Coldcard pauses automatic customer data deletion after July 30 security incident

Coldcard has suspended its automatic customer data deletion policy after the July 30, 2026 security incident created legal obligations to preserve records that could be relevant to ongoing and anticipated litigation. The hardware wallet maker said records that would normally be blanked after 120 days will now be retained until further notice, though customers can still ask support to apply the original retention schedule. The change follows a vulnerability that Galaxy Research linked to 1,596 confirmed stolen Bitcoin across three attack waves affecting about 7,300 wallet addresses, with a fourth wave that could raise losses to about 2,055 BTC if additional victim reports confirm it. Coinkite has said the flaw stemmed from firmware that used a deterministic pseudo-random generator during wallet creation, reducing entropy in some seed phrases. Patched firmware has been released, but users whose wallets were created with vulnerable software are still being urged to generate new seeds and move funds.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.