Coinkite triggered backlash after it sent warning emails about a critical flaw in its Coldcard hardware wallets to customers dating back to 2019. The messages alerted users to a seed generation bug that hackers exploited to steal over 1,000 BTC in the past two days. However, many buyers were outraged to learn their email addresses had been stored far longer than the company previously claimed.

Rodolfo Novak, Coinkite’s CEO and co-founder, had assured earlier that customer data was erased 90 days after purchase and that anonymous buying was possible. Yet the company’s recent outreach contradicted this by leveraging emails tied to purchases from several years ago. Coinkite acknowledged holding onto these addresses to allow customers to log in and verify their other personal info had been cleared, but did not specify any formal deletion schedule. Instead, the emails remain stored “for now.”

On social media, Coldcard confirmed the legitimacy of the email alerts and said sending them in batches was a difficult but necessary step. Novak also admitted that the company had limited means to reach all potentially affected users and asked for help spreading the word. This incident has raised fresh concerns about data retention practices in the hardware wallet industry, following repeated high-profile breaches elsewhere.

material is informational and not financial advice