# Coldcard

> Source: https://timechain.wiki/wiki/coldcard · TimechainWiki, the Bitcoin encyclopedia. (note · self-custody)

> Coldcard, made by Coinkite (Toronto), is the Bitcoin-only hardware wallet most associated with the power-user and sovereignty-focused end of the market. The flagship **Coldcard Q** ($249) adds a full QWERTY keyboard, colour screen, NFC, QR-code signing, and MicroSD — the strongest device for passphrase-heavy workflows and air-gapped multisig. The earlier **Coldcard Mk4** ($150; verify current — succeeded by the **Coldcard Mk5** at ~$170 as of 2026-07-15) remains the simpler keypad+MicroSD model. Distinctive features include native BIP-85 child-seed derivation (9,999-index convention), strong PSBT and descriptor support, dice-based entropy at setup, and full air-gap operation via MicroSD or QR. Firmware is source-available under a non-OSI public licence — auditable but not freely redistributable — placing Coldcard between fully-open vendors like BitBox and closed vendors like Ledger. Coldcard suits holders comfortable with a power-user UX who want strict air-gap discipline; it is overkill for casual single-sig holders better served by a simpler device.

---

## What this is

**Vendor**: Coinkite Inc. (Toronto, Canada). Founded by Rodolfo "NVK" Novak and Peter Gray (2014). Coinkite is among the longest-operating Bitcoin-only hardware-wallet vendors, with a sovereignty-and-Bitcoin-only philosophical stance that aligns with the strong-self-custody community.

**Product line as of 2026-07-15**:

- **Coldcard Q** ($249) — the flagship. Full QWERTY keyboard, colour display, USB-C, NFC, MicroSD slot, camera for QR-code signing. The first hardware wallet with a real keyboard, which transforms passphrase-entry ergonomics.
- **Coldcard Mk4** ($150; verify current) — the simpler keypad-and-screen device. Numeric keypad, monochrome display, USB-C, NFC, MicroSD. _As of 2026-07-15 the Mk4 has been succeeded by the **Coldcard Mk5** (~$170) — the same keypad+MicroSD form factor with an improved screen and buttons; the analysis on this page applies to both._ Still firmware-supported; the right choice for holders who don't need the Q's keyboard.
- **Coldcard Mk3** and earlier — discontinued but still firmware-supported. Existing holders need not upgrade urgently.

**Firmware**: Source-available under Coldcard's own licence (not OSI-approved but publicly readable and auditable). The reasoning the team has published: they want auditability without permitting clones built on their work. The synthesis treats this as a legitimate middle position between fully open-source (Trezor, BitBox02) and fully closed-source (Ledger).

**Secure element**: Coldcard uses a dual-chip architecture — a main microcontroller plus a secure element (specifically, ATECC608A or equivalent) for key storage. This provides physical-attack resistance comparable to Ledger and Foundation Passport.

---

## Who this is for

Coldcard is a strong fit for:

- **Multisig power users** — strong PSBT and descriptor support, vendor-diverse-multisig friendly, BIP-85 for derived multisig keys
- **Passphrase-heavy workflows** (Coldcard Q) — the full QWERTY keyboard makes entering complex passphrases tractable in a way no other hardware wallet matches
- **BIP-85 users** — Coldcard's BIP-85 implementation is the canonical one; 9,999-index searchable space; supports BIP-39 mnemonic derivation, WIF, and hex output
- **Air-gap-disciplined holders** — Coldcard works fully air-gapped via MicroSD (Mk4) or QR + MicroSD (Q); no USB connection needed for signing
- **Holders who want dice-entropy contribution** — Coldcard supports adding user-provided dice rolls to the seed-generation process, supplementing the device's RNG
- **Long-term holders comfortable with a power-user UX** — Coldcard is not aimed at first-time users; it rewards engagement with the device's features

Coldcard is **less appropriate** for:

- **First-time hardware-wallet users** — the UX is power-user oriented; the simpler keypad-and-screen Mk4 helps but Trezor or BitBox is gentler
- **Frequent spenders** — the air-gap workflow has more steps than USB-connected signing
- **Non-technical holders** — Coldcard's features are deep but expect engagement; a holder who doesn't want to learn the device will not get the value
- **Holders who care strongly about OSI-approved open-source firmware** — the source-available licence is not fully open in the OSI sense; BitBox or Trezor is a better fit

