Costs, licensing, consumer protection Privacy, self-custody, censorship resistance

Coldcard

Coinkite Inc.

3.6/5 4.3/5
Custody Self-custody

Data verified on last change the sources

Worth it if you're an advanced bitcoiner wanting fully air-gapped self-custody: two secure elements from different suppliers and Bitcoin-only firmware, with the Q model adding a QWERTY keyboard and QR scanner.

Avoid it if you hold assets other than Bitcoin, or generated a seed on vulnerable firmware: the July 2026 entropy flaw made those seeds guessable, with ~594 BTC stolen.

Coldcard, made by Canada's Coinkite, is the reference hardware wallet for Bitcoin-only holders: its firmware is Bitcoin-only and built for fully air-gapped use, signing transactions offline via microSD (or QR on the Q model) without ever plugging the device into a computer. It uses two secure elements from different vendors (Microchip ATECC608 and Maxim DS28C36B) to protect the seed. The current lineup includes the Coldcard Mk5 (≈€159, successor to the Mk4) and the Coldcard Q (≈€230) with a QWERTY keyboard, QR scanner and AAA batteries for fully offline operation. ⚠️ On 31 July 2026 an entropy flaw in the firmware (present since 4.0.0, March 2021) made device-generated seeds guessable: ~594 BTC drained from ~500 wallets. Coinkite has released fixed firmware, but seeds generated on vulnerable firmware must be replaced (see the Reputation block).

RISK: Critical incident ongoing (advisory 30 Jul 2026): firmware entropy flaw since 2021, ≥1,367 BTC (~$89M) stolen as of 2 Aug 2026 with the attack still active. Seeds generated on-device with vulnerable firmware must be REPLACED (new seed + fund migration): updating firmware is not enough. Coinkite also admitted retaining customer emails since 2019, contradicting its promise to delete them after 90 days.
65
Transparency: Medium
65/100 · see methodology
65
Data exposure: Medium
65/100 · lower is better for sovereignty · methodology

Data & conditions

Fund custody Self-custody (funds in your control)
Type Hardware (cold storage)
Source code Partly open-source
Recovery Seed phrase 12/24 parole (BIP-39); backup cifrato su microSD
Bitcoin-only Yes
Supported chains Bitcoin
Price €159
Secure element Yes
Air-gapped Yes
Connectivity USB-C, NFC, microSD, QR
Companion app Sparrow / Nunchuk / Electrum / Bitcoin Core (PSBT)
Built-in swap No
Built-in staking No
Segment B2C
MiCA / License status Nessuna (hardware wallet self-custody)

Plans & pricing

Strengths

  • Bitcoin-only with focused firmware; fully air-gapped use via microSD/QR; two secure elements from different vendors; Q model with QWERTY, QR scanner and AAA batteries.
  • Self-custody: funds stay in your wallet — the platform cannot touch them.
  • No KYC: usable without identity verification.
  • Self-hostable: you can run your own instance or node.

Weaknesses

  • Bitcoin-only (no multi-asset support); steep learning curve aimed at advanced users; Q priced above average; open-source firmware under a non-standard licence.
  • July 2026: an entropy flaw in the firmware (since 4.0.0, March 2021) made device-generated seeds guessable — ~594 BTC (~$38M) stolen from ~500 wallets. Seeds generated on vulnerable firmware remain at risk even after updating.
  • No notable sovereignty drawback documented.

Verdict

B A ★ 3.6/5 ★ 4.3/5

Score 3.6/5, solid profile. In its favour: bitcoin-only with focused firmware; fully air-gapped use via microSD/QR; two secure elements from different vendors; Q model with QWERTY, QR scanner and AAA batteries. The trade-off to weigh: bitcoin-only (no multi-asset support); steep learning curve aimed at advanced users; Q priced above average; open-source firmware under a non-standard licence.

On the Sovereignty lens the score is 4.3/5 (very strong): the strength is fund control (5.0/5), while trustless / auditability (2.5/5) is the weak link.

Privacy & anonymity 30% 4.8
Fund control 20% 5.0
Censorship resistance 20% 4.8
Trustless / auditability 20% 2.5

Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.

"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.

Reputation

What happened to people who used Coldcard, and what users say. External signals: they do not feed the promp.it rating.

Incidents & regulatory actions

Notable incidents

Documented events with consequences still open. Each entry carries a source and a date.

