Coldcard reverses data-deletion policy after $116M wallet exploit

Coinkite, the maker of the Coldcard wallet that got exploited for $116 million in July’s largest security incident, has informed its users that it has made big changes to how it stores their data ahead of legal obligations that could potentially arise.
The notice that was redistributed on Coldcard’s X account early on Friday detailed that Coinkite will stop automatically erasing customers’ records. That disclosure is a reversal that the firm directly linked to the firmware exploit that has drained more than $100 million in Bitcoins from its hardware wallets since July 30, 2026.
How does Coinkite handle user records?
Coinkite has confirmed that it will change how it handles customers’ data “in connection with the security incident disclosed on July 30, 2026.” However, before that statement, the company had routinely deleted customer records, except for their email addresses and countries of residence.
The change in the Coldcard Wallet’s maker standard practice is part of what it described as preparation for “legal obligations” stemming from the theft.
… Continue reading the full article at the original source below.


