Coinkite Faces Backlash Over Customer Email Retention After $88M Coldcard Hack
Coinkite is facing customer anger after the Coldcard hardware wallet bug enabled theft of more than 1,000 BTC, with losses estimated at 1,367 BTC (about $88M), according to Galaxy Research. To warn potentially affected buyers, Coinkite emailed addresses tied to purchases dating back to 2019, after seed-generation randomness problems emerged.
However, controversy quickly shifted from the vulnerability to privacy and data-retention practices. Customers criticized Coinkite for keeping email records despite prior claims that customer data would be deleted 90 days after purchase. CEO Rodolfo Novak said the firm retains purchase emails to support account logins and stated there is no clear data deletion schedule, adding that the emails are kept “for now.”
Coldcard also confirmed that batches of emails were being sent through Coinkite’s store and newsletter systems and urged recipients to verify legitimacy. Meanwhile, Novak previously said Coinkite offered anonymous purchases and deleted customer data after 90 days, framing the incident as a serious security matter.
For traders, the key issue is reputational and operational risk: a major wallet exploit plus disputed customer-data handling can trigger short-term sentiment hits toward hardware-wallet vendors and may increase caution around custody and hot-transfer behaviors.
Bearish
The immediate market impact is likely bearish for wallet-related sentiment. A Coldcard seed-generation randomness bug is a high-severity hardware-wallet failure that can shake confidence in self-custody tools, and the estimated scale (1,367 BTC / ~$88M) is large enough to keep attention on exploit timelines and potential follow-on sweeps. When customers then accuse Coinkite of retaining email data without a clear deletion schedule, it adds an additional reputational overhang that can prolong negative coverage and reduce willingness to trust the vendor ecosystem.
In the short term, similar incidents—big wallet compromises followed by operational/privacy disputes—often trigger faster risk-off behavior: traders may rotate away from “convenience custody” solutions, tighten self-transfer practices, and watch for exchange flows and liquidation cascades driven by stolen-fund movement. In the longer term, the effect depends on remediation quality: if Coinkite and Coldcard provide transparent fixes, clear customer-data governance, and visible security improvements, sentiment can stabilize. If not, repeated headlines around wallet exploits and data handling can widen the risk premium for related companies, keeping broader crypto sentiment heavy even if BTC fundamentals remain intact.