Coldcard Retains Customer Records Amid Bitcoin Wallet Security Investigation

Coldcard Retains Customer Records Amid Bitcoin Wallet Security Investigation

key insights

  • Legal exposure now affects privacy practices. The investigation requires temporary preservation of records normally scheduled for deletion.
  • Old seeds remain the central security concern. Firmware updates cannot repair weak randomness already embedded within existing seed phrases.
  • Unmoved Bitcoin remains traceable. Large attacker balances remain visible, giving investigators opportunities to monitor future transfers.

Coldcard has temporarily stopped automatically deleting customer records following its July 30 security disclosure. The hardware wallet maker cited legal obligations linked to ongoing and potential proceedings.

The decision changes a privacy practice that normally removes most customer information after 120 days. However, customers can still request treatment under the previous retention policy.

Coldcard puts 120-day deletion policy on hold

Before the security incident, the company automatically blanked most customer records after 120 days. It retained only email addresses and customers’ countries of residence. Customers could also request earlier deletion after receiving their hardware wallets.

That procedure changed after the July 30 disclosure. The company said potential litigation requires it to preserve records that could become legally relevant. Consequently, information scheduled for automatic removal will remain stored while those obligations continue.

The company acknowledged that the temporary measure departs from its established privacy practices. However, it said access would remain restricted to authorized personnel.

The retained information will only support compliance with legal requirements, according to the company. Customers still have another option. They can contact official support and request treatment under the original retention rules.

Coldcard said it will restore automatic deletion when legal requirements allow normal procedures to resume.

Key measure                                                        Current position

Previous deletion period                                          120 days

Information normally retained                               Email and country

Automatic deletion                                                    Temporarily suspended

Customer deletion requests                                     Still available

Reason for retention                                                  Legal obligations

Access to preserved data                                           Authorized personnel only

Security investigation expands after Bitcoin thefts

The policy shift follows investigations into a serious security flaw affecting the company’s hardware wallets. Galaxy Research has linked three confirmed attack waves to 1,596 stolen BTC. Those incidents involved about 7,300 wallet addresses.

Researchers are also investigating a suspected fourth wave. Confirmation could increase the estimated total to roughly 2,055 BTC.

Earlier blockchain observations identified approximately 1,815.75 BTC moving across four apparent waves. However, Galaxy distinguishes blockchain observations from thefts confirmed by affected wallet owners.

Investigators have shared relevant addresses with federal authorities, exchanges, and crypto investigation groups. That cooperation could help identify stolen funds entering regulated platforms.

Meanwhile, most identified Bitcoin remains unmoved.

Galaxy previously estimated that about 90% of the stolen assets remained untouched. Researchers later identified one attacker holding 1,159 BTC across seven addresses.

Another suspected attacker showed different behavior. Analysts observed 64 BTC entering a transaction flow associated with a cryptocurrency mixer.

That activity appeared separate from the larger seven-address cluster. Therefore, researchers believe multiple attackers may have exploited the same weakness.

Weak wallet randomness created the underlying risk

The security issue traces back to a March 2021 firmware change involving a new cryptographic library.

According to Coinkite’s technical disclosure, affected firmware generated some wallet seeds using a deterministic pseudo-random generator.

The intended process relied on a hardware-backed random-number generator. The implementation mistake significantly reduced the randomness protecting affected seed phrases.

Coinkite estimated affected Mk2 and Mk3 devices produced roughly 40 bits of effective entropy. Vulnerable Mk4, Mk5, and Q devices generated approximately 72 bits. The intended security level was 128 bits.

Attackers could therefore calculate possible seed combinations offline. Then they could generate addresses and compare them with publicly available records of the Bitcoin blockchain.

The attack did not require physical access to the hardware wallet. It also did not involve a vulnerability within the Bitcoin protocol. Coldcard has released firmware fixes covering affected models. Yet updated firmware cannot strengthen seed phrases created before users installed the fix.

Privacy consequences extend beyond stolen Bitcoin

The incident now presents two separate concerns for customers. One involves wallet security, while the other involves personal data retention.

Coldcard built part of its privacy approach around reducing how long customer information remained stored. Suspending automatic deletion temporarily changes that privacy calculation.

Still, customers retain the ability to request handling under the earlier policy. That provision gives affected buyers some control while legal proceedings develop.

The broader episode also highlights a challenge facing hardware wallet manufacturers. Strong physical security cannot compensate for weaknesses during cryptographic seed generation.

Likewise, software repairs cannot automatically secure credentials generated under vulnerable conditions.

For the hardware wallet industry, the incident could increase scrutiny of random-number generation and firmware auditing. Data minimization policies could also receive greater attention following major security breaches.

Conclusion

Coldcard now faces the consequences of the July incident across security, privacy, and potential legal proceedings.

The temporary data hold preserves records that could matter during investigations. However, customers can still request treatment under the company’s previous retention framework.

The bigger security investigation is still underway with investigators continuing to search for confirmed and suspected Bitcoin theft. The company is set to resume auto deletion when legal requirements allow.

Scroll to Top