On August 7, Coinkite—the Canadian manufacturer of Coldcard hardware wallets—suspended the company's 120-day automatic deletion policy for customer records. The stated cause is a legal record-preservation obligation, triggered by a security event disclosed on July 30. The original policy retained only email addresses and country of residence before purging all other customer data. That design represented the privacy-minimalist benchmark for the hardware wallet industry. It is now suspended indefinitely, with restoration conditioned on an undefined "when legally permitted" standard. The announcement carries no timetable, no verification mechanism, and no independent audit path for the eventual resumption.
The classification matters. This is not a firmware update, and it is not a vulnerability disclosure. It is a legal instrument overriding an automated data-lifecycle process. For a manufacturer whose brand equity rests on trust-minimization—fewer data fields, shorter retention windows, reduced reliance on third-party handling—the absence of a sunset clause is the material finding. Users who selected Coldcard on the basis of its stated data practices now face an indefinite extension of their exposure. The question requiring forensic attention is not whether the company has a legal right to suspend deletion. It does. The question is what exactly was suspended, what was retained, and under what observable conditions the suspension will terminate.
Coldcard is the flagship hardware product of Coinkite Inc., incorporated in 2013 and one of the earliest entrants in the Bitcoin hardware wallet market. The MK4 and Q series devices serve the advanced tier of self-custody users: long-term bitcoin holders, privacy-focused operators, and institutional multi-signature vault services such as Unchained Capital and Casa, which configure Coldcard as a signing device within broader custody frameworks. The product's security architecture follows industry-grade practice: private keys are generated and stored offline, transaction signing is performed via PSBT with air-gapped data transfer, and firmware is released as open source for external review.
The data policy historically mirrored that rigor. Original terms specified automatic deletion of customer records after 120 days, retaining only the email address used for order communication and the country of residence. No order history. No device serial numbers. No shipping addresses. No IP address logs.
Within the competitive landscape, this positioned Coldcard at the strictest end of data-minimization practice. Ledger's 2023 Recover service—which proposed fragmenting seed material for encrypted cloud backup—generated sustained community resistance and damaged that brand's standing among privacy-sensitive users. Trezor's data collection practices remain incompletely documented. BitBox02 and Foundation offer narrower product lines with privacy-forward positioning but more limited market penetration. Coldcard's 120-day deletion schedule was therefore not a peripheral compliance detail; it was a structural feature of the product's value proposition and a load-bearing element in the brand's community standing. The August 7 announcement followed the July 30 security disclosure by eight days. That gap suggests a period of legal assessment and counsel consultation before the policy change was published—a sequencing consistent with an externally triggered preservation requirement rather than a voluntary governance review.
A legal hold requires a company to preserve records when litigation or regulatory inquiry is actual or reasonably anticipated. Destruction of relevant records during that window constitutes spoliation and carries independent legal exposure. The compliance obligation is legitimate; the implementation, as publicly disclosed, presents four issues.
First, the scope of retained records is unspecified. The August 7 statement references "customer records" without enumerating data classes. The original policy retained two fields. The phrase "customer records" is broader and plausibly covers order histories, payment metadata, device serial numbers, shipping addresses, and any identity verification documents collected for particular transactions. Affected users cannot assess actual exposure without a field list. A legal hold scoped to records relevant to the underlying matter is standard practice; a global freeze applied to the entirety of a customer database is an over-broad execution that converts a targeted legal obligation into a generalized privacy downgrade.
Second, the exit mechanism reverses the burden of action. The company states that customers may contact support to request deletion under the original policy. This converts an automated and deterministic procedure into a discretionary, manually reviewed process. The user must self-identify, initiate contact, and await human adjudication, with no published response window, no status tracking, and no verification mechanism to confirm that deletion occurred. In data-governance terms, this is a regression from a closed-loop system to an open-loop system. Behavioral evidence across analogous compliance episodes indicates that the majority of affected users do not act on such opt-in provisions; the practical effect is indefinite retention for the silent majority.
Third, the restoration criterion is a placeholder. "Once legally permitted" is not an operational standard. Determination of when a legal hold expires requires ongoing interpretation of the underlying proceeding's status, and that interpretation resides exclusively within the company. There is no published review date, no external validation requirement, and no commitment to issue a formal restoration notice. The duration of the suspension is therefore unknown. Policy drift is a structural risk, not a theoretical one: an emergency measure becomes standing practice absent a defined termination event.
