Coldcard, made by Coinkite (Toronto), is the Bitcoin-only hardware wallet most associated with the power-user and sovereignty-focused end of the market. The flagship Coldcard Q (150; verify current — succeeded by the Coldcard Mk5 at ~$170 as of 2026-07-15) remains the simpler keypad+MicroSD model. Distinctive features include native BIP-85 child-seed derivation (9,999-index convention), strong PSBT and descriptor support, dice-based entropy at setup, and full air-gap operation via MicroSD or QR. Firmware is source-available under a non-OSI public licence — auditable but not freely redistributable — placing Coldcard between fully-open vendors like BitBox and closed vendors like Ledger. Coldcard suits holders comfortable with a power-user UX who want strict air-gap discipline; it is overkill for casual single-sig holders better served by a simpler device.
What this is
Vendor: Coinkite Inc. (Toronto, Canada). Founded by Rodolfo “NVK” Novak and Peter Gray (2014). Coinkite is among the longest-operating Bitcoin-only hardware-wallet vendors, with a sovereignty-and-Bitcoin-only philosophical stance that aligns with the strong-self-custody community.
Product line as of 2026-07-15:
- Coldcard Q ($249) — the flagship. Full QWERTY keyboard, colour display, USB-C, NFC, MicroSD slot, camera for QR-code signing. The first hardware wallet with a real keyboard, which transforms passphrase-entry ergonomics.
- Coldcard Mk4 (170) — the same keypad+MicroSD form factor with an improved screen and buttons; the analysis on this page applies to both._ Still firmware-supported; the right choice for holders who don’t need the Q’s keyboard.
- Coldcard Mk3 and earlier — discontinued but still firmware-supported. Existing holders need not upgrade urgently.
Firmware: Source-available under Coldcard’s own licence (not OSI-approved but publicly readable and auditable). The reasoning the team has published: they want auditability without permitting clones built on their work. The synthesis treats this as a legitimate middle position between fully open-source (Trezor, BitBox02) and fully closed-source (Ledger).
Secure element: Coldcard uses a dual-chip architecture — a main microcontroller plus a secure element (specifically, ATECC608A or equivalent) for key storage. This provides physical-attack resistance comparable to Ledger and Foundation Passport.
Who this is for
Coldcard is a strong fit for:
- Multisig power users — strong PSBT and descriptor support, vendor-diverse-multisig friendly, BIP-85 for derived multisig keys
- Passphrase-heavy workflows (Coldcard Q) — the full QWERTY keyboard makes entering complex passphrases tractable in a way no other hardware wallet matches
- BIP-85 users — Coldcard’s BIP-85 implementation is the canonical one; 9,999-index searchable space; supports BIP-39 mnemonic derivation, WIF, and hex output
- Air-gap-disciplined holders — Coldcard works fully air-gapped via MicroSD (Mk4) or QR + MicroSD (Q); no USB connection needed for signing
- Holders who want dice-entropy contribution — Coldcard supports adding user-provided dice rolls to the seed-generation process, supplementing the device’s RNG
- Long-term holders comfortable with a power-user UX — Coldcard is not aimed at first-time users; it rewards engagement with the device’s features
Coldcard is less appropriate for:
- First-time hardware-wallet users — the UX is power-user oriented; the simpler keypad-and-screen Mk4 helps but Trezor or BitBox is gentler
- Frequent spenders — the air-gap workflow has more steps than USB-connected signing
- Non-technical holders — Coldcard’s features are deep but expect engagement; a holder who doesn’t want to learn the device will not get the value
- Holders who care strongly about OSI-approved open-source firmware — the source-available licence is not fully open in the OSI sense; BitBox or Trezor is a better fit
Features and capabilities
Coldcard Q specifics (2026 flagship)
- Full QWERTY physical keyboard — the differentiating feature. Passphrase entry that previously required minutes of button-mashing on the Mk4 takes seconds on the Q.
- Colour display — sharper, more legible, better for verification of long addresses
- Camera — for scanning PSBT QR codes from the coordinator
- NFC — for tap-to-receive interaction with mobile coordinators (Nunchuk, others)
- MicroSD slot — for PSBT transfer via card (air-gap option)
- USB-C — for connected workflows, firmware update, file transfer
- Replaceable batteries — the Q operates on AA batteries, which the device sips from; battery life is months under typical use
Common to Coldcard line
- BIP-85 child-seed derivation — derive BIP-39 12/18/24-word children, WIF private keys, hex output, at user-selected indexes (0–9999 by default). The canonical BIP-85 implementation.
- PSBT v2 support — full Partially Signed Bitcoin Transaction handling
- BIP-380 output descriptors — modern descriptor format for multisig
- Native multisig — up to 15-of-15; vendor-diverse multisig friendly
- BIP-39 passphrase support — multiple passphrase wallets switchable on the device
- Dice-entropy contribution — user-provided dice rolls supplement the RNG at seed generation
- Bitcoin-only firmware — no altcoin support; reduces attack surface
- Secure element — ATECC608 family; physical-attack resistance
- Brick-me PIN — a special PIN that wipes the device immediately; option for coercion scenarios
Coldcard-specific quirks
- The trick PINs feature allows multiple PINs to map to different behaviours (decoy wallet, real wallet, brick-the-device) — a duress-response feature that requires careful planning to use safely
- The MicroSD-based firmware update is the only path; no over-the-network updates, which is structurally safer but operationally heavier than USB updates
- The dice-entropy contribution is a specific Coldcard feature that some holders value highly; others see it as a misplaced concern (the device’s hardware RNG is well-engineered)
Tradeoffs vs alternatives
| Dimension | Coldcard Q | Coldcard Mk4 | BitBox02 BTC-only | Foundation Passport | Trezor Safe 5 |
|---|---|---|---|---|---|
| Price | $249 | $150 | $137 | $199 | $129 |
| Bitcoin-only | Yes | Yes | Yes (BTC-only variant) | Yes | No (multi-coin) |
| Open-source firmware | Source-available | Source-available | Yes (OSI) | Yes (OSI) | Yes (OSI) |
| Secure element | Yes | Yes | Yes | Yes | Yes |
| Air-gap signing | QR + MicroSD | MicroSD only | No (USB only) | QR only | No (USB only) |
| Native SLIP-39 | No | No | No | No | Yes |
| BIP-85 | Excellent | Excellent | Good | Limited | Good |
| Passphrase entry | Best (QWERTY) | Tedious | Good (touch-input) | Good (touchscreen) | Excellent (touchscreen) |
| Multisig support | Excellent | Excellent | Excellent | Excellent | Good |
| Lopp 100-input signing (per 2024 report) | Fast | Fast | Fast | Fast | Moderate |
Compared to BitBox02: Coldcard is more feature-rich (BIP-85, air-gap MicroSD) but the BitBox02’s pure-USB workflow is simpler. Many holders run multi-vendor multisig with Coldcard + BitBox02 specifically for the complementary feature sets.
Compared to Foundation Passport: both target the air-gap-disciplined holder. Passport’s QR-only workflow is structurally cleaner; Coldcard’s MicroSD option provides a fallback path. Passport’s UX is more polished; Coldcard’s feature depth is greater.
Compared to Trezor: Coldcard is Bitcoin-only and more sovereignty-aligned; Trezor is multi-coin (which some holders see as an attack-surface increase) and has native SLIP-39 (which Coldcard does not).
Setup and operation
The setup flow (high-level):
- Verify packaging — Coldcards ship with a glued security bag and serial number printed on the bag. Verify the bag is intact and the serial matches the device.
- Initial boot — set a PIN. Coldcard’s PIN structure is unusual: a “prefix” then “remainder,” with the prefix producing a two-word anti-phishing phrase that helps verify the device hasn’t been tampered with.
- Generate seed — choose dice entropy or no dice; Coldcard generates 12 or 24 words. Record the seed by hand.
