Coldcard, made by Coinkite (Toronto), is the Bitcoin-only hardware wallet most associated with the power-user and sovereignty-focused end of the market. The flagship Coldcard Q (150; verify current — succeeded by the Coldcard Mk5 at ~$170 as of 2026-07-15) remains the simpler keypad+MicroSD model. Distinctive features include native BIP-85 child-seed derivation (9,999-index convention), strong PSBT and descriptor support, dice-based entropy at setup, and full air-gap operation via MicroSD or QR. Firmware is source-available under a non-OSI public licence — auditable but not freely redistributable — placing Coldcard between fully-open vendors like BitBox and closed vendors like Ledger. Coldcard suits holders comfortable with a power-user UX who want strict air-gap discipline; it is overkill for casual single-sig holders better served by a simpler device.


What this is

Vendor: Coinkite Inc. (Toronto, Canada). Founded by Rodolfo “NVK” Novak and Peter Gray (2014). Coinkite is among the longest-operating Bitcoin-only hardware-wallet vendors, with a sovereignty-and-Bitcoin-only philosophical stance that aligns with the strong-self-custody community.

Product line as of 2026-07-15:

  • Coldcard Q ($249) — the flagship. Full QWERTY keyboard, colour display, USB-C, NFC, MicroSD slot, camera for QR-code signing. The first hardware wallet with a real keyboard, which transforms passphrase-entry ergonomics.
  • Coldcard Mk4 (170) — the same keypad+MicroSD form factor with an improved screen and buttons; the analysis on this page applies to both._ Still firmware-supported; the right choice for holders who don’t need the Q’s keyboard.
  • Coldcard Mk3 and earlier — discontinued but still firmware-supported. Existing holders need not upgrade urgently.

Firmware: Source-available under Coldcard’s own licence (not OSI-approved but publicly readable and auditable). The reasoning the team has published: they want auditability without permitting clones built on their work. The synthesis treats this as a legitimate middle position between fully open-source (Trezor, BitBox02) and fully closed-source (Ledger).

Secure element: Coldcard uses a dual-chip architecture — a main microcontroller plus a secure element (specifically, ATECC608A or equivalent) for key storage. This provides physical-attack resistance comparable to Ledger and Foundation Passport.


Who this is for

Coldcard is a strong fit for:

  • Multisig power users — strong PSBT and descriptor support, vendor-diverse-multisig friendly, BIP-85 for derived multisig keys
  • Passphrase-heavy workflows (Coldcard Q) — the full QWERTY keyboard makes entering complex passphrases tractable in a way no other hardware wallet matches
  • BIP-85 users — Coldcard’s BIP-85 implementation is the canonical one; 9,999-index searchable space; supports BIP-39 mnemonic derivation, WIF, and hex output
  • Air-gap-disciplined holders — Coldcard works fully air-gapped via MicroSD (Mk4) or QR + MicroSD (Q); no USB connection needed for signing
  • Holders who want dice-entropy contribution — Coldcard supports adding user-provided dice rolls to the seed-generation process, supplementing the device’s RNG
  • Long-term holders comfortable with a power-user UX — Coldcard is not aimed at first-time users; it rewards engagement with the device’s features

Coldcard is less appropriate for:

  • First-time hardware-wallet users — the UX is power-user oriented; the simpler keypad-and-screen Mk4 helps but Trezor or BitBox is gentler
  • Frequent spenders — the air-gap workflow has more steps than USB-connected signing
  • Non-technical holders — Coldcard’s features are deep but expect engagement; a holder who doesn’t want to learn the device will not get the value
  • Holders who care strongly about OSI-approved open-source firmware — the source-available licence is not fully open in the OSI sense; BitBox or Trezor is a better fit

Features and capabilities

Coldcard Q specifics (2026 flagship)

  • Full QWERTY physical keyboard — the differentiating feature. Passphrase entry that previously required minutes of button-mashing on the Mk4 takes seconds on the Q.
  • Colour display — sharper, more legible, better for verification of long addresses
  • Camera — for scanning PSBT QR codes from the coordinator
  • NFC — for tap-to-receive interaction with mobile coordinators (Nunchuk, others)
  • MicroSD slot — for PSBT transfer via card (air-gap option)
  • USB-C — for connected workflows, firmware update, file transfer
  • Replaceable batteries — the Q operates on AA batteries, which the device sips from; battery life is months under typical use

Common to Coldcard line

  • BIP-85 child-seed derivation — derive BIP-39 12/18/24-word children, WIF private keys, hex output, at user-selected indexes (0–9999 by default). The canonical BIP-85 implementation.
  • PSBT v2 support — full Partially Signed Bitcoin Transaction handling
  • BIP-380 output descriptors — modern descriptor format for multisig
  • Native multisig — up to 15-of-15; vendor-diverse multisig friendly
  • BIP-39 passphrase support — multiple passphrase wallets switchable on the device
  • Dice-entropy contribution — user-provided dice rolls supplement the RNG at seed generation
  • Bitcoin-only firmware — no altcoin support; reduces attack surface
  • Secure element — ATECC608 family; physical-attack resistance
  • Brick-me PIN — a special PIN that wipes the device immediately; option for coercion scenarios