  1. Hack / funds theft Critical $115M ● open

    ~1,789 BTC (~$115M) stolen from 8,865 addresses due to an entropy flaw in seed generation

    Since firmware 4.0.0 (March 2021) seed generation skipped the hardware randomness generator and fell back to a predictable software PRNG: effective entropy ~40 bits on Mk2/Mk3 (fw 4.0.1–4.1.9), ~72 bits on Mk4/Mk5/Q. Keys were derivable remotely, with no physical access to the device. Coinkite advisory on 30 Jul 2026 (last updated 1 Aug). The first wave on 30 Jul drained ~1,082 BTC (~$70M) from ~1,196 addresses in ~41 minutes; further waves followed, four in total. Figures grew at each check: ~$89M from ~4,585 addresses as of 2 Aug, then ~1,816 BTC (~$116M) from over 5,200 addresses per TRM Labs' 5 Aug analysis, which warns they should be treated as preliminary (funds still moving, victims may surface for months); some outlets reported higher estimates, up to ~$130M. It is the largest hardware-wallet theft of 2026. Fixed firmware shipped within ~24h (Mk3 4.2.0+, Mk4/Mk5 5.6.0+, Q 1.5.0Q+, Edge 6.6.0X/QX+), but updating does NOT repair existing seeds: anyone who generated their seed on-device must create a new one and migrate funds. Seeds from ≥50 dice rolls or imported elsewhere are unaffected; a BIP-39 passphrase lowers the risk. TAPSIGNER, OPENDIME and SATSCARD not affected. No recovery of stolen funds and no reimbursement plan announced. As of 3 Sep 2026 Galaxy Research's consolidated tally attributes 1,789.28 BTC to the flaw (~$114.7M at the value when stolen) across 8,865 addresses: slightly fewer BTC but nearly twice the addresses of TRM's 5 Aug estimate, meaning the pool of victims widened. On 2 Sep 2026 the third-wave attacker moved funds for the first time, converting roughly 10% of that wave's haul into ETH through the cross-chain DEX THORChain (announced by Alex Thorn, Galaxy Research, at 01:46 on 3 Sep): these are the first bitcoin to leave the original addresses of any of the three waves Galaxy tracks. About 90% of the third wave is still untouched, some swaps failed and were retried, and Galaxy shared the new Ethereum address with law enforcement and with firms monitoring the stolen funds. On 31 Aug 2026 at 20:57 UTC a honeypot wallet from the public cktripwire.com monitoring project was also swept, one carrying 12.9 bits of added entropy — five dice rolls (TXID 276e8f16732cbcdc02b0ca2e8fa9427ae7fbce053f3c784142c9fe2ed30ed887, verifiable onchain): a direct measurement of how far the attacker's key grinding reaches, confirming that a handful of dice rolls is not enough; as of the same date, honeypots with 16 or more bits of added entropy remain untouched.

    ↗ source

verified on

Public reviews

2.4/5 35 reviews
  • Trustpilot ↗ 2.4/5 35 reviews

    Read from uk.trustpilot.com (the .com returns 403): 2.4 over 35 reviews. Coinkite profile (maker of Coldcard): measures the company, not the individual device. Coldcard has no companion mobile app (used with third-party wallets such as Sparrow/Electrum).

Weighted average across 1 public review platform (35 reviews in total), weighted by volume. This is not our rating: it is those platforms’ average.

FAQ

How much does a Coldcard cost?

The Coldcard Mk5 costs about €159 ($169.94 on Coinkite's official store), while the Coldcard Q, with QWERTY keyboard and QR scanner, costs about €230 ($249.21). Prices are in US dollars and orders ship from Canada: customs duties, VAT and clearance fees are the buyer's responsibility.

Does Coldcard support coins other than Bitcoin?

No: Coldcard is Bitcoin-only by design. The firmware is dedicated to Bitcoin alone to reduce the attack surface and stay focused on security.

Is Coldcard air-gapped?

Yes: it can run fully offline by signing transactions via microSD, or via QR on the Q model, without ever connecting to a computer. It also uses two secure elements from different vendors.

What happened in the July 2026 theft and what should I do?

On 31 July 2026 about 594 BTC (~$38 million) were drained from ~500 Coldcard wallets in 25 minutes. Cause: a build error introduced with firmware 4.0.0 (March 2021) skipped the hardware randomness generator, making seeds guessable — Mk3 (fw 4.0.1–4.1.9) most exposed, but Mk4, Mk5 and Q are affected too. If your seed was generated on the device with vulnerable firmware: update the firmware (Mk3 ≥4.2.0, Mk4/Mk5 ≥5.6.0, Q ≥1.5.0Q), generate a NEW seed and move funds there — updating alone does not repair existing seeds. Seeds created with ≥50 dice rolls are not affected.

Sources

Show 3 more sources

Update history

  1. reputazione.incidenti Updated exploit figures: as of Aug 2, ≥1,367 BTC (~$89M) from ~4,585 addresses, attack ongoing (first estimate: 594 BTC). Noted the controversy over customer emails retained since 2019 despite a 90-day deletion promise (not a data breach).
  2. rating_editoriale 4.4 → 3.6 Rating cut after the seed exploit: the flaw sat at the core of the product's security promise.

🔔 Notify me of changes

← Back to Hardware Wallets