---

## Features and capabilities

### Coldcard Q specifics (2026 flagship)

- **Full QWERTY physical keyboard** — the differentiating feature. Passphrase entry that previously required minutes of button-mashing on the Mk4 takes seconds on the Q.
- **Colour display** — sharper, more legible, better for verification of long addresses
- **Camera** — for scanning PSBT QR codes from the coordinator
- **NFC** — for tap-to-receive interaction with mobile coordinators (Nunchuk, others)
- **MicroSD slot** — for PSBT transfer via card (air-gap option)
- **USB-C** — for connected workflows, firmware update, file transfer
- **Replaceable batteries** — the Q operates on AA batteries, which the device sips from; battery life is months under typical use

### Common to Coldcard line

- **BIP-85 child-seed derivation** — derive BIP-39 12/18/24-word children, WIF private keys, hex output, at user-selected indexes (0–9999 by default). The canonical BIP-85 implementation.
- **PSBT v2 support** — full Partially Signed Bitcoin Transaction handling
- **BIP-380 output descriptors** — modern descriptor format for multisig
- **Native multisig** — up to 15-of-15; vendor-diverse multisig friendly
- **BIP-39 passphrase support** — multiple passphrase wallets switchable on the device
- **Dice-entropy contribution** — user-provided dice rolls supplement the RNG at seed generation
- **Bitcoin-only firmware** — no altcoin support; reduces attack surface
- **Secure element** — ATECC608 family; physical-attack resistance
- **Brick-me PIN** — a special PIN that wipes the device immediately; option for coercion scenarios

### Coldcard-specific quirks

- The **trick PINs** feature allows multiple PINs to map to different behaviours (decoy wallet, real wallet, brick-the-device) — a duress-response feature that requires careful planning to use safely
- The **MicroSD-based firmware update** is the only path; no over-the-network updates, which is structurally safer but operationally heavier than USB updates
- The **dice-entropy contribution** is a specific Coldcard feature that some holders value highly; others see it as a misplaced concern (the device's hardware RNG is well-engineered)

---

## Tradeoffs vs alternatives

| Dimension | Coldcard Q | Coldcard Mk4 | BitBox02 BTC-only | Foundation Passport | Trezor Safe 5 |
|---|---|---|---|---|---|
| Price | $249 | $150 | $137 | $199 | $129 |
| Bitcoin-only | Yes | Yes | Yes (BTC-only variant) | Yes | No (multi-coin) |
| Open-source firmware | Source-available | Source-available | Yes (OSI) | Yes (OSI) | Yes (OSI) |
| Secure element | Yes | Yes | Yes | Yes | Yes |
| Air-gap signing | QR + MicroSD | MicroSD only | No (USB only) | QR only | No (USB only) |
| Native SLIP-39 | No | No | No | No | Yes |
| BIP-85 | Excellent | Excellent | Good | Limited | Good |
| Passphrase entry | Best (QWERTY) | Tedious | Good (touch-input) | Good (touchscreen) | Excellent (touchscreen) |
| Multisig support | Excellent | Excellent | Excellent | Excellent | Good |
| Lopp 100-input signing (per 2024 report) | Fast | Fast | Fast | Fast | Moderate |

Compared to BitBox02: Coldcard is more feature-rich (BIP-85, air-gap MicroSD) but the BitBox02's pure-USB workflow is simpler. Many holders run multi-vendor multisig with Coldcard + BitBox02 specifically for the complementary feature sets.

Compared to Foundation Passport: both target the air-gap-disciplined holder. Passport's QR-only workflow is structurally cleaner; Coldcard's MicroSD option provides a fallback path. Passport's UX is more polished; Coldcard's feature depth is greater.

Compared to Trezor: Coldcard is Bitcoin-only and more sovereignty-aligned; Trezor is multi-coin (which some holders see as an attack-surface increase) and has native SLIP-39 (which Coldcard does not).

---

## Setup and operation

The setup flow (high-level):

1. **Verify packaging** — Coldcards ship with a glued security bag and serial number printed on the bag. Verify the bag is intact and the serial matches the device.
2. **Initial boot** — set a PIN. Coldcard's PIN structure is unusual: a "prefix" then "remainder," with the prefix producing a two-word anti-phishing phrase that helps verify the device hasn't been tampered with.
3. **Generate seed** — choose dice entropy or no dice; Coldcard generates 12 or 24 words. Record the seed by hand.
4. **Verify the seed** — Coldcard offers a verification flow where it asks for specific words at specific positions.
5. **Optionally set up a passphrase** — Coldcard supports BIP-39 passphrases; on the Q, entry is via QWERTY; on the Mk4, entry is via numeric keypad with letter cycling.
6. **Pair with a coordinator** — Sparrow, Specter, Nunchuk, Casa, Unchained, Bitcoin Core. Pairing typically involves exporting an xpub or descriptor from the Coldcard.

