Best Crypto Wallets
Top rated: Rabby 8.3
Software wallets for everyday use.
5rated →
Air-gapped signing over microSD, two secure elements and a Bitcoin-only scope — and, from March 2021 until the fixes of 31 July 2026, seed generation that used a weak software PRNG instead of the hardware random number generator. Attackers began sweeping those seeds on 30 July 2026 and took about 1,789 BTC (~$114.7m, Galaxy Research). Coinkite offers no compensation. If your seed was created on affected firmware without 50+ private dice rolls, make a new seed on updated firmware and move the funds now.
Best for: Air-gapped Bitcoin-only signing — only with a seed made on fixed firmware
4.0 is the weighted average of the five pillar findings below, minus one published deduction. We would not put our own funds here on the current evidence.
The storage design held: nobody extracted a key from a device. Key generation did not. A March 2021 build error made seed generation on Mk2/Mk3 firmware 4.0.1–4.1.9 and on Mk4, Mk5 and Q before 5.6.0 / 1.5.0Q use MicroPython’s Yasmarang PRNG; from 30 July 2026 attackers regenerated those seeds offline and swept about 1,789 BTC from 8,865 addresses (Galaxy Research; TRM Labs puts it near 1,816 BTC, $116m). The source was public for five years and nobody caught it. A firmware update does not repair an old seed.
Higher price than general-purpose devices. No ongoing cost.
Coinkite Inc. of Toronto, Canada, founded 2012. It published an advisory on 30 July 2026 and emergency firmware for every model on 31 July, but has offered no compensation, and its terms carry an arbitration clause. Victims’ claims were being discussed but no class action had been certified by 27 Sep 2026.
Reliable for its narrow purpose, Bitcoin only by design. The Mk4 has been superseded by the Mk5 (10 March 2026). Fixed releases: Mk4/Mk5 5.6.0+, Q 1.5.0Q+; Coinkite recommends 5.6.2 / 1.5.2Q (4 Sep 2026), which add a dice-roll verification tool.
The steepest learning curve of anything we rate. Documentation is thorough but assumes real competence, and there is no hand-holding.
Deductions applied
Strengths
Against it
Coldcard’s hardware did what it promised. It signs over microSD with no USB data path, keeps the seed behind two secure elements from different vendors, and no attacker extracted a key from a device. What failed was the step before storage. A build error in March 2021 made seed generation use MicroPython’s Yasmarang PRNG instead of the hardware random number generator, and nobody noticed for five years, although the source was public the whole time.
From 30 July 2026 attackers regenerated the weak seeds offline and swept the matching addresses. Galaxy Research counted 1,789.28 BTC (~$114.7m) from 8,865 addresses by 24 August; TRM Labs puts the total near 1,816 BTC ($116m). Coinkite, of Toronto, shipped fixed firmware for every model on 31 July and has offered no compensation. A white-hat group had moved 52.37 BTC into a Wyoming recovery trust by 22 September, under 3% of the loss. That is a user-fund loss with no one made whole, so the rating carries the fund-loss penalty and a much lower custody score.
If your seed was created on a Coldcard running firmware older than the fixed releases of 31 July 2026 — on any model from March 2021 onward — and you did not add at least 50 private dice rolls, treat it as exposed: update the firmware, generate a new seed on the updated device, test with a small amount, and move everything. Updating firmware does not repair an old seed.
Yes if the seed was generated on firmware released between March 2021 and the fixed releases of 31 July 2026, on a Mk2, Mk3, Mk4, Mk5 or Q, unless you mixed in at least 50 private dice rolls. Coinkite lists the exact affected and fixed versions for each model and track on coldcard.com/security/status. A strong BIP-39 passphrase put funds out of practical reach, but Coinkite still advises migrating. Seeds created on fixed firmware are not affected.
No compensation has been offered. As of 22 September 2026 white-hat operators had placed 52.37 BTC in a Wyoming trust with a claims process, and lawyers were discussing claims against Coinkite, whose terms contain an arbitration clause. No class action had been certified when we checked on 27 September 2026.
The air-gapped design and dual secure elements are still real protection against a compromised computer and a stolen device, and fixed firmware has shipped for every model. What the exploit showed is that storage security means little if key generation is weak, and that open code does not guarantee anyone has read it. If you buy one, update before creating a seed and add your own dice rolls; for an ordinary holder the BitBox02 or Trezor Safe 5 does the same job with far less to get wrong.
Assessed by
Blockchain Security Researcher · September 27, 2026
CoinRadar Daily is a non-commercial project. We have no commercial relationship with Coldcard Mk4, earn nothing from any link on this page, and carry no advertising or sponsorship anywhere on the site. Findings rest on public sources; we did not open an account or transact.
Rubric v2.0How we score →
Independent, rubric-scored tables for the services behind this story.
Top rated: Rabby 8.3
Software wallets for everyday use.
5rated →
Top rated: Kraken 8.4
Centralised venues that hold your funds while you trade.
6rated →
Top rated: Kraken Staking 8.0
Services that stake on your behalf.
5rated →