Coinkite criticized for keeping emails after Coldcard bug
Coinkite emailed buyers dating to 2019 about a Coldcard seed-generation bug tied to about 1,367 BTC stolen. Customers say the firm had promised to delete purchase data after 90 days.
Coinkite contacted customers this week to warn them about a seed-generation randomness bug in its Coldcard hardware wallets that has been linked to the theft of roughly 1,367 BTC, about $88 million. The company sent messages to email addresses tied to purchases dating back to 2019, with batches of notices starting Friday.
The firm explained it used addresses it could reach through its store and newsletter systems and asked recipients to treat the notices as legitimate. Coinkite noted purchase email addresses are retained so customers can log in and confirm that other personal information has been cleared, but the company acknowledged it does not have a formal deletion schedule and that addresses will be kept ‘‘for now.’’
Some customers reacted angrily online, saying the outreach contradicted earlier company statements that buyer information was erased after 90 days and that anonymous purchases were offered. Co-founder and CEO Rodolfo Novak had previously posted that the company ‘‘doesn’t store customer information’’ and asked the community for help contacting anyone who might be affected.
The bug affects the randomness used to generate wallet seeds. Where randomness is weak, private keys can become predictable and attackers can extract keys to move funds. After the flaw was discovered, attackers exploited the issue and emptied vulnerable wallets. Coinkite’s emails aimed to reach the largest set of possibly affected owners and advise them on steps to secure any remaining funds.
As the company issued notifications, security teams tracked the amount and movement of stolen coins. Coinkite reiterated that it treats security seriously and highlighted the frequency of incidents across the industry. Novak had also posted that breaches at other firms occur frequently and stressed the company’s commitment to its users.
The incident has focused attention on data-retention practices for hardware wallet vendors. Coinkite’s public statements and the batch emails have alerted many customers, but the company has not announced a new or consistent timetable for deleting stored purchase email addresses.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








