Coldcard
Coldcard, made by Coinkite (Toronto), is the Bitcoin-only hardware wallet most associated with the power-user and sovereignty-focused end of the market. The flagship Coldcard Q ($249) adds a full QWERTY keyboard, colour screen, NFC, QR-code signing, and MicroSD — the strongest device for passphrase-heavy workflows and air-gapped multisig. The earlier Coldcard Mk4 ($150; verify current — succeeded by the Coldcard Mk5 at ~$170 as of 2026-07-15) remains the simpler keypad+MicroSD model. Distinctive features include native BIP-85 child-seed derivation (9,999-index convention), strong PSBT and descriptor support, dice-based entropy at setup, and full air-gap operation via MicroSD or QR. Firmware is source-available under a non-OSI public licence — auditable but not freely redistributable — placing Coldcard between fully-open vendors like BitBox and closed vendors like Ledger. Coldcard suits holders comfortable with a power-user UX who want strict air-gap discipline; it is overkill for casual single-sig holders better served by a simpler device.
What this is
Vendor: Coinkite Inc. (Toronto, Canada). Founded by Rodolfo “NVK” Novak and Peter Gray (2014). Coinkite is among the longest-operating Bitcoin-only hardware-wallet vendors, with a sovereignty-and-Bitcoin-only philosophical stance that aligns with the strong-self-custody community.
Product line as of 2026-07-15:
- Coldcard Q ($249) — the flagship. Full QWERTY keyboard, colour display, USB-C, NFC, MicroSD slot, camera for QR-code signing. The first hardware wallet with a real keyboard, which transforms passphrase-entry ergonomics.
- Coldcard Mk4 ($150; verify current) — the simpler keypad-and-screen device. Numeric keypad, monochrome display, USB-C, NFC, MicroSD. As of 2026-07-15 the Mk4 has been succeeded by the Coldcard Mk5 (~$170) — the same keypad+MicroSD form factor with an improved screen and buttons; the analysis on this page applies to both. Still firmware-supported; the right choice for holders who don’t need the Q’s keyboard.
- Coldcard Mk3 and earlier — discontinued but still firmware-supported. Existing holders need not upgrade urgently.
Firmware: Source-available under Coldcard’s own licence (not OSI-approved but publicly readable and auditable). The reasoning the team has published: they want auditability without permitting clones built on their work. The synthesis treats this as a legitimate middle position between fully open-source (Trezor, BitBox02) and fully closed-source (Ledger).
Secure element: Coldcard uses a dual-chip architecture — a main microcontroller plus a secure element (specifically, ATECC608A or equivalent) for key storage. This provides physical-attack resistance comparable to Ledger and Foundation Passport.
Who this is for
Coldcard is a strong fit for:
- Multisig power users — strong PSBT and descriptor support, vendor-diverse-multisig friendly, BIP-85 for derived multisig keys
- Passphrase-heavy workflows (Coldcard Q) — the full QWERTY keyboard makes entering complex passphrases tractable in a way no other hardware wallet matches
- BIP-85 users — Coldcard’s BIP-85 implementation is the canonical one; 9,999-index searchable space; supports BIP-39 mnemonic derivation, WIF, and hex output
- Air-gap-disciplined holders — Coldcard works fully air-gapped via MicroSD (Mk4) or QR + MicroSD (Q); no USB connection needed for signing
- Holders who want dice-entropy contribution — Coldcard supports adding user-provided dice rolls to the seed-generation process, supplementing the device’s RNG
- Long-term holders comfortable with a power-user UX — Coldcard is not aimed at first-time users; it rewards engagement with the device’s features
Coldcard is less appropriate for:
- First-time hardware-wallet users — the UX is power-user oriented; the simpler keypad-and-screen Mk4 helps but Trezor or BitBox is gentler
- Frequent spenders — the air-gap workflow has more steps than USB-connected signing
- Non-technical holders — Coldcard’s features are deep but expect engagement; a holder who doesn’t want to learn the device will not get the value
- Holders who care strongly about OSI-approved open-source firmware — the source-available licence is not fully open in the OSI sense; BitBox or Trezor is a better fit
Features and capabilities
Coldcard Q specifics (2026 flagship)
- Full QWERTY physical keyboard — the differentiating feature. Passphrase entry that previously required minutes of button-mashing on the Mk4 takes seconds on the Q.