The operational flow for signing:

- Coordinator builds the PSBT
- Transfer to Coldcard: via USB (cable), MicroSD (write file to card, insert), or QR code (Q only; scan with camera)
- Coldcard displays the transaction details; the holder verifies the destination address on the device screen
- Holder confirms; Coldcard signs internally
- Transfer signed PSBT back: same channel
- Coordinator finalizes and broadcasts

For multisig, the same flow but the PSBT visits multiple devices (one per required signature) before finalization.

The air-gap version: replace all USB transfers with MicroSD or QR. The device never connects to a network-connected machine.

---

## Security considerations

### Strengths

- **Bitcoin-only firmware** — reduces attack surface; no altcoin-related code paths
- **Secure element** — physical-attack resistance comparable to Ledger and Passport
- **Source-available firmware** — independent auditors can review the code
- **Air-gap capability** — for holders who use it, structurally narrower exposure window
- **Trick PINs** — when used carefully, provide duress-response options
- **Brick-me PIN** — option to wipe the device under coercion (with backups intact)

### Known concerns

- **The source-available licence** — not OSI-approved; some open-source purists treat this as a meaningful gap from fully-open Trezor and BitBox02. The code is auditable in practice.
- **Updates require MicroSD** — slower than USB-based updates; some holders defer updates as a result. The discipline of staying current with firmware should be maintained.
- **The "Recovery" history** — Coldcard has had specific bugs over the years (one notable issue with how it handled certain edge cases in multisig signing); the team's response track record is strong (rapid patching, transparent disclosure).
- **Brand-loyalty community can be contentious** — some Coldcard advocates push the device for use cases where it doesn't fit. This is a community-vibe concern, not a device-security concern.

### Supply-chain integrity

Buy directly from coldcard.com or authorized resellers. Coinkite is based in Toronto and ships globally. The glued security bag with printed serial is the canonical tamper-evident check.

The 2020 Ledger customer-data leak does not affect Coldcard; Coinkite's customer database has not had a public leak. Coldcard purchasers are still on a smaller-than-Ledger but still-meaningful list; holders concerned about KYC-data correlation should consider shipping options.

---

## Pricing and acquisition

_As of 2026-07-15 (prices reverified; prior review 2026-05-14)_:

- **Coldcard Q**: $249 USD MSRP
- **Coldcard Mk4**: $150 USD MSRP (verify current — succeeded by the **Coldcard Mk5** at ~$170 as of 2026-07-15)
- **Accessories**: dice for entropy contribution, MicroSD cards, USB-C cables — all reasonable to source separately

Coldcard ships internationally. Some regulatory and customs friction depending on jurisdiction; the Coinkite team publishes current shipping policies.

**Authorized channels**: coldcard.com directly is the canonical purchase channel. Some authorized resellers exist (Bitcoin-focused retailers like Bitcoin Magazine store); these are vetted by Coinkite. Avoid eBay, Amazon, and other generic marketplaces — the supply-chain integrity guarantee is weaker through those channels.

**Bulk and business pricing**: Coinkite offers volume discounts for Coldcards used in multisig setups (typical 3-of-3 multisig holders).

---

## Common pitfalls

**Buying a Coldcard for a use case it doesn't fit.** Coldcard is overkill for casual single-sig holders. A Tier 1 holder who wants a hardware wallet may be better served by BitBox02 or Trezor for the simpler UX.

**Skipping the security-bag verification.** The bag check is fast and catches some categories of supply-chain attacks. Don't skip it.

**Forgetting the PIN structure.** Coldcard's prefix-and-remainder PIN scheme is unusual. Document the structure (not the PIN itself); a holder who forgets that there's a prefix will be confused at recovery.

**Misusing trick PINs.** The trick-PIN feature enables decoy and duress responses. Used carelessly, the holder forgets which PIN does what and triggers an unintended wipe. Use cautiously and document carefully.

**Treating BIP-85 children as more secure than the master.** A BIP-85-derived child seed is exactly as secure as the master. Compromise of the Coldcard's main seed compromises every BIP-85 child. See [BIP-85 child seeds](https://timechain.wiki/wiki/bip-85-child-seeds.md).

**Avoiding firmware updates because the MicroSD process is friction.** Firmware updates address real vulnerabilities. The MicroSD process is heavier than USB but is still tractable; don't defer updates indefinitely.

**Using the brick-me PIN as a routine response.** It is a coercion-response option, not a daily security feature. Triggering it wipes the device; recovery requires the seed backup.

**Three identical Coldcards in multisig.** Defeats vendor diversity. The standard recommendation: Coldcard plus two different vendors for 2-of-3 multisig.

