Coinkite Suspends the Policy That Deleted Customer Data After 120 Days

Coinkite has suspended the automated process that erased customer records 120 days after purchase, saying it must preserve documents that may be relevant to legal proceedings arising from the exploit of its Coldcard wallet firmware. The company's blog post carries the date 7 August 2026, while The Crypto Times dated the policy change a day earlier, to 6 August; both dates are on the record, and the company's own post is the later of the two. Under the standard policy, records were blanked automatically after 120 days, leaving only an email address and a country of residence. Customers who would prefer their details not be held can email the company's support address and have their record handled under the original schedule. The effect is blunt: a vendor whose product proposition rests on minimising what it knows about its buyers is now holding that data deliberately.
120 days, then nothing but an email
The rule Coinkite has paused was unusually short by consumer-hardware standards. Records were blanked at the 120-day mark, and accelerated deletion was available on request once an order had been delivered, so a buyer who wanted a purchase history gone could ask immediately rather than wait out the window. What survived the blanking was minimal. An email address and a country of residence remained, enough to reach a customer about a firmware advisory but not enough to reconstruct who bought which device or where it shipped. For a company selling a Coldcard hardware wallet, a device built to keep private keys off internet-connected machines, that schedule was part of the product, not an administrative detail.
Preservation, not investigation
Coinkite's stated basis is legal preservation. "Due to legal obligations arising from the security incident, including the preservation of records that may be relevant to ongoing and anticipated legal proceedings, we have temporarily suspended our automated data-blanking process," the company wrote, adding that it is "required by law to preserve records that may be relevant to legal proceedings" and that "this obligation applies regardless of our internal data-retention policies." The security incident in question is the sweep of coins from wallets generated with flawed firmware, which Galaxy Research put at 1,596 BTC of confirmed losses as of 4 August. No filed lawsuit, plaintiff or law firm is named in the post or in the coverage of it, though a class-action threat had been reported as early as 2 August.
The opt-out survives the freeze
The suspension is not absolute. Customers who email the support address will have their record handled under the original retention policy, Coinkite said, so the freeze applies by default and can be reversed individually on request. That leaves customers a choice that sits awkwardly with both halves of the situation. A buyer who opts out gets the privacy the product was sold on, and in doing so removes a record that a class action or a law-enforcement request might later want. A buyer who does nothing stays in the file. The company said it will resume standard blanking "as soon as we are legally permitted to do so," which places the end of the freeze outside its own control.
No case number to attach it to
Nothing in the post identifies the proceedings the preservation duty attaches to, and at the time of writing the firmware flaw behind the incident had produced no named defendant and no docket number in the coverage we could locate. Until one appears, there is no way to judge how long the freeze runs or which records fall inside its scope. The one-day gap between Coinkite's post and The Crypto Times' account is small in itself. In a matter where dates may eventually be argued over, it belongs on the record anyway. The nearer question for buyers is whether to exercise the opt-out now, before any preservation order that might supersede it.
Read also: Galaxy Counts at Least Fifteen Attackers in the Coldcard Exploit