- Colour display — sharper, more legible, better for verification of long addresses
- Camera — for scanning PSBT QR codes from the coordinator
- NFC — for tap-to-receive interaction with mobile coordinators (Nunchuk, others)
- MicroSD slot — for PSBT transfer via card (air-gap option)
- USB-C — for connected workflows, firmware update, file transfer
- Replaceable batteries — the Q operates on AA batteries, which the device sips from; battery life is months under typical use
Common to Coldcard line
- BIP-85 child-seed derivation — derive BIP-39 12/18/24-word children, WIF private keys, hex output, at user-selected indexes (0–9999 by default). The canonical BIP-85 implementation.
- PSBT v2 support — full Partially Signed Bitcoin Transaction handling
- BIP-380 output descriptors — modern descriptor format for multisig
- Native multisig — up to 15-of-15; vendor-diverse multisig friendly
- BIP-39 passphrase support — multiple passphrase wallets switchable on the device
- Dice-entropy contribution — user-provided dice rolls supplement the RNG at seed generation
- Bitcoin-only firmware — no altcoin support; reduces attack surface
- Secure element — ATECC608 family; physical-attack resistance
- Brick-me PIN — a special PIN that wipes the device immediately; option for coercion scenarios
Coldcard-specific quirks
- The trick PINs feature allows multiple PINs to map to different behaviours (decoy wallet, real wallet, brick-the-device) — a duress-response feature that requires careful planning to use safely
- The MicroSD-based firmware update is the only path; no over-the-network updates, which is structurally safer but operationally heavier than USB updates
- The dice-entropy contribution is a specific Coldcard feature that some holders value highly; others see it as a misplaced concern (the device’s hardware RNG is well-engineered)
Tradeoffs vs alternatives
| Dimension | Coldcard Q | Coldcard Mk4 | BitBox02 BTC-only | Foundation Passport | Trezor Safe 5 |
|---|---|---|---|---|---|
| Price | $249 | $150 | $137 | $199 | $129 |
| Bitcoin-only | Yes | Yes | Yes (BTC-only variant) | Yes | No (multi-coin) |
| Open-source firmware | Source-available | Source-available | Yes (OSI) | Yes (OSI) | Yes (OSI) |
| Secure element | Yes | Yes | Yes | Yes | Yes |
| Air-gap signing | QR + MicroSD | MicroSD only | No (USB only) | QR only | No (USB only) |
| Native SLIP-39 | No | No | No | No | Yes |
| BIP-85 | Excellent | Excellent | Good | Limited | Good |
| Passphrase entry | Best (QWERTY) | Tedious | Good (touch-input) | Good (touchscreen) | Excellent (touchscreen) |
| Multisig support | Excellent | Excellent | Excellent | Excellent | Good |
| Lopp 100-input signing (per 2024 report) | Fast | Fast | Fast | Fast | Moderate |
Compared to BitBox02: Coldcard is more feature-rich (BIP-85, air-gap MicroSD) but the BitBox02’s pure-USB workflow is simpler. Many holders run multi-vendor multisig with Coldcard + BitBox02 specifically for the complementary feature sets.
Compared to Foundation Passport: both target the air-gap-disciplined holder. Passport’s QR-only workflow is structurally cleaner; Coldcard’s MicroSD option provides a fallback path. Passport’s UX is more polished; Coldcard’s feature depth is greater.
Compared to Trezor: Coldcard is Bitcoin-only and more sovereignty-aligned; Trezor is multi-coin (which some holders see as an attack-surface increase) and has native SLIP-39 (which Coldcard does not).
Setup and operation
The setup flow (high-level):
- Verify packaging — Coldcards ship with a glued security bag and serial number printed on the bag. Verify the bag is intact and the serial matches the device.
- Initial boot — set a PIN. Coldcard’s PIN structure is unusual: a “prefix” then “remainder,” with the prefix producing a two-word anti-phishing phrase that helps verify the device hasn’t been tampered with.
- Generate seed — choose dice entropy or no dice; Coldcard generates 12 or 24 words. Record the seed by hand.
- Verify the seed — Coldcard offers a verification flow where it asks for specific words at specific positions.
- Optionally set up a passphrase — Coldcard supports BIP-39 passphrases; on the Q, entry is via QWERTY; on the Mk4, entry is via numeric keypad with letter cycling.
- Pair with a coordinator — Sparrow, Specter, Nunchuk, Casa, Unchained, Bitcoin Core. Pairing typically involves exporting an xpub or descriptor from the Coldcard.
The operational flow for signing:
- Coordinator builds the PSBT
- Transfer to Coldcard: via USB (cable), MicroSD (write file to card, insert), or QR code (Q only; scan with camera)
- Coldcard displays the transaction details; the holder verifies the destination address on the device screen
- Holder confirms; Coldcard signs internally
- Transfer signed PSBT back: same channel
- Coordinator finalizes and broadcasts
For multisig, the same flow but the PSBT visits multiple devices (one per required signature) before finalization.
The air-gap version: replace all USB transfers with MicroSD or QR. The device never connects to a network-connected machine.
Recovery — restoring the wallet on a fresh device
As of 2026-09-12, checked against Coinkite’s own documentation and security pages (linked inline). Two things frame every Coldcard recovery. There is no factory reset and no PIN recovery, ever: a Coldcard without its PIN is useless, and the written seed goes onto a fresh device instead. And since July 2026 there is a seed-generation incident to check before anything is moved: a seed created on a Coldcard running affected firmware is treated by the maker as compromised even after it is restored elsewhere, while a seed generated on another device and merely imported into a Coldcard is not affected.
What may be in hand
Three current models run two firmware lines: the Mk4 and Mk5 (a pocket-calculator shape with a 12-key number pad and sliding cover; the Mk5 has a better screen and keys, USB-C on the bottom, and runs the same firmware as the Mk4) and the Q (larger, a full QWERTY keyboard, a QR scanner under the screen, a battery door for three AAA cells). Mk4/Mk5 firmware is numbered like 5.6.2; Q firmware ends in Q, like 1.5.2Q. Older Mk2 and Mk3 units stopped at firmware 4.2.0, use micro-USB and cannot sign Taproot; a Mk1 bricks on any firmware newer than 3.0.6. Power: the Mk4/Mk5 has no battery and switches on the moment a USB-C cable brings power — a wall adapter is recommended over “smart” power banks, which may shut off because the device draws so little; the Q takes three AAA cells or USB-C and must be switched on by holding the top-left power key for a second. The green light on boot means the firmware verified; a red light means do not enter the PIN. The maker’s order of operations for any device is: set the PIN, then install the recommended firmware before choosing a seed or restore option, by copying the verified .dfu file to a MicroSD and running Advanced/Tools › Upgrade Firmware › From MicroSD. Sparrow refuses versions below the fixed releases.
The July 2026 incident. Coinkite’s security status page reports a firmware bug that weakened on-device seed generation; attackers regenerated the private keys offline and stole funds. Fixed releases are Mk4/Mk5 5.6.0 or later (5.6.2 recommended), Q 1.5.0Q or later (1.5.2Q), Mk2/Mk3 4.2.0. “An update is not a seed migration”: updating corrects future seed generation but does not repair a seed made earlier, and neither does a passphrase. The migration guide states that a seed generated elsewhere and imported is not weakened, that a seed generated on affected firmware stays affected when restored, imported or cloned, and that the fix is to generate a completely new seed on fixed firmware, verify its fingerprint and first address, send a test amount, then move the rest — never destroying the only working copy on the way. The one exception is a seed made with at least 50 private, unrecorded dice rolls. A recovery that cannot establish how the seed was made should follow the migration.
Unlocking a device that still holds the seed
The Main PIN has two parts — a prefix of two to six digits, then two anti-phishing words that depend on the prefix, then a suffix of two to six digits — written like 1234-5678. The words are a tamper check for someone who knows what they should be; a wrong prefix simply shows different words. A correct PIN gives the full main menu with the seed loaded: Ready To Sign, Passphrase, Address Explorer, Advanced/Tools and Settings, from which the wallet can be exported, addresses verified, a backup made, or the seed words viewed under Danger Zone. USB only appears to a computer after the PIN is entered.
After 13 failed attempts the device bricks itself, permanently, with a countdown shown after each failure — and the owner may have set the limit lower or added traps. Settings › Login Settings can hold Trick PINs (a PIN that bricks, wipes silently, opens a decoy duress wallet, makes the device “Look Blank”, or enters a Delta Mode that produces wrong signatures), an Add If Wrong rule that wipes or bricks after a chosen number of failures, a Kill Key that wipes the seed if pressed during login, MicroSD 2FA that wipes the seed if the right card is not inserted at login, a Login Countdown of up to 48 hours, scrambled keypads, and on the Q a Calculator Login that hides the PIN prompt behind a working calculator. A Single Signer Spending Policy may hide the Settings, backup and firmware menus until a policy PIN is entered. Because none of this is visible from outside, the operational rule is never to guess: use the written PIN, confirm the fingerprint under Advanced/Tools › View Identity against the holder’s records (a decoy wallet has a different one), and if anything is uncertain restore the seed onto a fresh device instead. Coinkite’s own words on a lost PIN: “there is ABSOLUTELY NO WAY to reset the PIN or factory reset”.
Wiping the device
There is no factory reset. With the PIN known, Advanced/Tools › Danger Zone › Seed Functions › Destroy Seed erases the seed and resets the wallet after an “Are you SURE?!?” screen; the PIN itself survives and can be changed afterwards. On older firmware, Wipe LFS and Delete All under Trick PINs finish the job; newer firmware does that during seed destruction. Nuke Device, further down the same menu, permanently bricks the hardware and must not be used. A Coldcard that already holds a different seed need not be wiped at all to look at an inherited one: Advanced/Tools › Temporary Seed › Import Words loads it into RAM for the session, shows its fingerprint as the first menu item, and forgets it at power-off.
Restoring from the backup
Restore needs an empty Coldcard — new, or with the seed destroyed — whose main menu reads New Seed Words / Import Existing / Migrate Coldcard. Import Existing offers 12, 18 or 24 words (English BIP-39 only), Scan QR Code on the Q, Restore Backup, Clone Coldcard, Import XPRV, Tapsigner Backup and Seed XOR; there is no SLIP-39 option. Entry differs by model. On the Mk4/Mk5, each word is chosen letter by letter with the 5 and 8 keys scrolling a shrinking list — to enter keen, pick k-, then kee-, then keen — with X to back up; the last word is offered from the checksum-valid choices, so an invalid phrase is largely prevented by design. On the Q, the keyboard types with autocomplete, and QR scans a SeedQR (not a Compact SeedQR). Pressing ✔ on the final word applies the seed to the secure element permanently. The maker’s advice is to allow time and not rush the 24 words.
Coinkite’s own backup format is backup.7z, an AES-256 archive protected by a separate random 12-word password unrelated to the seed. Import Existing › Restore Backup picks the file from the MicroSD, asks for those 12 words (the Q can scan them), then shows the backup’s master fingerprint for comparison before applying — restoring the seed and its settings, multisig configurations and Seed Vault, but never the PIN and never a passphrase. The file also opens in any 7-Zip tool with the twelve lowercase words joined by single spaces. A backup made while a passphrase wallet was active holds that wallet’s private key, not the parent words. Clone Coldcard copies a live, unlocked Coldcard onto an empty one by shuttling a MicroSD, and is explicitly not a fix for the 2026 incident. Seeds from Ledger, Trezor and other devices import the same way; a migration brings no PIN, passphrase, custom paths or altcoin accounts with it.
The passphrase
The main-menu item Passphrase applies a BIP-39 passphrase after login, entered on the device: on the Mk4/Mk5 through a menu of Edit Phrase (keys 1–4 switch letters, numbers, symbols and case), Add Word (a BIP-39 word) and Add Numbers, then APPLY; on the Q straight into the keyboard, or from a QR. Up to 100 ASCII characters, case-sensitive, no accented letters. The device shows an eight-character extended fingerprint (XFP) when the passphrase is applied, and that is the only proof of the right wallet — there is no validation, a wrong passphrase opens a different empty wallet, and a PSBT signed under the wrong passphrase fails with an error that names the correct XFP. The passphrase is never stored on the device and lasts until Secure Logout or power-off; an owner may have saved it encrypted to a specific MicroSD card, recalled with Passphrase › Restore Saved, so a card found with the device deserves a look. Apply the passphrase before opening Address Explorer or exporting a wallet, or the wrong addresses appear. An owner who used Lock Down Seed has converted the device to the passphrase wallet’s key alone; the Passphrase menu is then gone and the original words are not on the device. Since the incident the maker recommends a passphrase for any meaningful balance, so a wallet set up after mid-2026 is more likely than before to have one.
Connecting to Sparrow and confirming the first address
The maker-preferred route is air-gapped: Advanced/Tools › Export Wallet › Sparrow Wallet writes a JSON file (single-sig or multisig) to the MicroSD, the Virtual Disk, NFC, or as a BBQr code on the Q; press 1 at the confirmation to choose an account number other than zero. In Sparrow, File › New Wallet › Airgapped Hardware Wallet › Coldcard › Import File (or Scan for the Q’s BBQr) › Apply. Sparrow’s guide still shows older menu labels and the Generic JSON export named coldcard-export.json; the current firmware path is the one above. USB also works as a Connected Hardware Wallet if the owner did not switch the USB port off under Settings › Hardware On/Off, and the device is only visible after its PIN. No companion app or driver exists; Linux may want Sparrow’s udev rules.
Address check: Address Explorer on the main menu (press 4 past the warning) lists the first address for each type — Classic P2PKH, P2SH-Segwit and Segwit P2WPKH, the last being the bc1 address at m/84'/0'/0'/0/0 the maker calls the first choice today — then the first ten of the chosen type, with 0 for change addresses, and Account Number and Custom Path for other paths. Pick the type whose first address Sparrow shows; an unfamiliar list means a mistyped passphrase or a different path. The Q can also scan an address QR and verify ownership, and both models can verify over NFC, searching the first 764 receive and change addresses. Multisig addresses are partly masked on the device by default.
Multisig
Settings › Multisig Wallets › Import loads a configuration from the MicroSD, Virtual Disk, QR (Q) or NFC, in Coldcard-export or BIP-380 descriptor form, and shows the details for approval; one key must carry this Coldcard’s own fingerprint. The Trust PSBT? setting can offer an import from a signing request instead. The device’s cosigner key for a coordinator comes from Export XPUB (a file named ccxp-<XFP>.json) or the Sparrow Wallet export. Configurations survive in the encrypted backup, not in the seed words. See Multisig setups and PSBT and wallet descriptors.
Security considerations
Strengths
- Bitcoin-only firmware — reduces attack surface; no altcoin-related code paths
- Secure element — physical-attack resistance comparable to Ledger and Passport
- Source-available firmware — independent auditors can review the code
- Air-gap capability — for holders who use it, structurally narrower exposure window
- Trick PINs — when used carefully, provide duress-response options
- Brick-me PIN — option to wipe the device under coercion (with backups intact)
Known concerns
- The source-available licence — not OSI-approved; some open-source purists treat this as a meaningful gap from fully-open Trezor and BitBox02. The code is auditable in practice.
- Updates require MicroSD — slower than USB-based updates; some holders defer updates as a result. The discipline of staying current with firmware should be maintained.
- The July 2026 seed-generation incident — a firmware bug weakened on-device seed generation; attackers regenerated keys offline and stole funds. Coinkite’s security status page sets the fixed releases (Mk4/Mk5 5.6.0+, Q 1.5.0Q+, Mk2/Mk3 4.2.0) and states that updating does not repair a seed generated earlier; its migration guide asks holders of such seeds to generate a new one on fixed firmware and move the funds. Seeds generated elsewhere and imported are not affected. The disclosure and guidance were prompt and specific; the incident is nonetheless the most serious in the product’s history and bears on any seed created on a Coldcard before the fix.
- The “Recovery” history — Coldcard has had specific bugs over the years (one notable issue with how it handled certain edge cases in multisig signing); the team’s response track record is strong (rapid patching, transparent disclosure).
- Brand-loyalty community can be contentious — some Coldcard advocates push the device for use cases where it doesn’t fit. This is a community-vibe concern, not a device-security concern.
Supply-chain integrity
Buy directly from coldcard.com or authorized resellers. Coinkite is based in Toronto and ships globally. The glued security bag with printed serial is the canonical tamper-evident check.
The 2020 Ledger customer-data leak does not affect Coldcard; Coinkite’s customer database has not had a public leak. Coldcard purchasers are still on a smaller-than-Ledger but still-meaningful list; holders concerned about KYC-data correlation should consider shipping options.
Pricing and acquisition
As of 2026-07-15 (prices reverified; prior review 2026-05-14):
- Coldcard Q: $249 USD MSRP
- Coldcard Mk4: $150 USD MSRP (verify current — succeeded by the Coldcard Mk5 at ~$170 as of 2026-07-15)
- Accessories: dice for entropy contribution, MicroSD cards, USB-C cables — all reasonable to source separately
Coldcard ships internationally. Some regulatory and customs friction depending on jurisdiction; the Coinkite team publishes current shipping policies.
Authorized channels: coldcard.com directly is the canonical purchase channel. Some authorized resellers exist (Bitcoin-focused retailers like Bitcoin Magazine store); these are vetted by Coinkite. Avoid eBay, Amazon, and other generic marketplaces — the supply-chain integrity guarantee is weaker through those channels.
Bulk and business pricing: Coinkite offers volume discounts for Coldcards used in multisig setups (typical 3-of-3 multisig holders).
Common pitfalls
Buying a Coldcard for a use case it doesn’t fit. Coldcard is overkill for casual single-sig holders. A Tier 1 holder who wants a hardware wallet may be better served by BitBox02 or Trezor for the simpler UX.
Skipping the security-bag verification. The bag check is fast and catches some categories of supply-chain attacks. Don’t skip it.
Forgetting the PIN structure. Coldcard’s prefix-and-remainder PIN scheme is unusual. Document the structure (not the PIN itself); a holder who forgets that there’s a prefix will be confused at recovery.
Misusing trick PINs. The trick-PIN feature enables decoy and duress responses. Used carelessly, the holder forgets which PIN does what and triggers an unintended wipe. Use cautiously and document carefully.
Treating BIP-85 children as more secure than the master. A BIP-85-derived child seed is exactly as secure as the master. Compromise of the Coldcard’s main seed compromises every BIP-85 child. See BIP-85 child seeds.
Avoiding firmware updates because the MicroSD process is friction. Firmware updates address real vulnerabilities. The MicroSD process is heavier than USB but is still tractable; don’t defer updates indefinitely.
Using the brick-me PIN as a routine response. It is a coercion-response option, not a daily security feature. Triggering it wipes the device; recovery requires the seed backup.
Three identical Coldcards in multisig. Defeats vendor diversity. The standard recommendation: Coldcard plus two different vendors for 2-of-3 multisig.
Tooling and resources
Coldcard documentation (as of 2026-05-14):
- coldcard.com — official site
- The Coldcard manual (downloadable PDF) — comprehensive operational reference
- Coinkite blog — release notes, security advisories, philosophical posts
- The “NVK on Twitter” account — Rodolfo Novak’s running commentary on the Bitcoin-and-self-custody scene
Coordinator software supporting Coldcard:
- Sparrow Wallet — desktop, excellent Coldcard support
- Specter Desktop — desktop, multisig-focused
- Nunchuk — desktop and mobile
- Bitcoin Core (with PSBT) — for the deeply technical
- Casa app, Unchained app — collaborative-custody coordinators that support Coldcard as one of several allowed hardware wallets
Community resources:
- The Coldcard subreddit and community forums — sometimes contentious, often informative
- Lopp’s writing — Coldcard receives substantive treatment in operational essays. See Jameson Lopp.
The synthesis document (canonical for the section):
- Bitcoin Self-Custody & Security: A Synthesis of Contemporary Best Practices, LegacyCipher discussion, April 2026 — Coldcard treated as a strong choice for power users.
As of 2026-07-15: the Coldcard Q has been available since late 2024; firmware is actively updated. The Mk4 has been succeeded by the Coldcard Mk5 (~$170), the current keypad-and-screen model. (Prior review 2026-05-14.)
Open questions for further development
- Coldcard’s source-available licence is treated as a legitimate middle position by some practitioners and as a meaningful gap by open-source purists. Should the framework take a stronger stance?
- The Coldcard Q’s QWERTY keyboard is a substantial UX advance for passphrase-heavy workflows. Will competitors adopt similar designs, and does this shift the device-selection calculus more broadly?
- Coinkite’s philosophical alignment (Bitcoin-only, sovereignty-focused) is part of the brand. Is this alignment doing real work for users, or is it primarily a marketing position?
Related notes
The framing context:
- Hardware wallets overview — the framework Coldcard is being evaluated against
- Self-custody configuration ladder — Coldcard fits well into Configurations 1, 2, 4, and 6
- Threat modeling for self-custody — Coldcard’s strengths align with specific threat profiles
Per-device alternatives:
- Trezor — native SLIP-39 alternative
- BitBox — fully-open-source alternative; common multisig pair
- Foundation Passport — strict-air-gap alternative
- Blockstream Jade — budget alternative
- Bitkey — non-technical alternative
- Ledger considerations and tradeoffs — the alternative with substantial caveats
Coldcard-relevant capabilities:
- BIP-85 child seeds — Coldcard is the canonical implementation
- PSBT and wallet descriptors — Coldcard’s PSBT and descriptor support is strong
- Passphrases and the 25th word — the Q’s QWERTY makes passphrases tractable
- Seed phrases and BIP-39 — Coldcard’s dice-entropy contribution
Custody configurations:
- Multisig setups — Coldcard as a multisig signing device
- Collaborative custody services — Coldcard support by Unchained, Casa, Nunchuk
Operational practice:
The principal practitioner:
The sub-MOC home: