跃地址数激增84%,价格较历史高点下跌72%

在XRP生态系统中,网络活跃度与价格走势出现背离。分析师阿里·马丁内斯指出,XRP活跃地址数从8月1日的23,642个增至目前的43,543个,大幅增长84.18%。与此同时,XRP价格约为3.66美元的历史高点(2025年7月)低约71.7%。 当前市场焦点集中在1美元至1.06美元区间。这主要源于网络活动增加、大额持币者增持以及衍生品市场头寸变化。数据显示,过去一周大型持有者累积了超过3.8亿枚XRP,且月度图表上的Tom DeMark Sequential指标发出了买入信号。 背离现象部分源于XRP在逼近1美元高流动性区域时,未平仓合约兴趣上升,而现货交易量受限。若价格能守住1美元并重返1.06美元上方,当前头寸布局或支撑价格尝试反弹。反之,若跌破1美元,可能引发杠杆多头头寸的强平压力,尤其是在资金费率持续为正的背景下。 衍生品数据显示,自6月底以来,XRP资金费率多数时间为正,表明永续合约市场中多头头寸总体超过空头。尽管价格自6月中旬的1.20美元上方跌至8月12日的0.90美元,这种多头倾向依然存在,导致价格与衍生品头寸间出现脱节。 技术指标依然疲软。14日RSI为35.97,低于其均线39.95和中性水平50。MACD指标也呈负值,MACD线位于信号线下方,柱状图为负,显示看跌动能尚未扭转。 关键价位方面,守住1美元是测试1.06美元阻力的前提,据称该位置曾有近30亿XRP的交易记录。若失守1美元,代币可能进一步跌向0.98美元乃至0.93美元的流动性区域。

cryptonews.ru29 分鐘前

XRP活跃地址数激增84%,价格较历史高点下跌72%

cryptonews.ru29 分鐘前

交易

現貨

熱門文章

如何購買DATA

歡迎來到HTX.com!在這裡,購買DATA Network (DATA)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買DATA Network (DATA)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的DATA Network (DATA)購買DATA Network (DATA)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易DATA Network (DATA)在HTX的現貨市場輕鬆交易DATA Network (DATA)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

677 人學過發佈於 2026.07.01更新於 2026.07.01

如何購買DATA

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 DATA (DATA)幣價的意見。

活动图片