Coinkite Under Fire for Retaining Customer Emails After $88M Coldcard Hack

CN
2 hours ago

Key Takeaways

  • Coinkite emailed buyers dating back to 2019 to warn of a bug, sparking anger over data retention.
  • Users slammed the firm for storing email data despite past claims of erasing buyer info after 90 days.
  • Coinkite defended holding emails for account logins, but admitted it lacks a data deletion schedule.

Coinkite is again facing the ire of its customers in the aftermath of a seed generation randomness bug that allowed threat actors to steal over 1,000 BTC in the last two days.

In an effort to reach the majority of customers who could be affected by the issue plaguing its Coldcard series of hardware wallets, the company sent emails to alert about the severity of this event to email addresses associated with purchases starting in 2019.

On social media, Coldcard acknowledged that it had been contacting its customers via email, reaffirming the legitimacy of these messages.

“It’s been challenging, but we have now emailed every address we could reach through our store and newsletter systems. The emails have been going out in batches since Friday. If you received one, we want to confirm that it is legitimately from Coinkite,” the company explained.

When criticized for retaining email data, Coinkite pointed to its public policy, which states that purchase email addresses are saved so customers can log in and check that their other info has been blanked. Nonetheless, the company did not indicate a deletion policy for this data, pointing out that these addresses would be kept “for now.”

Even so, Rodolfo Novak, co-founder and CEO of Coinkite, stressed that the company doesn’t store customer information and had no way to reach affected customers, calling for assistance in contacting all possible affected users.

In an earlier post, Novak had claimed that the company provided the option to make anonymous purchases and erased customer data 90 days after.

“Every other month one of our competitors has a data breach. Coinkite/COLDCARD takes this extremely seriously, like our customers, we are bitcoiners first,” he stressed at the time.

According to Galaxy Research, the event had already reached 1,367 BTC at 5:36 p.m. EDT on Saturday, accounting for over $88 million in losses.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink