How we reviewed this: from the manufacturer’s own documentation and published security research.
The most serious Bitcoin-only hardware wallet on the market, and the subject of the largest hardware wallet theft ever recorded. If you already own one, the section below matters more than the review.
By the CryptoNorth Team
A defect in Coldcard firmware from March 2021 onward made some device-generated seed phrases — the 12 or 24 recovery words that are the master key to a wallet — predictable enough to brute-force. Attackers began draining wallets on 30 July 2026, taking roughly 1,816 BTC (about $116 million USD) from more than 5,200 addresses, with later estimates above $130 million[4][5].
Affected: Mk2, Mk3, Mk4, Mk5 and Q. Not affected: TAPSIGNER, OPENDIME and SATSCARD.
Mk4 and Mk5: 5.6.0 or later (5.6.1 currently recommended), or Edge 6.6.0X. Mk2 and Mk3: 4.2.0 or later. Q: 1.5.0Q or Edge 6.6.0QX[1][2].
Updating the firmware does not repair an existing seed. It fixes future seed generation only. If your seed was created on affected firmware you need a brand new seed and a migration of your funds — follow Coinkite's official migration guide[3].
Coinkite's advisory treats a seed generated with at least 50 fair, independent, private dice rolls whose sequence was never recorded or exposed as the RNG exception[1][2]. A BIP-39 passphrase does not repair a bad seed; passphrase users should still migrate. If you are unsure you used 50+ private dice, assume you are affected and migrate.
The Coldcard is a Bitcoin-only hardware wallet built by Coinkite, a Toronto company, for people who treat key management as a discipline rather than a purchase. It has a numeric keypad, a small screen, and a design philosophy that assumes your computer is hostile.
Its signature feature is true air-gapped operation: you can set it up, sign transactions and move funds without ever connecting it to a computer, passing data by microSD card instead. Almost no other wallet at this price does that, and for anyone holding a serious amount of Bitcoin it is the reason to consider one.
Coinkite's store Mk4 category is empty; Mk5 has replaced it for new purchases at $189 at Coinkite. Mk4 remains supported. Buy only from Coinkite or an authorised reseller.
Firmware version 4.0.1, released in March 2021, contained a build configuration error. Instead of drawing randomness from the device's hardware entropy source when generating a seed, it fell back to a weak software random number generator. Effective key strength dropped from 128 bits to as little as 40 bits on older devices — low enough to brute-force with ordinary modern computing power[4].
Nobody noticed for over five years. The theft began on 30 July 2026 and ran in four waves. Because the attack works by regenerating the seed from scratch, the attacker never needed to touch the device, see it, or compromise the owner's computer. An air-gapped wallet in a safe was as exposed as one plugged into a laptop.
Coldcard's firmware is open source. Anyone could have read this code for five years, and the defect still went undetected until money started moving. Open source remains genuinely better than closed — it is why the flaw could be understood and fixed quickly once found — but “auditable” is not the same as “audited”. It is worth holding that thought next to the open-source argument for the Trezor Safe 3, which we make on that page and still believe.
Coinkite's response has been reasonable: an advisory published and updated within days, fixed firmware across every affected model, a dedicated migration guide, and a technical backgrounder explaining the failure[6]. That is roughly what you would want a manufacturer to do. It does not undo five years of bad seeds.
Setting the advisory aside, the Mk4 does something most wallets do not. You can run it having never once plugged it into a computer:
The device can be powered from a wall adapter rather than a computer, so no data connection need ever exist. It also supports genuinely serious operational features: a duress PIN that opens a decoy wallet, a brick PIN that permanently destroys the device, hidden passphrase wallets, and multisig setups that need several devices to approve a payment.
This is the toolkit of someone protecting a meaningful amount of Bitcoin against physical coercion, not someone storing $500 of savings. If those features sound like overkill for your situation, they are, and a simpler device will serve you better.
The Coldcard supports Bitcoin and nothing else. No Ethereum, no tokens, no altcoins, and no companion app that manages them. This is not a limitation Coinkite intends to fix.
The argument is that every additional chain adds code, and code is where flaws live. That argument is harder to make in August 2026 than it was in June, since the defect that cost users $116 million was in the Bitcoin seed generation itself. It remains a coherent philosophy. It is simply no longer an unanswerable one.
You hold a substantial amount of Bitcoin only, you want air-gapped signing and duress protections, and you are comfortable generating your seed with your own dice rolls rather than trusting any manufacturer's randomness. Mk4 is replaced by Mk5 ($189 at Coinkite) for new purchases; Mk4 remains supported. If you buy, update to 5.6.1 before generating anything, and use the dice.
You hold anything besides Bitcoin, you are new to self-custody, or you want a device you can set up without reading documentation. The Trezor Safe 3 and Ledger Nano S Plus are far gentler.
Do not buy a used Coldcard, and do not keep using a seed generated on affected firmware because the device has now been updated. Those are the two ways people are losing money right now.
We have kept the Coldcard listed rather than quietly removing it. A wallet that had a serious flaw, disclosed it, fixed it and documented the migration is more useful to you as a listed device with the full story attached than as an absence.
Assume yes unless the dice exception applies. Your seed is at risk if it was generated on firmware from 4.0.1 (March 2021) up to the fix, which for the Mk4 is version 5.6.0. Coinkite treats a seed generated with at least 50 fair, independent, private dice rolls that were never recorded as the RNG exception. A BIP-39 passphrase does not repair a bad seed; passphrase users should still migrate. If you are not sure you used 50+ private dice, treat the seed as compromised and migrate.
No, and this is the single most important point. Updating fixes how the device generates seeds in future. It does nothing to an existing seed, because that seed was already created with weak randomness and an attacker can regenerate it independently of your device. You need to create a brand new seed on updated firmware and move your funds to it. Coinkite publishes a step-by-step migration guide.
Mk2, Mk3, Mk4, Mk5 and Q. The TAPSIGNER, OPENDIME and SATSCARD products are not affected. Fixed versions are 4.2.0+ for Mk2 and Mk3, 5.6.0+ for Mk4 and Mk5 (5.6.1 is currently recommended), and 1.5.0Q for the Q. Some news coverage described this as an Mk3 issue, which understates it - Coinkite own advisory lists the Mk4 as affected too.
They never touched the wallet. Because the seed was generated with far too little randomness, the range of possible seeds was small enough to search by brute force. The attacker generated candidate seeds, derived their addresses, checked which held Bitcoin, and swept those. A device sitting unplugged in a safe was exactly as vulnerable as one in daily use, which is why physical security offered no protection here.
That is a judgement call and reasonable people differ. The failure was severe and lasted five years in code anybody could read. The response afterwards was solid: prompt disclosure, fixed firmware for every affected model, a migration guide and a public technical explanation. If you buy today, update to 5.6.1 first and generate your seed with your own dice rolls, which removes reliance on the manufacturer randomness that failed. If that process sounds like more than you want to take on, buy a simpler wallet instead.
This review is for informational purposes only and is not financial or security advice. The situation described is recent and still developing — figures for amounts stolen have risen since first reporting. Always confirm current firmware versions and guidance with Coinkite's official security status page rather than relying on any third party, including us.
Mk4 remains supported. For a new device, Coinkite now sells the Mk5 at $189 at Coinkite. Update to firmware 5.6.1 and generate your seed with dice before funding it.