LATEST NEWS
SELECTED FOR YOU

Coldcard overhauls data retention policy, prepares for ‘legal obligations’ from $100M exploit

ByHannah CollymoreHannah Collymore 3 mins read
Coldcard overhauls data retention policy, prepares for 'legal obligations' from $100M exploit
  • Coinkite is reversing Coldcard’s policy of automatically deleting customer records, citing legal obligations.
  • A firmware exploit has drained about $116 million in Bitcoin since July 30, 2026.
  • With 1,816 BTC gone from more than 5,200 addresses and Canadian holders hit hardest, the case has renewed doubts about self-custody.

Coinkite, the maker of the Coldcard wallet that got exploited for $116 million in July’s largest security incident, has informed its users that it has made big changes to how it stores their data ahead of legal obligations that could potentially arise.

The notice that was redistributed on Coldcard’s X account early on Friday detailed that Coinkite will stop automatically erasing customers’ records. That disclosure is a reversal that the firm directly linked to the firmware exploit that has drained more than $100 million in Bitcoins from its hardware wallets since July 30, 2026.

How does Coinkite handle user records?

Coinkite has confirmed that it will change how it handles customers’ data “in connection with the security incident disclosed on July 30, 2026.” However, before that statement, the company had routinely deleted customer records, except for their email addresses and countries of residence.

The change in the Coldcard Wallet’s maker standard practice is part of what it described as preparation for “legal obligations” stemming from the theft.

The company did not specify in its statement what information it plans to store or for how long it will store it moving forward.

Still, it is the latest major shift away from the privacy-first, self-custody ethos that had become the mantra for Bitcoin Maxis for decades.

What happened to Coldcard?

Coinkite’s data retention policy overhaul follows one of the year’s worst security incidents, which exploited the firmware version 4.0.1 that the company shipped in March 2021.

As TRM Labs warned, reflecting the seriousness of the security vulnerability, installing the fixed firmware only protects future wallets. Any seed created on a vulnerable Coldcard between March 2021 and the patch should be considered unsafe.

So far, Cryptopolitan has reported four attack waves since July 30 when the exploit was first exposed.

The first wave wiped out about 594 BTC, worth nearly $38 million at the time, from roughly 500 wallets in 25 minutes. Galaxy Research tracked three more waves over the next four days. As of this report, the attacker’s haul is now at 1,816 BTC across more than 5,200 addresses.

TRM calls it the third-largest crypto hack of 2026, a year where the industry has already lost more than $1.2 billion across 276 incidents.

Coinkite pushes back on the ‘they knew’ claims

As losses mounted, so did accusations that Coinkite sat on the flaw for years. The company has been correcting the record in public. 

Responding to Jack Mallers on August 7, COLDCARD wrote that “there wasn’t a weak entropy fallback,” arguing the weak PRNG, named Yasmarang, was MicroPython’s built-in general-purpose generator introduced upstream, not a Coinkite fallback.

Separately, on August 5, reports emerged that a 2021 Rabbit Hole Recap episode often cited as proof of prior knowledge referred to a different bug, not the RNG issue. Coinkite’s own historical disclosure page lists 23 security-relevant events dating back to 2019, and the company has pointed critics to it repeatedly.

Canada took the hardest hit

Geography skewed the damage. Cryptopolitan reported on August 5 that about 25% of the attributed losses traced to holders in Canada, with the United States and Thailand also heavily affected, based on Chainalysis data linking the wallet address database to likely regions. 

Chainalysis attributed Canada’s exposure to early Bitcoin adoption and influencer campaigns that pushed Coldcard locally.

The fallout has rippled outward. CoinMarketCap’s weekly research note said the hack has shaken trust in self-custody and pushed some Bitcoiners back toward centralized exchanges. In response, a group calling itself the Red Team, led by AnchorWatch CEO Rob Hamilton, has begun AI-assisted audits of Bitcoin wallets and libraries, scanning 150 repositories so far.

The smartest crypto minds already read our newsletter. Want in? Join them.

FAQs

How did the Coldcard exploit work?

A March 2021 firmware bug caused some devices to generate seeds using a weak software random number generator, cutting key strength from 128 bits to as little as 40 bits, low enough to brute force remotely without physical access to the wallet.

How much bitcoin was stolen and when?

Galaxy Research's tally, cited by TRM Labs, stands near 1,816 BTC, roughly $116 million, drained from more than 5,200 addresses across four waves starting July 30, 2026.

Does updating Coldcard firmware protect an affected wallet?

No. According to TRM Labs, the patch only secures newly created wallets, so anyone whose seed was generated on vulnerable firmware must create a new seed and move their funds.

Share this article

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore

Hannah Collymore

Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.

MORE … NEWS