Coldcard has temporarily suspended its automatic customer data deletion process because of legal obligations tied to the security incident disclosed on July 30, preserving records that would otherwise have been erased after 120 days.
- Coldcard has suspended its automatic customer data deletion policy because of legal obligations tied to its July security incident.
- Customers can still request their records be handled under the company’s original data retention policy by contacting support.
- The policy change follows a wallet flaw that Galaxy Research linked to 1,596 confirmed stolen Bitcoin across three attack waves.
- Coldcard said retained customer records will remain restricted to authorized personnel and used only to meet legal requirements.
Coldcard announced the policy change in a post on X, saying it must retain customer records that could be relevant to ongoing and anticipated legal proceedings arising from the wallet security incident.
The company said the temporary measure overrides its published data-retention schedule but added that customers who do not want their information preserved under the legal protocol can still request the application of its existing retention policy by contacting customer support.
Coldcard has paused automatic data deletion
Explaining the change, the company said its standard practice has been to “automatically blank customer records after 120 days,” keeping only customers’ email addresses and country of residence. It also noted that buyers have long been able to request accelerated deletion after their orders were delivered.
The company said the July 30 security incident has changed those procedures because it is now legally required to preserve records that may become relevant during litigation.
As a result, customer records that were scheduled for deletion under the normal 120-day policy will now be retained until further notice.
Coldcard said customers who prefer not to have their records included in that legal preservation process can contact its support team to request that their information be handled under the original retention policy instead.
Addressing privacy concerns, the company wrote that it understood the decision “is a departure from our published practices” and acknowledged that customers value the privacy protections it previously committed to maintaining.
It added that retained customer information will remain securely stored, access will be limited to authorized personnel, and the data “will not be used for any purpose other than compliance with legal obligations.”
According to the company, the previous automated deletion system will return once legal requirements no longer require record preservation.
Security incident has already triggered investigations
The revised retention policy follows one of the largest known hardware wallet security incidents affecting Bitcoin users.
As previously reported by Galaxy Research, attackers have stolen 1,596 BTC from about 7,300 wallet addresses across three confirmed attack waves linked to the Coldcard vulnerability. The research firm said a fourth suspected wave could increase total losses to about 2,055 BTC, although it has not yet received enough victim confirmations to classify those additional thefts as confirmed.
Galaxy has distinguished its confirmed figures from blockchain-only observations. While earlier on-chain analysis identified approximately 1,815.75 BTC moving across four observed waves, the firm’s latest estimate is based on confirmed reports from affected wallet owners.
Separately, Galaxy’s head of firmwide research, Alex Thorn, said blockchain activity indicates the suspected fourth wave was “substantially comprised of” a single attacker. Even so, the firm has continued treating the additional addresses as unconfirmed until more victims come forward.
Investigators have also shared confirmed attacker and victim addresses with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups so the stolen funds can be monitored if they move through regulated platforms.
Firmware flaw reduced wallet seed randomness
According to Coinkite’s earlier technical disclosure, the vulnerability originated in March 2021 during the integration of a new cryptographic library into Coldcard firmware.
Instead of generating wallet seeds through the intended hardware-backed random-number generator, affected firmware accidentally relied on MicroPython’s deterministic pseudo-random generator during wallet creation.
Block’s Bitcoin engineering and security team independently reviewed the firmware and reached the same conclusion, stating that vulnerable versions called the deterministic MicroPython fallback instead of the STM32 hardware random-number generator while generating seed phrases.
Coinkite estimated that affected Mk2 and Mk3 devices provided roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q devices generated about 72 bits rather than the intended 128 bits.
Because of that weakness, attackers were able to reproduce possible wallet seeds offline, derive Bitcoin addresses from those seeds and compare them with publicly visible blockchain data. The attack did not require physical possession of affected devices, users’ PINs or any weakness in the Bitcoin protocol itself.
Most stolen Bitcoin remains untouched
Although the investigation has expanded, most of the stolen cryptocurrency has not yet moved.
Galaxy previously said about 90% of the stolen Bitcoin remained untouched, giving investigators additional time to monitor attacker-controlled addresses. Later on-chain analysis found that the largest identified attacker still holds 1,159 BTC spread across seven addresses without moving the funds.
Separate blockchain monitoring has identified activity from another attacker, however. According to analysts tracking the transactions, 64 BTC entered a transaction flow associated with a cryptocurrency mixer. Roughly 10 BTC was initially mixed, while approximately 54 BTC returned as change before being split into outputs of about 7 BTC each.
Researchers said the activity appears unrelated to the seven-address cluster holding the 1,159 BTC, indicating that multiple attackers likely exploited the same wallet weakness.
At the same time, Coinkite has continued urging affected users to replace vulnerable wallet seeds even after installing updated firmware. The company has already released patched firmware for all affected Coldcard models and destroyed remaining inventory containing vulnerable versions.
According to Coinkite, firmware updates protect only wallets created after the fix. Users whose seed phrases were generated with vulnerable firmware are advised to create entirely new seeds, verify a receiving address, send a small test transaction and move the remaining balance only after confirming the transfer works. Existing wallets created with at least 50 fair private dice rolls are not affected by this specific random-number-generation flaw.