---

## Tooling and resources

**Coldcard documentation** _(as of 2026-05-14)_:

- coldcard.com — official site
- The Coldcard manual (downloadable PDF) — comprehensive operational reference
- Coinkite blog — release notes, security advisories, philosophical posts
- The "NVK on Twitter" account — Rodolfo Novak's running commentary on the Bitcoin-and-self-custody scene

**Coordinator software supporting Coldcard**:

- Sparrow Wallet — desktop, excellent Coldcard support
- Specter Desktop — desktop, multisig-focused
- Nunchuk — desktop and mobile
- Bitcoin Core (with PSBT) — for the deeply technical
- Casa app, Unchained app — collaborative-custody coordinators that support Coldcard as one of several allowed hardware wallets

**Community resources**:

- The Coldcard subreddit and community forums — sometimes contentious, often informative
- Lopp's writing — Coldcard receives substantive treatment in operational essays. See [Jameson Lopp](https://timechain.wiki/wiki/jameson-lopp.md).

**The synthesis document** (canonical for the section):

- *Bitcoin Self-Custody & Security: A Synthesis of Contemporary Best Practices*, LegacyCipher discussion, April 2026 — Coldcard treated as a strong choice for power users.

_As of 2026-07-15_: the Coldcard Q has been available since late 2024; firmware is actively updated. The Mk4 has been succeeded by the **Coldcard Mk5** (~$170), the current keypad-and-screen model. _(Prior review 2026-05-14.)_

---

## Open questions for further development

- Coldcard's source-available licence is treated as a legitimate middle position by some practitioners and as a meaningful gap by open-source purists. Should the framework take a stronger stance?
- The Coldcard Q's QWERTY keyboard is a substantial UX advance for passphrase-heavy workflows. Will competitors adopt similar designs, and does this shift the device-selection calculus more broadly?
- Coinkite's philosophical alignment (Bitcoin-only, sovereignty-focused) is part of the brand. Is this alignment doing real work for users, or is it primarily a marketing position?

---

## Related notes

**The framing context**:

- [Hardware wallets overview](https://timechain.wiki/wiki/hardware-wallets-overview.md) — the framework Coldcard is being evaluated against
- [Self-custody configuration ladder](https://timechain.wiki/wiki/self-custody-configuration-ladder.md) — Coldcard fits well into Configurations 1, 2, 4, and 6
- [Threat modeling for self-custody](https://timechain.wiki/wiki/threat-modeling-for-self-custody.md) — Coldcard's strengths align with specific threat profiles

**Per-device alternatives**:

- [Trezor](https://timechain.wiki/wiki/trezor.md) — native SLIP-39 alternative
- [BitBox](https://timechain.wiki/wiki/bitbox.md) — fully-open-source alternative; common multisig pair
- [Foundation Passport](https://timechain.wiki/wiki/foundation-passport.md) — strict-air-gap alternative
- [Blockstream Jade](https://timechain.wiki/wiki/blockstream-jade.md) — budget alternative
- [Bitkey](https://timechain.wiki/wiki/bitkey.md) — non-technical alternative
- [Ledger considerations and tradeoffs](https://timechain.wiki/wiki/ledger-considerations-and-tradeoffs.md) — the alternative with substantial caveats

**Coldcard-relevant capabilities**:

- [BIP-85 child seeds](https://timechain.wiki/wiki/bip-85-child-seeds.md) — Coldcard is the canonical implementation
- [PSBT and wallet descriptors](https://timechain.wiki/wiki/psbt-and-wallet-descriptors.md) — Coldcard's PSBT and descriptor support is strong
- [Passphrases and the 25th word](https://timechain.wiki/wiki/passphrases-and-the-25th-word.md) — the Q's QWERTY makes passphrases tractable
- [Seed phrases and BIP-39](https://timechain.wiki/wiki/seed-phrases-and-bip-39.md) — Coldcard's dice-entropy contribution

**Custody configurations**:

- [Multisig setups](https://timechain.wiki/wiki/multisig-setups.md) — Coldcard as a multisig signing device
- [Collaborative custody services](https://timechain.wiki/wiki/collaborative-custody-services.md) — Coldcard support by Unchained, Casa, Nunchuk

**Operational practice**:

- [Backup strategies for seeds](https://timechain.wiki/wiki/backup-strategies-for-seeds.md)
- [Recovery rehearsal practice](https://timechain.wiki/wiki/recovery-rehearsal-practice.md)
- [Common attack vectors](https://timechain.wiki/wiki/common-attack-vectors.md)

**The principal practitioner**:

- [Jameson Lopp](https://timechain.wiki/wiki/jameson-lopp.md)

**The sub-MOC home**:

- [Practical self-custody and sovereignty](https://timechain.wiki/wiki/practical-self-custody-and-sovereignty.md)