Coldcard-specific quirks

  • The trick PINs feature allows multiple PINs to map to different behaviours (decoy wallet, real wallet, brick-the-device) — a duress-response feature that requires careful planning to use safely
  • The MicroSD-based firmware update is the only path; no over-the-network updates, which is structurally safer but operationally heavier than USB updates
  • The dice-entropy contribution is a specific Coldcard feature that some holders value highly; others see it as a misplaced concern (the device’s hardware RNG is well-engineered)

Tradeoffs vs alternatives

DimensionColdcard QColdcard Mk4BitBox02 BTC-onlyFoundation PassportTrezor Safe 5
Price$249$150$137$199$129
Bitcoin-onlyYesYesYes (BTC-only variant)YesNo (multi-coin)
Open-source firmwareSource-availableSource-availableYes (OSI)Yes (OSI)Yes (OSI)
Secure elementYesYesYesYesYes
Air-gap signingQR + MicroSDMicroSD onlyNo (USB only)QR onlyNo (USB only)
Native SLIP-39NoNoNoNoYes
BIP-85ExcellentExcellentGoodLimitedGood
Passphrase entryBest (QWERTY)TediousGood (touch-input)Good (touchscreen)Excellent (touchscreen)
Multisig supportExcellentExcellentExcellentExcellentGood
Lopp 100-input signing (per 2024 report)FastFastFastFastModerate

Compared to BitBox02: Coldcard is more feature-rich (BIP-85, air-gap MicroSD) but the BitBox02’s pure-USB workflow is simpler. Many holders run multi-vendor multisig with Coldcard + BitBox02 specifically for the complementary feature sets.

Compared to Foundation Passport: both target the air-gap-disciplined holder. Passport’s QR-only workflow is structurally cleaner; Coldcard’s MicroSD option provides a fallback path. Passport’s UX is more polished; Coldcard’s feature depth is greater.

Compared to Trezor: Coldcard is Bitcoin-only and more sovereignty-aligned; Trezor is multi-coin (which some holders see as an attack-surface increase) and has native SLIP-39 (which Coldcard does not).


Setup and operation

The setup flow (high-level):

  1. Verify packaging — Coldcards ship with a glued security bag and serial number printed on the bag. Verify the bag is intact and the serial matches the device.
  2. Initial boot — set a PIN. Coldcard’s PIN structure is unusual: a “prefix” then “remainder,” with the prefix producing a two-word anti-phishing phrase that helps verify the device hasn’t been tampered with.
  3. Generate seed — choose dice entropy or no dice; Coldcard generates 12 or 24 words. Record the seed by hand.
  4. Verify the seed — Coldcard offers a verification flow where it asks for specific words at specific positions.
  5. Optionally set up a passphrase — Coldcard supports BIP-39 passphrases; on the Q, entry is via QWERTY; on the Mk4, entry is via numeric keypad with letter cycling.
  6. Pair with a coordinator — Sparrow, Specter, Nunchuk, Casa, Unchained, Bitcoin Core. Pairing typically involves exporting an xpub or descriptor from the Coldcard.

The operational flow for signing:

  • Coordinator builds the PSBT
  • Transfer to Coldcard: via USB (cable), MicroSD (write file to card, insert), or QR code (Q only; scan with camera)
  • Coldcard displays the transaction details; the holder verifies the destination address on the device screen
  • Holder confirms; Coldcard signs internally
  • Transfer signed PSBT back: same channel
  • Coordinator finalizes and broadcasts

For multisig, the same flow but the PSBT visits multiple devices (one per required signature) before finalization.

The air-gap version: replace all USB transfers with MicroSD or QR. The device never connects to a network-connected machine.


Security considerations

Strengths

  • Bitcoin-only firmware — reduces attack surface; no altcoin-related code paths
  • Secure element — physical-attack resistance comparable to Ledger and Passport
  • Source-available firmware — independent auditors can review the code
  • Air-gap capability — for holders who use it, structurally narrower exposure window
  • Trick PINs — when used carefully, provide duress-response options
  • Brick-me PIN — option to wipe the device under coercion (with backups intact)

Known concerns

  • The source-available licence — not OSI-approved; some open-source purists treat this as a meaningful gap from fully-open Trezor and BitBox02. The code is auditable in practice.
  • Updates require MicroSD — slower than USB-based updates; some holders defer updates as a result. The discipline of staying current with firmware should be maintained.
  • The “Recovery” history — Coldcard has had specific bugs over the years (one notable issue with how it handled certain edge cases in multisig signing); the team’s response track record is strong (rapid patching, transparent disclosure).
  • Brand-loyalty community can be contentious — some Coldcard advocates push the device for use cases where it doesn’t fit. This is a community-vibe concern, not a device-security concern.

