
Hardware wallet maker
Coldcard
2012 · Canadacoldcard.com ↗
Also known as Coinkite, Coinkite Inc., COLDCARD Mk4, COLDCARD Mk5, COLDCARD Q, NVK
coldcard
Coldcard is a Bitcoin-only hardware wallet line (Mk4, Mk5 and Q) made by Coinkite, a Toronto company, designed for air-gapped signing over microSD or NFC. In July 2026 attackers began draining wallets whose seeds had been generated on firmware released since March 2021, because a build error had made those seeds far less random than intended; Galaxy Research counted about 1,789 BTC stolen by late August.
Our read
Coldcard was built for Bitcoin holders who want no USB data path, multi-vendor secure elements and features like duress PINs, and the hardware still delivers that. The 2026 entropy bug is the thing to weigh: it was a software mistake that sat unnoticed for five years in open code, and it cost owners around $114m. If you hold a Coldcard seed created before the July 2026 fixes, move the funds to a new seed; if you are choosing a device, look at how any maker generates randomness, not just how it stores keys.
Key facts
- Current models
- Mk5 (launched 10 March 2026), Q (QWERTY, colour screen, QR scanner); Mk4 superseded by Mk5
- Mar 2026 · Coinkite ↗
- 2026 seed-entropy exploit
- 1,789.28 BTC (~$114.7m) across 8,865 addresses, Galaxy Research high-confidence count
- Aug 2026 · The Crypto Times ↗
- Fixed firmware
- Mk2/Mk3 4.2.0+, Mk4/Mk5 5.6.0+, Q 1.5.0Q+, Edge 6.6.0X / 6.6.0QX+; recommended 5.6.2 and 1.5.2Q
- Sep 2026 · Coinkite ↗
- Other products
- Tapsigner, Satscard, Opendime, Seedplate, Blockclock (not affected by the 2026 bug)
- Jul 2026 · Coinkite ↗
What happened in the 2026 Coldcard hack
Nobody broke into a Coldcard. What failed was the randomness used to create seeds. In March 2021 Coinkite moved seed generation to a new library, libNgU. The build flag meant to switch off MicroPython's software random generator did not take effect at link time, so seed generation called Yasmarang, a general-purpose PRNG seeded from fixed values, instead of the hardware random number generator the design required. Nobody caught it for five years.
The effect depended on the model. On Mk2 and Mk3 running firmware 4.0.1 to 4.1.9, seeds were weak enough to brute-force: TRM Labs estimates as little as 40 bits instead of 128. On Mk4, Mk5 and Q before the fixed releases Coinkite puts effective strength at about 72 bits, still well short of the target. An attacker only needed to regenerate candidate seeds offline and check which addresses held coins.
| Date (2026) | Event |
|---|---|
| 30 July | First wave: about 1,083 BTC taken from 1,196 addresses in 41 minutes. Coinkite publishes its advisory the same day |
| 31 July | Second wave, about 594 BTC in 25 minutes. Emergency firmware ships for every model |
| 1–4 August | Two more waves; Coinkite tells owners to "migrate your funds"; small amounts start moving through Wasabi and Tornado Cash |
| 24 August | Galaxy Research's high-confidence tally: 1,789.28 BTC (~$114.7m) from 8,865 addresses |
| 4 September | Firmware 5.6.2 / 1.5.2Q adds a tool to verify dice-roll mixing |
| 21 September | White-hat operators move 52.37 BTC into a Wyoming trust for verified victims to claim |
Seeds created with at least 50 private dice rolls were not exposed, because the dice added independent randomness. A strong BIP-39 passphrase also put funds out of practical reach, though Coinkite still advises migrating. Updating firmware does not repair an old seed: a new one has to be generated on fixed firmware and the coins moved.
- 01Check which firmware created your seed and whether you added 50+ private dice rolls when you made it.
- 02Update the Coldcard to the fixed release for your model and track (Standard or Edge) before creating anything new.
- 03Generate a new seed on the updated device, back it up, and verify the wallet fingerprint and a receive address.
- 04Send a small test transaction, then move the rest; keep the old backup until the move is confirmed.
Coinkite has not offered compensation. Its terms contain an arbitration clause, lawyers in Canada and investors including 117 Partners have discussed product-liability and class claims, and at least one Brazilian victim filed a police complaint. No class action had been certified when we checked.
Coldcard Mk4, Mk5 and Q
Coinkite announced the first Coldcard in December 2017 with a pitch that still describes the line: Bitcoin only, a numeric keypad, a real security chip, and microSD so transactions can move between computer and device without any cable. Later models kept that and added NFC.
| Model | Announced | What changed |
|---|---|---|
| Mk1 to Mk3 | 2017–2019 | Single secure element, microSD, micro-USB. Mk2/Mk3 seeds from firmware 4.0.1–4.1.9 are affected by the 2026 bug |
| Mk4 | Jan 2022 | Two secure elements from different vendors, USB-C, NFC, no transaction-size limit |
| Q | Feb 2023 (reservations) | Full QWERTY keyboard, colour screen, QR scanner, two microSD slots, battery option |
| Mk5 | Mar 2026 | Mk4 security core, 1.54" Gorilla Glass display, new keypad, faster NFC, colours |
The Mk4 design stores the seed in one secure element and encrypts it with a key that needs the second secure element and the main processor as well. When Ledger's Donjon lab glitched the second chip with a laser in 2023, it reached about half of that chip's memory slots but not the seed. Features like a duress PIN that opens a decoy wallet, a "brick me" PIN and trick PINs are part of why security-focused buyers pick Coldcard.
Our scored review covers the Mk4: Coldcard review.
Coinkite, the company behind Coldcard
Coinkite Inc. was set up in Toronto in 2012 by Rodolfo Novak, known as NVK, and began as a bitcoin payments and multisig web wallet before moving to hardware. Besides Coldcard it sells Opendime (a USB bearer stick), Satscard and Tapsigner (NFC cards), Seedplate steel backups and the Blockclock display. Those products run separate code and were not affected by the 2026 bug.
Coinkite publishes Coldcard firmware source on GitHub and ships signed releases in two tracks: Standard, and Edge for newer features. That openness is also how the flaw became visible to anyone looking at the right commit; it took an exploitation wave for it to be found. Since August 2026 Coinkite has said every applicable firmware release should be treated as critical.
Incident log
1 entry · $115M lost in total · repaid, confirmed: 0 of 1 where user funds were at stake
Exploit$115M
Weak seed generation exploited across Coldcard wallets
A March 2021 build error made Coldcard seed generation use MicroPython's Yasmarang PRNG instead of the hardware RNG. Seeds from Mk2/Mk3 firmware 4.0.1–4.1.9 and from Mk4, Mk5 and Q firmware before 5.6.0 / 1.5.0Q were guessable offline. From 30 July 2026 attackers regenerated keys and swept wallets in several waves; Galaxy Research's high-confidence count was 1,789.28 BTC (~$114.7m) from 8,865 addresses by 24 August. TRM Labs put the total near 1,816 BTC ($116m). Seeds with 50+ dice rolls were unaffected.
Not repaidCoinkite has offered no compensation. As of 22 September 2026 white-hat operators had moved 52.37 BTC (about 2.8% of the loss) into a Wyoming recovery trust with a claims process; no payouts to victims had been confirmed.
In our ratings
This page is the record. The scores sit on the review cards, next to the evidence and the weights they came from.
Compare Coldcard with
BitBoxHardware wallet maker · 2015 · SwitzerlandZurich-based Shift Crypto makes the BitBox02 and BitBox02 Nova hardware wallets: open-source firmware, microSD backup, Bitcoin-only and multi-coin editions.
TrezorHardware wallet maker · 2013 · Czech RepublicPrague maker of the first consumer bitcoin hardware wallet (2014), now the Safe 3, 5 and 7. Open-source firmware; part of the SatoshiLabs group.
KeystoneHardware wallet maker · 2018 · Hong KongHong Kong maker of the Keystone 3 Pro, an air-gapped hardware wallet that signs over QR codes and uses three secure chips. Formerly sold as Cobo Vault.
LedgerHardware wallet maker · 2014 · FranceParis-based maker of the Nano, Flex and Stax hardware wallets and the Ledger Wallet app. Closed-source firmware; customer data leaked in 2020 and 2026.
Frequently asked questions
Is my Coldcard affected by the 2026 vulnerability?+
If the seed was generated on a Mk2 or Mk3 with firmware 4.0.1–4.1.9, or on a Mk4, Mk5 or Q before firmware 5.6.0 / 1.5.0Q, treat it as exposed unless you added at least 50 private dice rolls. Update the firmware, create a new seed and move the coins; the update alone does not fix the old seed.
Was the Coldcard device itself hacked?+
No. Attackers never touched the devices. They exploited predictable seeds offline, rebuilding private keys from the weak random numbers the buggy firmware had used.
Will Coinkite reimburse victims?+
Coinkite has not offered compensation. A white-hat group has placed 52.37 BTC in a Wyoming trust for verified victims, and lawyers are exploring claims against the company.
Who owns Coldcard?+
Coinkite Inc., a Toronto company founded in 2012 by Rodolfo Novak (NVK).
Coldcard vs Trezor or Ledger?+
Coldcard is Bitcoin-only and built around air-gapped use; Trezor and Ledger are multi-coin. How they score side by side is in our [hardware wallet ratings](/ratings/hardware-wallets).
What changed
- Profile published.
Compiled by
Blockchain Security Researcher · September 27, 2026
We have no commercial relationship with Coldcard and earn nothing from any link on this page. Every fact above carries the date it was true and a link to where it comes from; if one is out of date, the contact page reaches the editor who keeps this file.