- Verify the seed — Coldcard offers a verification flow where it asks for specific words at specific positions.
- Optionally set up a passphrase — Coldcard supports BIP-39 passphrases; on the Q, entry is via QWERTY; on the Mk4, entry is via numeric keypad with letter cycling.
- Pair with a coordinator — Sparrow, Specter, Nunchuk, Casa, Unchained, Bitcoin Core. Pairing typically involves exporting an xpub or descriptor from the Coldcard.
The operational flow for signing:
- Coordinator builds the PSBT
- Transfer to Coldcard: via USB (cable), MicroSD (write file to card, insert), or QR code (Q only; scan with camera)
- Coldcard displays the transaction details; the holder verifies the destination address on the device screen
- Holder confirms; Coldcard signs internally
- Transfer signed PSBT back: same channel
- Coordinator finalizes and broadcasts
For multisig, the same flow but the PSBT visits multiple devices (one per required signature) before finalization.
The air-gap version: replace all USB transfers with MicroSD or QR. The device never connects to a network-connected machine.
Security considerations
Strengths
- Bitcoin-only firmware — reduces attack surface; no altcoin-related code paths
- Secure element — physical-attack resistance comparable to Ledger and Passport
- Source-available firmware — independent auditors can review the code
- Air-gap capability — for holders who use it, structurally narrower exposure window
- Trick PINs — when used carefully, provide duress-response options
- Brick-me PIN — option to wipe the device under coercion (with backups intact)
Known concerns
- The source-available licence — not OSI-approved; some open-source purists treat this as a meaningful gap from fully-open Trezor and BitBox02. The code is auditable in practice.
- Updates require MicroSD — slower than USB-based updates; some holders defer updates as a result. The discipline of staying current with firmware should be maintained.
- The “Recovery” history — Coldcard has had specific bugs over the years (one notable issue with how it handled certain edge cases in multisig signing); the team’s response track record is strong (rapid patching, transparent disclosure).
- Brand-loyalty community can be contentious — some Coldcard advocates push the device for use cases where it doesn’t fit. This is a community-vibe concern, not a device-security concern.
Supply-chain integrity
Buy directly from coldcard.com or authorized resellers. Coinkite is based in Toronto and ships globally. The glued security bag with printed serial is the canonical tamper-evident check.
The 2020 Ledger customer-data leak does not affect Coldcard; Coinkite’s customer database has not had a public leak. Coldcard purchasers are still on a smaller-than-Ledger but still-meaningful list; holders concerned about KYC-data correlation should consider shipping options.
Pricing and acquisition
As of 2026-07-15 (prices reverified; prior review 2026-05-14):
- Coldcard Q: $249 USD MSRP
- Coldcard Mk4: 170 as of 2026-07-15)
- Accessories: dice for entropy contribution, MicroSD cards, USB-C cables — all reasonable to source separately
Coldcard ships internationally. Some regulatory and customs friction depending on jurisdiction; the Coinkite team publishes current shipping policies.
Authorized channels: coldcard.com directly is the canonical purchase channel. Some authorized resellers exist (Bitcoin-focused retailers like Bitcoin Magazine store); these are vetted by Coinkite. Avoid eBay, Amazon, and other generic marketplaces — the supply-chain integrity guarantee is weaker through those channels.
Bulk and business pricing: Coinkite offers volume discounts for Coldcards used in multisig setups (typical 3-of-3 multisig holders).
Common pitfalls
Buying a Coldcard for a use case it doesn’t fit. Coldcard is overkill for casual single-sig holders. A Tier 1 holder who wants a hardware wallet may be better served by BitBox02 or Trezor for the simpler UX.
Skipping the security-bag verification. The bag check is fast and catches some categories of supply-chain attacks. Don’t skip it.
Forgetting the PIN structure. Coldcard’s prefix-and-remainder PIN scheme is unusual. Document the structure (not the PIN itself); a holder who forgets that there’s a prefix will be confused at recovery.
