Coldcard temporarily suspended its automatic customer data deletion process due to legal obligations stemming from the security incident disclosed on July 30. The hardware wallet maker announ
Coldcard temporarily suspended its automatic customer data deletion process due to legal obligations stemming from the security incident disclosed on July 30.
The hardware wallet maker announced the change on X, saying it must preserve customer records that could become relevant to ongoing or anticipated legal proceedings connected to the incident.
Under Coldcard’s normal privacy policy, most customer records are automatically blanked after 120 days, with only email addresses and countries of residence retained. Customers have also historically been able to request accelerated deletion once their orders were delivered. That process has now been temporarily paused.
Coldcard suspends 120-day deletion policyColdcard said records that would ordinarily be deleted will instead be preserved until the legal requirement ends.
The company acknowledged that the measure is a departure from its published privacy practices, but said retained information will stay securely stored, access will be restricted to authorized personnel, and the data will only be used to comply with legal obligations.
Customers who do not want their information preserved under the new protocol can still contact Coldcard support and request that the company's existing retention policy be applied.
Coldcard said its normal automated deletion process will resume once it is no longer legally required to preserve the information.
The move effectively creates a temporary preservation hold on customer records that could potentially become evidence in investigations or litigation surrounding the July incident.
Coldcard exploit losses reach 1,596 BTCThe policy change comes as investigators continue assessing one of the largest hardware wallet security incidents reported this year. According to Galaxy Research, attackers stole approximately 1,596 BTC from around 7,300 wallet addresses across three confirmed attack waves linked to the Coldcard vulnerability.
A suspected fourth wave could increase losses to roughly 2,055 BTC. However, Galaxy has not included those additional funds in its confirmed total because it has not received enough reports from affected wallet owners.
Galaxy's head of firmwide research, Alex Thorn, has also said blockchain evidence suggests the suspected fourth wave was “substantially comprised of” a single attacker.
Confirmed attacker and victim addresses have reportedly been shared with US federal law enforcement agencies, cryptocurrency exchanges and cyber-investigation firms. This could allow regulated platforms to identify and potentially flag stolen funds if attackers try to move them through centralized exchanges.
For now, Coldcard's usual 120-day deletion process is suspended as investigations and potential legal proceedings surrounding the July incident continue.