Fourth, attribution of the July 30 security event remains unresolved. The possible classifications carry different analytical outcomes. A customer-funds incident would draw forensic examination of order records into scope and would likely be limited to affected parties. A data-breach incident implies that retained records may already be accessible to an unauthorized actor, in which case extending the retention window enlarges the potential exposure surface. A supply-chain incident would implicate shipping and recipient information. The statement does not distinguish among these classifications, and user risk assessments differ materially across them.
The regulatory dimension compounds the technical analysis. Coinkite operates under Canadian jurisdiction, where PIPEDA requires personal information to be collected for reasonable purposes and handled consistently with those purposes. The original purpose limitation was explicit: deletion within 120 days. Indefinite retention exceeds that purpose. Legal-hold obligations constitute a recognized exception, but the exception is intended to preserve records relevant to the matter at hand, not to suspend the data rights of unrelated customers indefinitely. For European Union purchasers, GDPR deletion rights yield to legal obligations, but the lawful basis must be demonstrated with reference to the specific records involved. A blanket suspension across all users, regardless of connection to the underlying proceeding, is a compliance shortcut that may not withstand examination.
The ecosystem consequences follow from the trust architecture. Hardware wallet adoption rests on three layers of user trust: confidence in the code, confidence in the supply chain, and confidence in the manufacturer's data policy. This three-layer mapping is the same framework I applied in my 2024 audit of Bitcoin ETF custody structures, where regulatory approval and cryptographic security proved to be independent axes. Here, the code layer is unaffected. The supply chain is unaffected. The data-policy layer has been modified by unilateral action under legal compulsion. Users do not necessarily abandon working hardware of this quality over one policy change. They do alter acquisition channels. Expect incremental movement toward third-party distributors, cash-based purchases, and self-assembled signing solutions that require no corporate data intermediary at all.
The quantitative dimension deserves explicit articulation. The retention window extends from a fixed 120-day term to an open-ended term. The probability that the retained dataset experiences future compromise or internal misuse is a monotonic function of the retention period: each additional month of holding increases cumulative risk, particularly for a manufacturer whose systems recorded a security event within the prior fortnight. The expected loss, should a breach occur, scales with the volume of data retained. The company has not communicated the storage state during the hold—whether retained records are encrypted at rest, and what access controls apply. Information asymmetry of this form is precisely what the original deletion policy had been designed to prevent.
A dispassionate read of the company's position is warranted, and several points favor Coldcard. The cryptographic product core is unaffected. Private keys are generated and stored offline; air-gapped signing functions operate intact. The trust guarantee that matters most—the impossibility of the device leaking key material—has not been compromised. Legal hold is also not discretionary. Any advised manufacturer must preserve records when legal proceedings are actual or reasonably anticipated; noncompliance with a preservation notice is independently sanctionable. Given the coercive context, the proactive disclosure of the suspension represents a transparency act relative to a quieter alternative.
The original data-minimization design remains evidence of institutional intent. The 120-day policy was operational practice, not marketing. The commitment to restore automatic deletion when legally permitted is consistent with that history. Coinkite's record includes responsible coordinated vulnerability disclosures and consistent iteration across the MK1 through MK4 and Q generations. No documented pattern of promise-breaking precedes this event. Competitive alternatives carry their own vulnerabilities: Ledger retains the Recover controversy, Trezor's practices are less clearly documented, and smaller competitors lack the track record of secure iteration at scale. Loyalty accumulated over a decade is not consumed by a single compliance episode.
The legitimate criticism remains proportionality. Preserving records pertaining to specific users or transactions is the narrow implementation. A global suspension draws no distinction between a user whose records are directly relevant to the proceeding and a customer who purchased a device three years ago. That lack of proportionate scoping pressures the company's standing among precisely the users whose continued trust constitutes its principal commercial asset.
The variable to monitor is restoration accountability. If Coinkite publishes a post-resolution report enumerating the retained data classes, documenting resumption of automatic deletion, and subjecting that restoration to independent verification, the episode will register as a temporary compliance interruption in a longer record. If the suspension persists without disclosure, the industry benchmark will shift.
The 120-day deletion clock was a feature. The legal hold converts it into a precedent—a demonstration that the deletion promise was always conditional on the absence of legal compulsion, and that the condition can be triggered without user consent. The standardization of custody risk was the prior decade's project. Standardizing deletion risk—who holds authority over the data kill switch, under what procedural conditions it may be pulled, and how restoration is verified—is the necessary successor. Coldcard's suspension will either become a case study in transparent restoration or a cautionary note on enterprise dependence.

