xmr.club
EN 中文 ES RU
★ FRONT-PAGEASageSwap— Anonymous swap — no KYC, no AML hold, no IP logging, declines law-enforcement requests.→
/wallets · verified 2026-09-16

Coldcard

D

Bitcoin-only hardware wallet by Coinkite. Air-gapped via PSBT-on-SD. Reference signer for Bitcoin maxis.

Maintainer: Coinkite / NVK

Incident timeline

  1. 2026-07-30 First sweep — ~594 BTC (~$38M) drained from ~500 Coldcard-secured wallets into a single consolidation address within ~25 minutes.
  2. 2026-08-03 Further waves over four days; Galaxy Research tally reaches ~1,816 BTC (~$116M) across 5,200+ addresses.
  3. 2026-08-04 Coinkite publishes a security advisory, halts Coldcard shipments, destroys affected-firmware inventory, and directly contacts shipped-order customers. Root cause: a March-2021 firmware integration error (software PRNG instead of the STM32 hardware RNG).
  4. 2026-09-16 xmr.club downgrades Coldcard A → D and posts this incident; prior grade rested on verification that predated the exploit (last checked 2026-05-13).
  5. 2026-09-25auto On 21 Sep 2026 Galaxy Research and Alex Thorn reported that white-hat operators consolidated Coldcard-exploit coins into a Crypto Recovery Trust address in block 967948, with an OP_RETURN pointing victims to cryptorecoverytrust.com. Thorn put the traced amount at 52.37 BTC, about 2.8% of tracked losses and roughly 4…

At a glance

Grade
D ()
KYC posture
light kyc
Fees
$120 hardware · Bitcoin-only · PSBT-via-SD
Last verified
2026-09-16
Operating since
2017 · 9y — Coinkite (parent) founded 2012; Coldcard hardware wallet product launched ~2017-2018. Domain WHOIS 2003 is premium-domain.
Incident
⚠ Active since 2026-07-30 — /incidents
D Why grade D?

Listed for completeness or as a warning. Either KYC posture is questionable at scale, the provider has known unresolved issues, or the listing exists to anchor a comparison.

Full rubric + 7-step verification walkthrough at /methodology.

curator verdict · bottom line

Curator Verdict & OpSec Breakdown

THE BOTTOM LINE

Coldcard carries significant OpSec reservations, unverified compliance claims, or unresolved incident flags. It is not recommended for critical privacy workflows.

✓

Proven Strengths

  • ▸ Non-custodial architecture: user retains full custody of private keys throughout execution.
  • ▸ Open-source codebase: public code repositories allow independent verification and audit.
  • ▸ Established operational track record: serving users continuously since 2017 (9 years).
⚠

OpSec Trade-offs & Caveats

  • ▸ ACTIVE INCIDENT (2026-07-30): A March-2021 Coldcard firmware bug routed seed generation to a software pseudo-random number generator instead of the STM32 hardware RNG, weakening entropy on affected devices to as little as 40 bits (from 128). An attacker who reconstructed the formula derived private keys remotely — no physical access needed — sweeping ~594 BTC (~$38M) from ~500 wallets in the first 25 minutes, growing to ~1,816 BTC (~$116M) across 5,200+ addresses over four days (Galaxy Research tally). It is the largest hardware-wallet exploit of 2026.
  • ▸ Heuristic KYC triggers: transactions or accounts may be frozen for ID review if flagged by automated risk rules.
  • ▸ Clearnet-only footprint: lacks an official .onion hidden service mirror; exposes visitor network IP unless routed through VPN/Tor.

Review

⚠ CRITICAL — Coldcard firmware seed-entropy exploit (July 2026). A March-2021 firmware bug generated some seeds with a software PRNG instead of the hardware RNG, cutting key strength to as low as 40 bits and letting an attacker derive private keys remotely, without touching the device — ~1,816 BTC (~$116M) swept from 5,200+ addresses. Grade cut A → D. If you use a Coldcard, verify firmware against Coinkite's advisory and migrate funds to a seed made on known-good hardware. See the incident timeline below.

ColdCard is Coinkite's Bitcoin-only hardware wallet, built for users who treat their signing device as a hostile-environment appliance: dual secure elements, a true air-gap option, and a long list of anti-coercion features that assume someone may eventually point a wrench at you.

Background Made in Canada by Coinkite, ColdCard (current models Mk4 and the keyboard-equipped Q) has earned a reputation as the signer of choice for security-maximalist Bitcoiners. The firmware is source-available and the device is designed so that it can be used entirely offline, passing signed transactions via microSD card or QR rather than ever touching a computer's USB stack if you prefer.

What you trust You trust two independent secure-element chips (a defense-in-depth design so a break in one does not expose the seed), the source-available firmware, and Coinkite's track record. The air-gap modes let you minimize trust in your connected machine entirely — PSBTs move on a microSD card or, on the Q, by QR.

Operational specs Bitcoin-only. Dual secure elements; PIN with anti-phishing words that prove the device hasn't been swapped; optional "duress" PINs that open a decoy wallet, and a "brick-me" PIN that destroys the secure element. Trick PINs, BIP39 passphrases, and multisig are all supported. The Q model adds a full keyboard, larger screen, and built-in QR scanner; the Mk4 favors microSD and NFC. Fully functional in a permanently air-gapped workflow with Sparrow, Electrum, and others.

Philosophy ColdCard's design philosophy is adversarial: assume the supply chain, the connected computer, and even the physical custody of the device may be compromised, and engineer countermeasures for each. The duress and brick-me PINs are an explicit acknowledgment that the threat is sometimes a person, not just malware.

Grade rationale Grade A. A mature, defense-in-depth signer with genuine air-gap capability and the deepest anti-coercion feature set in the category. The Bitcoin-only scope and the source-available (rather than fully free) firmware license are the only marks against an otherwise exemplary security posture.

Useful when You hold meaningful Bitcoin and want a battle-tested, air-gappable signer; you need duress/decoy features for plausible deniability; you are building multisig and want a coordinator-agnostic device; you prefer microSD/QR transfer over USB trust.

Caveats Bitcoin-only — not a Monero device. Firmware is source-available, not fully open-source/free, which some purists weigh against it. The breadth of security features has a learning curve; misconfigured duress or passphrase setups can lock you out as effectively as an attacker. Buy only from Coinkite or authorized resellers to limit supply-chain risk.

Fees

$120 hardware · Bitcoin-only · PSBT-via-SD

Links

Sourced from operator pages — verify identity via more than one channel before trusting time-sensitive instructions.

Audit trail — receipts for the editorial claim

  • ● UPSTREAM Up · HTTP 200 · 882ms · checked 3h ago
  • ○ ONION No .onion mirror listed
  • ✎ MANUAL Last manual verification 2026-09-16 (<30d)

Reviews — moderated · rules

No community reviews yet. Be the first below.

Add a review

Honest, brand-neutral feedback welcome. A curator approves before it appears here. No JS required.

Required: review body. Honest, descriptive reviews get approved within a day. Marketing copy, slurs, or invective get rejected. Per-day cap of 5 submissions per IP.