Supply-chain integrity

Buy directly from coldcard.com or authorized resellers. Coinkite is based in Toronto and ships globally. The glued security bag with printed serial is the canonical tamper-evident check.

The 2020 Ledger customer-data leak does not affect Coldcard; Coinkite’s customer database has not had a public leak. Coldcard purchasers are still on a smaller-than-Ledger but still-meaningful list; holders concerned about KYC-data correlation should consider shipping options.


Pricing and acquisition

As of 2026-07-15 (prices reverified; prior review 2026-05-14):

  • Coldcard Q: $249 USD MSRP
  • Coldcard Mk4: 170 as of 2026-07-15)
  • Accessories: dice for entropy contribution, MicroSD cards, USB-C cables — all reasonable to source separately

Coldcard ships internationally. Some regulatory and customs friction depending on jurisdiction; the Coinkite team publishes current shipping policies.

Authorized channels: coldcard.com directly is the canonical purchase channel. Some authorized resellers exist (Bitcoin-focused retailers like Bitcoin Magazine store); these are vetted by Coinkite. Avoid eBay, Amazon, and other generic marketplaces — the supply-chain integrity guarantee is weaker through those channels.

Bulk and business pricing: Coinkite offers volume discounts for Coldcards used in multisig setups (typical 3-of-3 multisig holders).


Common pitfalls

Buying a Coldcard for a use case it doesn’t fit. Coldcard is overkill for casual single-sig holders. A Tier 1 holder who wants a hardware wallet may be better served by BitBox02 or Trezor for the simpler UX.

Skipping the security-bag verification. The bag check is fast and catches some categories of supply-chain attacks. Don’t skip it.

Forgetting the PIN structure. Coldcard’s prefix-and-remainder PIN scheme is unusual. Document the structure (not the PIN itself); a holder who forgets that there’s a prefix will be confused at recovery.

Misusing trick PINs. The trick-PIN feature enables decoy and duress responses. Used carelessly, the holder forgets which PIN does what and triggers an unintended wipe. Use cautiously and document carefully.

Treating BIP-85 children as more secure than the master. A BIP-85-derived child seed is exactly as secure as the master. Compromise of the Coldcard’s main seed compromises every BIP-85 child. See BIP-85 child seeds.

Avoiding firmware updates because the MicroSD process is friction. Firmware updates address real vulnerabilities. The MicroSD process is heavier than USB but is still tractable; don’t defer updates indefinitely.

Using the brick-me PIN as a routine response. It is a coercion-response option, not a daily security feature. Triggering it wipes the device; recovery requires the seed backup.

Three identical Coldcards in multisig. Defeats vendor diversity. The standard recommendation: Coldcard plus two different vendors for 2-of-3 multisig.


Tooling and resources

Coldcard documentation (as of 2026-05-14):

  • coldcard.com — official site
  • The Coldcard manual (downloadable PDF) — comprehensive operational reference
  • Coinkite blog — release notes, security advisories, philosophical posts
  • The “NVK on Twitter” account — Rodolfo Novak’s running commentary on the Bitcoin-and-self-custody scene

Coordinator software supporting Coldcard:

  • Sparrow Wallet — desktop, excellent Coldcard support
  • Specter Desktop — desktop, multisig-focused
  • Nunchuk — desktop and mobile
  • Bitcoin Core (with PSBT) — for the deeply technical
  • Casa app, Unchained app — collaborative-custody coordinators that support Coldcard as one of several allowed hardware wallets

Community resources:

  • The Coldcard subreddit and community forums — sometimes contentious, often informative
  • Lopp’s writing — Coldcard receives substantive treatment in operational essays. See Jameson Lopp.

The synthesis document (canonical for the section):

  • Bitcoin Self-Custody & Security: A Synthesis of Contemporary Best Practices, LegacyCipher discussion, April 2026 — Coldcard treated as a strong choice for power users.

As of 2026-07-15: the Coldcard Q has been available since late 2024; firmware is actively updated. The Mk4 has been succeeded by the Coldcard Mk5 (~$170), the current keypad-and-screen model. (Prior review 2026-05-14.)


Open questions for further development

  • Coldcard’s source-available licence is treated as a legitimate middle position by some practitioners and as a meaningful gap by open-source purists. Should the framework take a stronger stance?
  • The Coldcard Q’s QWERTY keyboard is a substantial UX advance for passphrase-heavy workflows. Will competitors adopt similar designs, and does this shift the device-selection calculus more broadly?
  • Coinkite’s philosophical alignment (Bitcoin-only, sovereignty-focused) is part of the brand. Is this alignment doing real work for users, or is it primarily a marketing position?

The framing context:

Per-device alternatives:

Coldcard-relevant capabilities:

Custody configurations:

Operational practice:

The principal practitioner:

The sub-MOC home: