Coinkite, the Canadian company behind the Coldcard Bitcoin hardware wallet, has suspended its automatic customer-data deletion policy to preserve records for expected litigation stemming from the firmware flaw that has drained more than $130 million in Bitcoin.
The move, disclosed in an August 6 blog post, marks an uncomfortable departure for a firm whose brand is built on privacy and self-custody.
What Coinkite Changed
Under its standard practice, Coinkite says it automatically blanks customer records after 120 days, keeping only an email address and country of residence, and lets customers request accelerated deletion at any time after delivery. That schedule is now on hold.
The company said it has “temporarily suspended” the automated data-blanking process because of “legal obligations arising from the security incident, including the preservation of records that may be relevant to ongoing and anticipated legal proceedings.”
In practice, records that would have been deleted under the normal timeline will now be retained “until further notice.” Coinkite framed the change as a compliance requirement it cannot avoid: the obligation to preserve records relevant to legal proceedings, it said, “applies regardless of our internal data-retention policies and overrides our standard deletion schedule.”
Notably, the company built in an opt-out. Customers who still want their data handled under the original privacy policy can email Coinkite support to be exempted from the retention protocol, meaning the default has flipped to preservation, but individual deletion requests will still be honored.
Coinkite said retained data will be stored securely, limited to authorized personnel, and used only for legal compliance, and that it will resume standard blanking “as soon as we are legally permitted to do so.”
Why “Anticipated Legal Proceedings” Is the Real Signal
The phrase doing the heavy lifting is “anticipated legal proceedings.” A company does not suspend a core privacy policy and start preserving evidence over a hypothetical. The language is a strong indication that Coinkite expects litigation—plausibly from customers who lost funds—and is taking the standard step of implementing a legal hold to avoid spoliation of potentially relevant records.
It is worth being precise here: as of the disclosure, Coinkite has not named any filed lawsuit or plaintiff, and “anticipated” is its own characterization. But the practical meaning is clear enough that the company felt compelled to warn its privacy-conscious users about it directly.
That is the tension at the center of the story. Coldcard’s entire value proposition is minimizing trust and exposure—air-gapped devices, Bitcoin-only firmware, and a data policy that deletes customer information rather than hoarding it. Being legally forced to retain that same data, precisely because of a defect in its product, cuts against the promise the brand is sold on. The legal basis is legitimate and routine; the optics, for this particular company and customer base, are not comfortable.
The Incident Behind It
The retention change is the legal aftershock of one of the year’s most serious self-custody failures. As The Crypto Times has reported, a firmware bug introduced in a March 2021 update caused affected Coldcard devices to generate recovery seeds with too little randomness—roughly 72 bits of entropy on newer models against an expected 128, and far weaker on older Mk2/Mk3 units—leaving the underlying keys reproducible offline without any access to the physical device.
Attackers precomputed those weak seeds and began sweeping funds in coordinated waves from July 30, and the theft has since fragmented into an open contest. Galaxy Research estimated that at least 15 separate attackers pushed losses toward $130 million across more than 7,700 addresses, with stolen coins having sat dormant for an average of about three years—meaning the victims were overwhelmingly long-term holders who believed their Bitcoin was safe in cold storage.
Coinkite has shipped emergency firmware for every affected model and destroyed remaining vulnerable inventory, and CEO Rodolfo Novak has acknowledged the company was unaware of the bug until researchers surfaced it.
What Affected Users Should Still Do
The guidance from the original advisory has not changed, and it remains the priority for anyone potentially exposed: a firmware update does not repair a seed that was already generated on affected firmware.
Anyone who created a single-signature seed on an affected Coldcard without sufficient dice-roll entropy or a strong, unique BIP-39 passphrase should migrate their Bitcoin to a newly generated seed on patched hardware—carefully verifying backups and sending a test transaction before moving the full balance. Coinkite has stated that seeds protected by 50 or more independent private dice rolls, or by a strong passphrase, face minimal risk from this specific flaw.
The Bigger Picture
The data-retention reversal is a reminder that a hardware-wallet failure does not end when the firmware is patched. The financial damage — now well into nine figures — is the visible cost; the legal and reputational reckoning is the slower one.
For Coinkite, a legal hold is the prudent, arguably unavoidable response to looming claims, and its transparency and opt-out offer are to its credit. But the episode leaves a privacy-first company holding onto exactly the kind of customer data it promised to delete for exactly as long as the lawsuits it now expects take to resolve. How those proceedings unfold—and whether they establish liability for a self-custody device maker whose users “did everything right”—is the next chapter of a story that is far from over.
