NewsCryptoColdcard Reverses Data-Deletion Policy After $116 Million Wallet Exploit

Coldcard Reverses Data-Deletion Policy After $116 Million Wallet Exploit

Author: Cryptopolitan·

Key Takeaways

  • A firmware vulnerability in Coldcard wallets (version 4.0.1, shipped March 2021) enabled attackers to reconstruct private keys by exploiting a flawed pseudo-random number generator called Yasmarang, resulting in approximately $116 million in losses.
  • The attacker has accumulated 1,816 BTC across more than 5,200 addresses through four documented attack waves since July 30, 2026, with the initial wave draining roughly 594 BTC from approximately 500 wallets in 25 minutes.
  • Coinkite will no longer automatically delete customer records, citing legal obligations arising from the security incident, representing a significant departure from its previous privacy-first data practices.
  • Chainalysis data indicates approximately 25% of attributed losses affected holders in Canada, with the United States and Thailand also significantly impacted due to early Bitcoin adoption and targeted influencer campaigns.
  • A group known as the Red Team, led by AnchorWatch CEO Rob Hamilton, has launched AI-assisted audits of Bitcoin wallets and libraries, scanning 150 repositories in response to growing recognition that firmware supply chains require rigorous third-party auditing.
Coldcard Reverses Data-Deletion Policy After $116 Million Wallet Exploit

Coinkite, the manufacturer of the Coldcard hardware wallet—a device long regarded as a premium option among Bitcoin self-custody advocates—has informed users of significant changes to its data retention practices following a $116 million exploit, the largest security incident of July 2026. The notice, reshared on Coldcard's official X account early Friday, announced that Coinkite will no longer automatically delete customer records.

The policy reversal is directly tied to a firmware exploit that has drained more than $100 million in Bitcoin from Coldcard hardware wallets since July 30, 2026.

Changes to User Data Handling

Coinkite confirmed it will modify how it processes customer data "in connection with the security incident disclosed on July 30, 2026." Prior to this change, the company routinely deleted customer records, retaining only email addresses and countries of residence.

The shift is described as preparation for "legal obligations" arising from the theft. Large-scale cryptocurrency exploits frequently generate civil litigation and regulatory inquiries, proceedings that typically require extended retention of transaction records, customer communications, and forensic evidence. Coinkite did not specify what additional data it intends to store or for how long the new retention period will last.

The move marks a notable departure from the privacy-first, self-custody principles long championed within the Bitcoin community, where minimizing data collection has been viewed as a core security feature rather than merely a privacy preference.

Details of the Exploit

The data retention overhaul follows one of 2026's most damaging security incidents. The vulnerability targeted firmware version 4.0.1, which Coinkite shipped in March 2021.

At the core of the exploit is the way hardware wallets generate seed phrases. A seed phrase encodes the entropy from which all private keys are derived; if the random number generator producing that entropy is flawed, attackers can independently reconstruct the same keys without ever touching the physical device. This class of vulnerability is particularly severe because it bypasses the hardware protections—secure elements, PIN gates, and physical tamper resistance—that define a hardware wallet's value proposition.

As TRM Labs warned, installing the patched firmware only protects wallets created going forward. Any seed generated on a vulnerable Coldcard between March 2021 and the patch release should be considered compromised.

Cryptopolitan has documented four attack waves since the exploit was first reported on July 30. The initial wave drained approximately 594 BTC—worth nearly $38 million at the time—from roughly 500 wallets in just 25 minutes. Galaxy Research tracked three additional waves over the following four days. As of this report, the attacker has accumulated 1,816 BTC across more than 5,200 addresses.

TRM Labs classifies the incident as the third-largest cryptocurrency hack of 2026, a year in which the industry has already lost more than $1.2 billion across 276 incidents. Unlike smart-contract breaches that dominate exchange and DeFi losses, hardware wallet exploits directly undermine the trust model of offline self-custody—a segment that has historically received less third-party security auditing than protocols and dApps.

Coinkite Pushes Back on Prior-Knowledge Claims

As losses mounted, accusations emerged that Coinkite had been aware of the flaw for years. The company has publicly pushed back against these claims.

Responding to Jack Mallers on August 7, COLDCARD stated on X that "there wasn't a weak entropy fallback," arguing that the weak pseudo-random number generator (PRNG), named Yasmarang, was MicroPython's built-in general-purpose generator introduced upstream—rather than a Coinkite-designed fallback.

Separately, on August 5, reports indicated that a 2021 Rabbit Hole Recap episode, frequently cited as evidence of prior knowledge, actually referenced a different vulnerability—not the RNG issue. Coinkite's own historical disclosure page lists 23 security-relevant events dating back to 2019, and the company has repeatedly directed critics to it.

Geographic Distribution of Losses

Geographic factors significantly influenced the damage. Cryptopolitan reported on August 5 that approximately 25% of attributed losses traced to holders in Canada, with the United States and Thailand also heavily affected. These findings were based on Chainalysis data linking the wallet address database to likely regions.

Chainalysis attributed Canada's disproportionate exposure to early Bitcoin adoption and influencer campaigns that promoted Coldcard within the country.

The fallout has extended beyond direct losses. CoinMarketCap's weekly research note stated that the hack has shaken confidence in self-custody solutions and driven some Bitcoin users back toward centralized exchanges. In response, a group known as the Red Team, led by AnchorWatch CEO Rob Hamilton, has launched AI-assisted audits of Bitcoin wallets and libraries, scanning 150 repositories to date—an effort that reflects growing recognition that entropy generation and firmware supply chains warrant the same rigorous auditing culture that has matured around smart contracts in recent years.