A randomness flaw in seed generation for Coldcard hardware wallets has been linked to the theft of more than 1,000 BTC over the past two days, according to the report cited by Odaily. Data from Galaxy Research showed that, as of 5:36 p.m. Eastern Time on Saturday, the incident involved 1,367 BTC, with losses topping $88 million. In response, hardware wallet maker Coinkite said it sent security alerts to email addresses it had retained since 2019 through its store and newsletter systems in order to reach potentially affected users. Coldcard confirmed the messages were authentic and said it had contacted as many reachable addresses as possible. That step, however, drew scrutiny to Coinkite’s data retention practices. The company said its public policy states that purchase email addresses are kept so customers can log in and verify that other information has been cleared, but it did not provide a deletion timeline and said those addresses would be kept temporarily. The report also noted that Coinkite co-founder and CEO Rodolfo Novak had previously said the company does not store customer information, deletes customer data 90 days after purchase, and offers an anonymous purchase option.
A seed-generation randomness flaw in Coldcard hardware wallets has been tied to the theft of more than 1,000 BTC over the past two days, according to a report carried by Odaily.
Galaxy Research data showed that, as of 5:36 p.m. Eastern Time on Saturday, the incident involved 1,367 BTC, with losses exceeding $88 million.
Coinkite sent alerts to retained email addresses
To notify users who may have been affected, Coinkite sent security alerts to email addresses it had retained since 2019 through its store and newsletter systems. Coldcard confirmed that the emails came from Coinkite and said it had tried to reach all addresses it could still contact.
Data retention practice draws criticism
Coinkite also came under criticism for retaining customer email data. The company said its public policy explains that purchase email addresses are kept so customers can log in and check whether other information has been cleared, but it did not give a deletion timetable and said those addresses would be kept "temporarily."
The report added that Coinkite co-founder and CEO Rodolfo Novak had previously said the company does not store customer information, deletes customer data 90 days after a purchase, and offers an anonymous purchase option.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.