Coldcard Coldcard Q
A plan byColdcard
Coldcard, made by Canada's Coinkite, is the reference hardware wallet for Bitcoin-only holders: its firmware is Bitcoin-only and built for fully air-gapped use, signing transactions offline via microSD (or QR on the Q model) without ever plugging the device into a computer. It uses two secure elements from different vendors (Microchip ATECC608 and Maxim DS28C36B) to protect the seed. The current lineup includes the Coldcard Mk5 (≈€159, successor to the Mk4) and the Coldcard Q (≈€230) with a QWERTY keyboard, QR scanner and AAA batteries for fully offline operation. ⚠️ On 31 July 2026 an entropy flaw in the firmware (present since 4.0.0, March 2021) made device-generated seeds guessable: ~594 BTC drained from ~500 wallets. Coinkite has released fixed firmware, but seeds generated on vulnerable firmware must be replaced (see the Reputation block).
Coldcard Q
- Price
- €230
What's included
- Bitcoin-only
- Full QWERTY keyboard
- Built-in QR scanner
- Dual microSD slots
- AAA batteries (full air-gap)
Data & conditions
| Fund custody | Self-custody (funds in your control) |
|---|---|
| Type | Hardware (cold storage) |
| Source code | Partly open-source |
| Recovery | Seed phrase 12/24 parole (BIP-39); backup cifrato su microSD |
| Bitcoin-only | Yes |
| Supported chains | Bitcoin |
| Price | €159 |
| Secure element | Yes |
| Air-gapped | Yes |
| Connectivity | USB-C, NFC, microSD, QR |
| Companion app | Sparrow / Nunchuk / Electrum / Bitcoin Core (PSBT) |
| Built-in swap | No |
| Built-in staking | No |
| Segment | B2C |
| MiCA / License status | Nessuna (hardware wallet self-custody) |
Strengths
- Bitcoin-only with focused firmware; fully air-gapped use via microSD/QR; two secure elements from different vendors; Q model with QWERTY, QR scanner and AAA batteries.
- Self-custody: funds stay in your wallet — the platform cannot touch them.
- No KYC: usable without identity verification.
- Self-hostable: you can run your own instance or node.
Weaknesses
- Bitcoin-only (no multi-asset support); steep learning curve aimed at advanced users; Q priced above average; open-source firmware under a non-standard licence.
- July 2026: an entropy flaw in the firmware (since 4.0.0, March 2021) made device-generated seeds guessable — ~594 BTC (~$38M) stolen from ~500 wallets. Seeds generated on vulnerable firmware remain at risk even after updating.
- No notable sovereignty drawback documented.
Verdict
Score 3.6/5, solid profile. In its favour: bitcoin-only with focused firmware; fully air-gapped use via microSD/QR; two secure elements from different vendors; Q model with QWERTY, QR scanner and AAA batteries. The trade-off to weigh: bitcoin-only (no multi-asset support); steep learning curve aimed at advanced users; Q priced above average; open-source firmware under a non-standard licence.
On the Sovereignty lens the score is 4.3/5 (very strong): the strength is fund control (5.0/5), while trustless / auditability (2.5/5) is the weak link.
Promp's editorial rating based on real fees and net annual cost. Promp reviews third-party products independently.
"Sovereignty" rating: score computed on privacy/anonymity (30%), fund control (20%), censorship resistance (20%), trustless/auditability (20%) and costs (10%). Same data, different weights.
Reputation
What happened to people who used Coldcard, and what users say. External signals: they do not feed the promp.it rating.
Incidents & regulatory actions
Notable incidentsDocumented events with consequences still open. Each entry carries a source and a date.
-
Hack / funds theft Critical $89M ● open
≥1,367 BTC (~$89M) stolen from ~4,585 addresses due to an entropy flaw in seed generation — attack ongoing
Since firmware 4.0.0 (March 2021) seed generation skipped the hardware randomness generator and fell back to a predictable software PRNG: effective entropy ~40 bits on Mk2/Mk3 (fw 4.0.1–4.1.9), ~72 bits on Mk4/Mk5/Q. Coinkite advisory on 30 Jul 2026; first wave on 30 Jul drained ~1,082 BTC (~$70M) from ~1,196 addresses in ~41 minutes (early estimates: 594 BTC), followed by further waves: as of 2 Aug 2026, ≥1,367 BTC (~$89M) from ~4,585 addresses, attack still ongoing. Fixed firmware within ~24h (Mk3 4.2.0+, Mk4/Mk5 5.6.0+, Q 1.5.0Q+, Edge 6.6.0X/QX+), but updating does NOT repair existing seeds: anyone who generated their seed on-device must create a new one and migrate funds. Seeds from ≥50 dice rolls or imported elsewhere are unaffected; a BIP-39 passphrase lowers the risk. TAPSIGNER, OPENDIME and SATSCARD not affected. Stolen funds not recovered.
↗ source
verified on
FAQ
How much does a Coldcard cost?
The Coldcard Mk5 costs about €159 ($169.94 on Coinkite's official store), while the Coldcard Q, with QWERTY keyboard and QR scanner, costs about €230 ($249.21). Prices are in US dollars and orders ship from Canada: customs duties, VAT and clearance fees are the buyer's responsibility.
Does Coldcard support coins other than Bitcoin?
No: Coldcard is Bitcoin-only by design. The firmware is dedicated to Bitcoin alone to reduce the attack surface and stay focused on security.
Is Coldcard air-gapped?
Yes: it can run fully offline by signing transactions via microSD, or via QR on the Q model, without ever connecting to a computer. It also uses two secure elements from different vendors.
What happened in the July 2026 theft and what should I do?
On 31 July 2026 about 594 BTC (~$38 million) were drained from ~500 Coldcard wallets in 25 minutes. Cause: a build error introduced with firmware 4.0.0 (March 2021) skipped the hardware randomness generator, making seeds guessable — Mk3 (fw 4.0.1–4.1.9) most exposed, but Mk4, Mk5 and Q are affected too. If your seed was generated on the device with vulnerable firmware: update the firmware (Mk3 ≥4.2.0, Mk4/Mk5 ≥5.6.0, Q ≥1.5.0Q), generate a NEW seed and move funds there — updating alone does not repair existing seeds. Seeds created with ≥50 dice rolls are not affected.
Sources
- Official service page Coldcard Q · QR · QWERTY · Batterie · +4 Data verified on Jul 20, 2026
- blog.coinkite.com Mk5 sostituisce Mk4 · Secure element · Incidente entropia 2026 · Firmware corretti · +4 Data verified on Aug 2, 2026
- coindesk.com Importo furto · Numero wallet · Finestra temporale · Importo · +2 Data verified on Aug 2, 2026
- news.bitcoin.com Controversia email retention Data verified on Aug 2, 2026
Show 3 more sources
- coinkite.com Data verified on Jul 20, 2026
- github.com Data verified on Jul 20, 2026
- store.coinkite.com Prezzo usd · Modelli · Connettivita · Air gapped Data verified on Jul 20, 2026
Update history
- reputazione.incidenti Updated exploit figures: as of Aug 2, ≥1,367 BTC (~$89M) from ~4,585 addresses, attack ongoing (first estimate: 594 BTC). Noted the controversy over customer emails retained since 2019 despite a 90-day deletion promise (not a data breach).
- rating_editoriale 4.4 → 3.6 Rating cut after the seed exploit: the flaw sat at the core of the product's security promise.