Subscribe Now
Trending News

Blog Post

“WE’RE BITCOINERS FIRST” — SAYS THE COMPANY THAT HOARDED YOUR EMAILS FOR 7 YEARS WHILE YOUR COINS GOT DRAINED
Uncategorized

“WE’RE BITCOINERS FIRST” — SAYS THE COMPANY THAT HOARDED YOUR EMAILS FOR 7 YEARS WHILE YOUR COINS GOT DRAINED 

They told you they don’t store your data. They told you anonymous purchases were the point. They told you “we are bitcoiners first.”

Then they emailed every single customer they could find — going back to 2019 — to warn them about the $89 million heist that their own firmware made possible.

So which lie do we believe now?

The “We Don’t Store Anything” Company Has Your Email From 2019

Coinkite, maker of the Coldcard hardware wallet, is under fire tonight — not just for the seed-generation disaster that let an attacker drain 1,367 BTC (~$88 million) from 4,585 addresses — but for the spectacular lie that got exposed in the cleanup.

To warn affected users, Coinkite sent emails to every address associated with purchases dating back to 2019. Every. Single. One. Going back seven years.

Here’s the problem: CEO Rodolfo Novak has spent years telling the world the opposite. “The company doesn’t store customer information,” he claimed. Anonymous purchases. Buyer data “erased 90 days after.” He said the quiet part out loud: “like our customers, we are bitcoiners first.”

Bitcoiners first. Privacy first. We don’t keep your data.

Then they kept your email address for seven years and used it when it was convenient for them.

“We’re Bitcoiners First” — Unless We Need To Reach You

When called out, Coinkite’s defense was honestly worse than the bug. They said purchase emails are saved so customers “can log in and check that their other info has been blanked.”

So the data that was supposed to be erased 90 days after purchase… wasn’t. It was in their systems the whole time — for account logins, for newsletters, for exactly this moment.

And they ADMITTED they have NO data deletion policy.

Let that sink in. A company whose entire brand is “self-custody, privacy, no middlemen, we don’t see your keys” — kept a database of its customers’ email addresses for seven years, with no deletion policy, against its own public promises.

The Actual Crime: Your Keys Were Predictable

While you were being told your data was gone, your actual coins were vulnerable in a way that makes the data retention look like a parking ticket.

A March 2021 firmware build routed seed generation to a predictable software randomiser instead of the chip’s hardware RNG. A bounded set of possible keys. Anyone with the disclosure and enough compute could reproduce your seed offline — without ever touching your device.

Galaxy Research tracked three waves of sweeps:

  • Wave 1 (July 30): 1,082.65 BTC from 1,195 addresses in 41 MINUTES. Forty-one minutes.
  • Wave 2 (July 31): 76.16 BTC from 1,478 addresses.
  • Wave 3 (Aug 1): ~208 BTC from 1,912 addresses — now hidden in 293 separate P2WSH vaults so it’s harder to trace.

The median victim’s address had been inactive for 3.5 years. These were the people who did everything right: hardware wallet, cold storage, offline seeds. The true believers. The ones who trusted “not your keys, not your coins” — and then trusted Coinkite to make the keys.

And the firm that promised to forget them… remembered everything.

While Bitcoiners Run To Exchanges

The fear is real. On July 31, exchanges recorded net inflows of 11,163 BTC in a single day — River, Binance, Kraken, OKX all swelled. The people who got burned are running BACK to custodians. The “not your keys, not your coins” crowd is depositing into exchanges because a hardware wallet vendor just proved it can produce predictable keys for half a decade and call itself “bitcoiners first.”

That’s not just $88 million gone. That’s the trust in the entire cold-storage layer taking a hit — and the irony is it’s the “privacy-first” vendor’s own data-retention policy that got caught with its pants down.

The Question Nobody Wants To Ask

If Coinkite kept your email for seven years while promising to erase it — what else did they keep? And if a hardware wallet company can’t be trusted with YOUR EMAIL, why the hell should anyone trust them with your keys?

Buy your next wallet from someone whose data practices you can actually verify — and don’t let anyone “bitcoiners first” you into handing over anything you can’t take back.

Get started with a broker that respects self-custody: https://loveisbitcoin.com/bull — coupon code LOVEISBITCOIN at checkout.

So tell me: after this, do you still believe hardware wallet companies when they say they “don’t store your data” — or are you checking your email right now?

Previous

"WE'RE BITCOINERS FIRST" — SAYS THE COMPANY THAT HOARDED YOUR EMAILS FOR 7 YEARS WHILE YOUR COINS GOT DRAINED

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal