Coinkite's Customer Email Retention Sparks Criticism Amid Coldcard Breach
Coinkite is facing criticism for retaining customer emails after a major security breach involving its Coldcard wallet. The company sent out security notices to customers dating back to 2019, warning them about the high risk of losing their Bitcoin due to a seed generation randomness bug. However, this move has sparked anger among customers who were assured that Coinkite would erase buyer information after 90 days.
The bug allowed threat actors to steal over $88 million in BTC, with losses reaching 1,367 BTC as of Saturday evening. Coinkite's CEO Rodolfo Novak had previously stated that the company retained customer data for just 90 days after a purchase, but it appears this is not the case.
Coinkite defended its decision to hold onto email data, citing its public policy which allows customers to log in and check their information. However, the company lacks a deletion schedule for this data, leaving many to question its commitment to customer security.