Regulatory and Legal Compliance

Coldcard Temporarily Halts Customer Data Deletion Over July Exploit

According to reporting by crypto.news, hardware wallet manufacturer Coldcard has temporarily suspended its automatic customer data deletion schedule due to legal obligations tied to a security incident disclosed on July 30, 2026. This reported development has not officially confirmed formal litigation, but preserves records that would otherwise have been erased after 120 days.

Coldcard logo and hardware security concept graphic
Image: crypto.news

Suspension of Automated Data Deletion Policies

Crypto.news reported that hardware wallet manufacturer Coldcard has implemented a temporary suspension of its standard automatic customer data deletion schedule. Under normal operating conditions, the company automatically purges customer records after a period of one hundred and twenty days, retaining only minimal contact details such as email addresses and the user's country of residence. However, publications indicate that the security incident disclosed on July thirty, twenty twenty-six, has altered these internal data-handling procedures significantly. The organization stated that ongoing and anticipated legal proceedings require the preservation of records that would otherwise have been permanently erased under the published schedule. This policy shift overrides previous privacy commitments made to buyers regarding rapid post-delivery data removal.

According to the published reporting, the decision to retain customer information was driven by the necessity to comply with legal obligations stemming from the severe wallet compromise. While the enterprise acknowledged that this temporary measure represents a notable departure from its established privacy practices, it emphasized that the stored information will be handled under strict security controls. Access to the preserved records is reportedly restricted exclusively to authorized personnel and will not be utilized for any operational activities outside of direct compliance with anticipated legal requirements. The company intends to reinstate its previous automated deletion mechanism once legal obligations no longer mandate the retention of these specific user files.

Opt-Out Mechanisms and User Privacy Protections

In response to potential consumer privacy concerns arising from the halted deletion schedule, the publishing source noted that Coldcard has established an exception pathway for customers. Individuals who do not wish to have their records included in the legal preservation protocol maintain the right to request the application of the original data-retention schedule. To initiate this process, customers are required to reach out directly to the company's customer support division. This provision ensures that buyers who prioritize immediate and complete data erasure over potential legal record-keeping needs can still exercise control over their personal information footprint stored on company servers.

The hardware wallet provider attempted to reassure its user base by detailing the protective measures applied to the preserved records during this interim period. The organization reiterated that all retained customer files remain securely encrypted within internal storage systems and are segregated from general marketing or operational databases. Only designated staff members handling compliance and legal inquiries are granted access credentials. The enterprise maintains that these safeguards are designed to mitigate privacy risks while the broader investigation and associated legal reviews proceed across multiple jurisdictions and with various external cyber-investigation groups.

Scope of the July Security Incident and Galaxy Research Findings

The revision of the data retention framework directly follows a major hardware wallet security incident that has impacted numerous Bitcoin users globally. Research published by Galaxy Research indicated that malicious actors successfully stole one thousand five hundred and ninety-six Bitcoin from approximately seven thousand three hundred distinct wallet addresses across three confirmed attack waves. Analysts at the research firm noted that a potential fourth wave of attacks could elevate aggregate losses to over two thousand and fifty-five Bitcoin, although victim confirmations for those additional addresses remain below the threshold required for definitive classification. Researchers carefully distinguished these verified figures from broader observations of blockchain transaction flows.

Furthermore, investigators have shared verified attacker and victim addresses with United States federal law enforcement agencies, cryptocurrency exchanges, and specialized cyber-investigation organizations. This collaborative intelligence sharing aims to monitor stolen funds effectively if perpetrators attempt to deposit or transfer assets through regulated trading platforms. While the vast majority of the pilfered cryptocurrency remains stationary in attacker-controlled wallets, isolated laundering attempts involving cryptocurrency mixers have been detected by independent on-chain analysts tracking the movement of digital assets across the broader blockchain network.

Technical Origins of the Firmware Vulnerability

According to prior technical disclosures from Coinkite, the vulnerability trace back to a code integration executed in March twenty-one involving a new cryptographic library within the device firmware. Rather than relying on the intended hardware-backed random-number generator, affected firmware builds inadvertently depended on a deterministic pseudo-random generator native to MicroPython during the wallet seed creation process. Independent security reviews conducted by Block's Bitcoin engineering and security team corroborated these technical findings, confirming that vulnerable versions called the predictable fallback instead of the robust STM thirty-two hardware generator when constructing initial seed phrases.

Coinkite estimated that the resulting entropy reduction affected multiple hardware models. Specifically, vulnerable Mk two and Mk three devices provided approximately forty bits of effective entropy, while affected Mk four, Mk five, and Coldcard Q models generated roughly seventy-two bits instead of the targeted one hundred and twenty-eight bits of entropy. This cryptographic weakness enabled external threat actors to reproduce potential wallet seeds completely offline, subsequently deriving valid Bitcoin addresses and cross-referencing them with publicly visible blockchain ledger data without requiring physical access to the target devices or user PIN numbers.

On-Chain Tracking and Funds Distribution

Despite the widespread scope of the security breach, blockchain analysis indicates that the vast majority of the stolen digital assets remains untouched in addresses controlled by the malicious actors. Galaxy Research previously reported that approximately ninety percent of the pilfered Bitcoin has not moved since the initial thefts, affording security researchers and investigative agencies valuable time to monitor attacker addresses. Subsequent blockchain monitoring revealed that the primary identified attacker cluster continues holding over one thousand one hundred and fifty-0dd Bitcoin distributed across seven distinct wallet addresses without executing transfer operations to external exchanges.

In contrast, other blockchain analysts identified separate transaction activity originating from a different attacker cluster. Reports noted that a portion of the stolen funds entered transaction flows associated with decentralized mixing services, where initial tranches were processed before change outputs were split into smaller denomination fractions. Security analysts emphasized that this distinct mixing behavior appears disconnected from the primary holding cluster, reinforcing the hypothesis that multiple independent threat actors successfully exploited the identical random-number-generation flaw during the active attack windows.

Remediation Guidance and Mitigation Steps

Coinkite has strongly urged all affected hardware wallet users to execute comprehensive seed migration protocols even after successfully installing updated firmware versions. The manufacturer has already released patched firmware iterations across all impacted product categories and permanently destroyed remaining warehouse inventory containing the vulnerable code versions. Company representatives clarified that applying a firmware update secures only newly created wallets and cannot retroactively secure private keys derived from flawed random number generation during initial device setup.

Users whose seed phrases were generated using vulnerable firmware versions are explicitly advised to generate entirely new cryptographic seeds, verify a freshly derived receiving address, execute a small test transaction, and transfer remaining balances only after confirming that the transfer completes successfully. Existing wallets that were originally generated using at least fifty fair private dice rolls remain completely unaffected by this specific random-number-generation flaw, providing a secure alternative for cautious holders.

Cexvia conclusion

Incident Conclusion and Verification Status

Crypto.news reported that Coldcard has paused its automatic 120-day customer data deletion policy to comply with legal preservation obligations stemming from the July security incident. This reported measure, which has not officially confirmed formal legal proceedings, affects all Coldcard customers whose data was scheduled for purging, while providing an opt-out mechanism via customer support.

Risk meaning
The temporary reversal of data privacy commitments highlights the legal pressures hardware wallet providers face when major security incidents occur. While retained information is intended solely for compliance, the retention of email addresses and country of residence increases the potential footprint of stored user data during active investigations.
User action
Affected users who prefer not to have their records preserved under the new legal retention protocol can contact Coldcard customer support to request that their information be handled under the original retention policy. Furthermore, users utilizing vulnerable firmware versions should migrate funds to newly generated seeds.
Coldcard