Coinkite Faces Backlash Over Email Retention After $88M Coldcard Hack
Coinkite, the manufacturer of Coldcard hardware wallets, is facing criticism from customers after it sent security alerts to email addresses associated with purchases dating back to 2019. The emails were intended to warn users about a critical seed generation randomness bug that has resulted in the theft of over 1,000 BTC (approximately $88 million) in recent days.
Users were angered that Coinkite had retained their email data, contradicting earlier statements from co-founder and CEO Rodolfo Novak that customer information was erased 90 days after purchase. Novak had previously emphasized the company’s commitment to privacy, stating, “Every other month one of our competitors has a data breach. Coinkite/COLDCARD takes this extremely seriously, like our customers, we are bitcoiners first.”
In response to the backlash, Coinkite defended its data retention policy, explaining that purchase email addresses are kept to allow customers to log in and verify that their other information has been blanked. However, the company admitted it does not have a specific deletion schedule for this data, stating that addresses would be retained “for now.”
Novak also highlighted the difficulty of reaching affected customers, as the company does not store other personal information. He called for community assistance in contacting potential victims.
On social media, Coldcard acknowledged the email campaign, saying, “It’s been challenging, but we have now emailed every address we could reach through our store and newsletter systems. The emails have been going out in batches since Friday. If you received one, we want to confirm that it is legitimately from Coinkite.”
The incident has intensified scrutiny on Coinkite’s data practices, with critics arguing that the company prioritized privacy in marketing but failed to fully implement its stated policies. As of Saturday, Galaxy Research reported that the theft had reached 1,367 BTC, valued at over $88 million, with exchange deposits spiking as the stolen funds are moved.