temporarily suspended its automatic customer data deletion process due to legal obligations stemming from the security incident disclosed on July 30. Coldcard said its normal automated deletion process will resume once it is no longer legally required to preserve the information. The move effectively creates a temporary preservation hold on customer records that could potentially become evidence in investigations or litigation surrounding the July incident. According to , attackers approximately 1,596 BTC from around 7,300 wallet addresses across three confirmed attack waves linked to the Coldcard vulnerability. For now, Coldcard's usual 120-day deletion process is suspended as investigations and potential legal proceedings surrounding the July incident continue.