Bitcoin-only hardware wallet by Coinkite. Air-gapped via PSBT-on-SD. Reference signer for Bitcoin maxis.
Best evidence tier. Signup tested end-to-end by xmr.club curator — deposit + withdrawal + edge cases. No-KYC posture verified at retail volume. Last_verified within 12 months.
Full rubric + 7-step verification walkthrough at /methodology.
ColdCard is Coinkite's Bitcoin-only hardware wallet, built for users who treat their signing device as a hostile-environment appliance: dual secure elements, a true air-gap option, and a long list of anti-coercion features that assume someone may eventually point a wrench at you.
Background Made in Canada by Coinkite, ColdCard (current models Mk4 and the keyboard-equipped Q) has earned a reputation as the signer of choice for security-maximalist Bitcoiners. The firmware is source-available and the device is designed so that it can be used entirely offline, passing signed transactions via microSD card or QR rather than ever touching a computer's USB stack if you prefer.
What you trust You trust two independent secure-element chips (a defense-in-depth design so a break in one does not expose the seed), the source-available firmware, and Coinkite's track record. The air-gap modes let you minimize trust in your connected machine entirely — PSBTs move on a microSD card or, on the Q, by QR.
Operational specs Bitcoin-only. Dual secure elements; PIN with anti-phishing words that prove the device hasn't been swapped; optional "duress" PINs that open a decoy wallet, and a "brick-me" PIN that destroys the secure element. Trick PINs, BIP39 passphrases, and multisig are all supported. The Q model adds a full keyboard, larger screen, and built-in QR scanner; the Mk4 favors microSD and NFC. Fully functional in a permanently air-gapped workflow with Sparrow, Electrum, and others.
Philosophy ColdCard's design philosophy is adversarial: assume the supply chain, the connected computer, and even the physical custody of the device may be compromised, and engineer countermeasures for each. The duress and brick-me PINs are an explicit acknowledgment that the threat is sometimes a person, not just malware.
Grade rationale Grade A. A mature, defense-in-depth signer with genuine air-gap capability and the deepest anti-coercion feature set in the category. The Bitcoin-only scope and the source-available (rather than fully free) firmware license are the only marks against an otherwise exemplary security posture.
Useful when You hold meaningful Bitcoin and want a battle-tested, air-gappable signer; you need duress/decoy features for plausible deniability; you are building multisig and want a coordinator-agnostic device; you prefer microSD/QR transfer over USB trust.
Caveats Bitcoin-only — not a Monero device. Firmware is source-available, not fully open-source/free, which some purists weigh against it. The breadth of security features has a learning curve; misconfigured duress or passphrase setups can lock you out as effectively as an attacker. Buy only from Coinkite or authorized resellers to limit supply-chain risk.
$120 hardware · Bitcoin-only · PSBT-via-SD
Sourced from operator pages — verify identity via more than one channel before trusting time-sensitive instructions.
.onion mirror listed 2026-05-13 (<90d) No community reviews yet. Be the first below.
Honest, brand-neutral feedback welcome. A curator approves before it appears here. No JS required.
Silence censorship. Protect your privacy and bypass restrictions with Xeovo VPN. No email required.
Long-running no-KYC aggregator. XMR-friendly, Tor mirror, broad coin support.
Mobile + desktop multi-coin wallet (XMR, BTC, LTC, ETH) with in-app swap + CakePay.
Non-custodial cross-chain swap router with refund-on-refusal AML policy and multi-destination split swaps. No
Two-year-old no-account instant swap — in-house test swap settled in 3 minutes (0–1 conf), Trocador A privacy