Search the site
Press ESC to close
LIVE
Loading...
Updating...

Coldcard Updates Data Policy Following Recent Security Incident

Fact-checked
3 min read
413 words
Share

The prominent hardware wallet manufacturer Coldcard has officially announced a temporary suspension of its automated customer data clearing protocols. This decision follows a security incident disclosed on July 30, which has triggered specific legal and compliance obligations for the firm. While the company previously prioritized minimal data retention to enhance user privacy, it is now mandated to preserve records that may be pertinent to ongoing and potential litigation proceedings.

Shift from Automated Deletion to Legal Preservation

Under its standard operating procedure, Coldcard maintained a rigorous privacy policy where customer purchase records were automatically purged after 120 days. Following this period, the company typically retained only essential information, such as user email addresses and country of residence. Furthermore, the firm offered a "manual delete" option, allowing Bitcoin hardware wallet purchasers to request the immediate removal of their data once their device was successfully delivered.

However, the legal landscape surrounding the July 30 security breach has necessitated a pause in these privacy-centric cycles. The company explained that:

Due to ongoing and potential legal proceedings related to the security incident, the company is obligated to retain records that may be associated with litigation.

This means that data which would have normally been erased according to the four-month cycle will now be archived until legal authorities permit the resumption of standard clearing procedures.

User Rights and Data Protection Measures

Despite the suspension of automatic clearing, Coldcard has clarified that users still maintain certain rights regarding their personal information. The company aims to balance its regulatory compliance with its commitment to the cryptocurrency community's privacy expectations.

  • Users may still submit formal requests for the processing of their personal information under the original data retention policy.
  • The temporary retention primarily affects data potentially linked to the forensic investigation of the recent breach.
  • Coldcard continues to utilize encryption and secure storage for any data that remains on their servers during this litigation period.

The manufacturer has signaled that normal data management operations will resume as soon as the legal hold is lifted by relevant jurisdictions.

In conclusion, the adjustment to Coldcard's data policy highlights the complex intersection of blockchain privacy standards and traditional legal requirements. While the suspension of automatic data purging may concern privacy-conscious Bitcoin holders, the company maintains that these steps are an unavoidable consequence of the July 2026 security event. Investors and users are encouraged to monitor official channels for updates on when the standard 120-day deletion cycle will be reinstated.

Frequently Asked Questions

Quick answers to the most common questions about this topic.