Misusing trick PINs. The trick-PIN feature enables decoy and duress responses. Used carelessly, the holder forgets which PIN does what and triggers an unintended wipe. Use cautiously and document carefully.
Treating BIP-85 children as more secure than the master. A BIP-85-derived child seed is exactly as secure as the master. Compromise of the Coldcard’s main seed compromises every BIP-85 child. See BIP-85 child seeds.
Avoiding firmware updates because the MicroSD process is friction. Firmware updates address real vulnerabilities. The MicroSD process is heavier than USB but is still tractable; don’t defer updates indefinitely.
Using the brick-me PIN as a routine response. It is a coercion-response option, not a daily security feature. Triggering it wipes the device; recovery requires the seed backup.
Three identical Coldcards in multisig. Defeats vendor diversity. The standard recommendation: Coldcard plus two different vendors for 2-of-3 multisig.
Tooling and resources
Coldcard documentation (as of 2026-05-14):
- coldcard.com — official site
- The Coldcard manual (downloadable PDF) — comprehensive operational reference
- Coinkite blog — release notes, security advisories, philosophical posts
- The “NVK on Twitter” account — Rodolfo Novak’s running commentary on the Bitcoin-and-self-custody scene
Coordinator software supporting Coldcard:
- Sparrow Wallet — desktop, excellent Coldcard support
- Specter Desktop — desktop, multisig-focused
- Nunchuk — desktop and mobile
- Bitcoin Core (with PSBT) — for the deeply technical
- Casa app, Unchained app — collaborative-custody coordinators that support Coldcard as one of several allowed hardware wallets
Community resources:
- The Coldcard subreddit and community forums — sometimes contentious, often informative
- Lopp’s writing — Coldcard receives substantive treatment in operational essays. See Jameson Lopp.
The synthesis document (canonical for the section):
- Bitcoin Self-Custody & Security: A Synthesis of Contemporary Best Practices, LegacyCipher discussion, April 2026 — Coldcard treated as a strong choice for power users.
As of 2026-07-15: the Coldcard Q has been available since late 2024; firmware is actively updated. The Mk4 has been succeeded by the Coldcard Mk5 (~$170), the current keypad-and-screen model. (Prior review 2026-05-14.)
Open questions for further development
- Coldcard’s source-available licence is treated as a legitimate middle position by some practitioners and as a meaningful gap by open-source purists. Should the framework take a stronger stance?
- The Coldcard Q’s QWERTY keyboard is a substantial UX advance for passphrase-heavy workflows. Will competitors adopt similar designs, and does this shift the device-selection calculus more broadly?
- Coinkite’s philosophical alignment (Bitcoin-only, sovereignty-focused) is part of the brand. Is this alignment doing real work for users, or is it primarily a marketing position?
Related notes
The framing context:
- Hardware wallets overview — the framework Coldcard is being evaluated against
- Self-custody configuration ladder — Coldcard fits well into Configurations 1, 2, 4, and 6
- Threat modeling for self-custody — Coldcard’s strengths align with specific threat profiles
Per-device alternatives:
- Trezor — native SLIP-39 alternative
- BitBox — fully-open-source alternative; common multisig pair
- Foundation Passport — strict-air-gap alternative
- Blockstream Jade — budget alternative
- Bitkey — non-technical alternative
- Ledger considerations and tradeoffs — the alternative with substantial caveats
Coldcard-relevant capabilities:
- BIP-85 child seeds — Coldcard is the canonical implementation
- PSBT and wallet descriptors — Coldcard’s PSBT and descriptor support is strong
- Passphrases and the 25th word — the Q’s QWERTY makes passphrases tractable
- Seed phrases and BIP-39 — Coldcard’s dice-entropy contribution
Custody configurations:
- Multisig setups — Coldcard as a multisig signing device
- Collaborative custody services — Coldcard support by Unchained, Casa, Nunchuk
Operational practice:
The principal practitioner:
The sub-MOC home: