Coldcard pauses automatic customer data deletion after July BTC wallet exploit

Coldcard has temporarily halted its automatic customer data deletion due to legal obligations tied to a July 30 security incident. Under its normal policy, Coldcard “blanked” customer records after 120 days, keeping only email and country. After the July exploit, the company said it must preserve potentially relevant records for investigations and possible litigation. Coldcard says customers can still opt out of this legal retention by contacting support to apply the original retention schedule instead. The company also stressed that retained data will be restricted to authorized personnel and used only for compliance. The policy change follows a major hardware-wallet vulnerability linked by Galaxy Research to theft of 1,596 BTC from about 7,300 wallet addresses across three confirmed attack waves. Galaxy also flagged a potential fourth, unconfirmed wave that could raise total losses toward ~2,055 BTC. Earlier technical disclosures attribute the flaw to reduced seed randomness in affected firmware: instead of using the hardware-backed RNG, vulnerable devices relied on MicroPython’s deterministic PRNG during wallet seed generation. This allowed attackers to reproduce candidate wallet seeds offline, derive addresses, and compare against public blockchain data. Coinkite reports patched firmware for affected models and says updates only protect wallets created after the fix; users with vulnerable-generated seeds are urged to create new seeds and verify with test transactions.
Neutral
This is primarily a compliance-and-privacy change by Coldcard rather than a new market-moving technical exploit. For traders, the direct implication is limited: no immediate evidence suggests fresh BTC theft is occurring today. However, the backstory—1,596 BTC confirmed losses (and a possible additional unconfirmed wave) tied to weakened seed randomness—keeps the security overhang in focus. In similar past hardware-wallet compromise cycles, markets often see short-lived volatility around disclosure headlines, followed by a fade unless additional wallet-drain waves are confirmed. Here, the retention policy extension may slightly increase operational friction for affected users (who must manage new seeds and verify balances), but it does not change Bitcoin network fundamentals. Short term, BTC sentiment could remain cautious due to the ongoing investigation and potential fourth wave. Long term, patched firmware and investor awareness typically reduce tail-risk, which tends to be neutral-to-slightly bullish for confidence in self-custody. Overall, expect a neutral market impact: headline-driven attention may affect sentiment briefly, but absent confirmation of new theft waves or systemic issues beyond specific firmware versions, broader market stability should hold.