Coldcard Q: what the sources say
Current 5 disclosed weaknesses 3 company incidents
The questions, with sources
"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.
Five facts
- The Coldcard Q is listed in stock on Coinkite's official store on 2026-10-11 with two unlabeled prices, $369 and $319 [source 4].
- It has a 2.3-inch colour LCD, a QWERTY keyboard, a QR scanner, NFC, USB-C and two microSD slots, and uses the same two secure elements as the Mk4 per Coinkite [source 16].
- Firmware is published with reproducible builds (Q1 makefile) under MIT plus the Commons Clause, not an OSI license [source 11][source 12].
- Coinkite's advisory of 2026-07-30 says Q seeds generated on firmware before 1.5.0Q used a weaker software RNG; press reports roughly 1,400 to 1,600 BTC stolen across Coldcard models [source 5][source 7][source 8].
- Updating firmware does not fix seeds already generated on affected firmware; Coinkite advises migrating them [source 5].
Audits
- No independent audit found in our search.
Publicly disclosed weaknesses
- 2026-07-30 Seed-generation flaw: since a March 2021 library migration (firmware 4.0.1 onward) the seed path used a software PRNG instead of the hardware TRNG, reducing seed search space. Coinkite states Mk4/Mk5/Q seeds had about 72 bits of effective entropy (design target 128) and that attackers exploited this offline to regenerate keys and steal funds. Affected: Mk4/Mk5 before 5.6.0, Q before 1.5.0Q. Coinkite's advisory (30 Jul 2026), analysis by Block and Galaxy Research cited by press. Updating fixes generation of new seeds only; seeds created on affected firmware must be migrated. Funds lost: yes. Mitigated source
- 2025-09 Delta PIN private-key recovery from two signatures (coordinated disclosure, Mk4/Mk5 and Q families; Coinkite says full matrix not published). Patched in 5.4.4 / 1.3.4Q per Coinkite. Funds lost: not verified. Fixed source
- 2026-07 Legacy input-amount spoofing (credited fix), Mk4/Mk5 before 5.5.1 and Q before 1.4.1Q; fixed per Coinkite. Funds lost: not verified. Fixed source
- 2026-08 Staged-PSBT transaction substitution when signing over USB with PSRAM-staged PSBTs (credited fix), before 5.6.1 / 1.5.1Q; plus several input-validation, callgate and SIGHASH_SINGLE hardening reports (Aug 2026). Fixed in 5.6.1 and 1.5.1Q per Coinkite; Coinkite notes its 30-entry list is a chronology, not a count of independent vulnerabilities. Funds lost: not verified. Fixed source
- 2023-09 DS28C36 (the second secure element used in Mk4) double-laser readout, coordinated disclosure; Coinkite describes partial exposure and no full seed recovery. Page lists it under Mk4 SE2; the Q uses the same secure elements per Coinkite. Funds lost: no. Fix status not verified source
Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.
Incidents at the maker or its service providers
- 2026-07-30 Theft of bitcoin from wallets with seeds generated on affected Coldcard firmware (see vulnerability above). Privacy Guides reports about 1,400 BTC (c. $70M at the time) in the first days; Decrypt, citing Galaxy Research, reports 1,596 BTC high-confidence losses across three waves as of 4 Aug 2026; Optech reported over 1,000 BTC. Figures vary by source and date. Coinkite says the devices were not hacked or remotely accessed. Customer funds lost: yes. Outcome: Fixed firmware released; Coinkite advises migrating any seed created on affected firmware. Totals still developing at time of sources. source
- 2026-08 Phishing campaigns impersonating Coinkite/Coldcard ('coordinated hardware audit') delivered a batch file installing the remote-access tool ScreenConnect (reported by Proofpoint via Decrypt on 3 Aug 2026; analysed by PhishFort, 18 Aug 2026). Campaign did not ask for seed phrases per PhishFort. Customer funds lost: not verified. Outcome: Third-party warnings; sources do not state funds lost from this campaign. source
- 2026-08 Criticism that Coinkite emailed some customers despite stating it deletes customer data after 90 days; Coinkite reportedly responded that Canadian law requires keeping business records for eight years (as reported by Privacy Guides). Customer funds lost: no. Outcome: Reported controversy over data retention; no breach reported in the source. source
These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.
Questions about Coldcard Q
Is Coldcard Q safe?
We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 5 publicly disclosed weaknesses and 3 company incidents in our search. Read the sources above before you buy.
Does Coldcard Q need an internet connection?
Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB, QR. The companion app or software that builds the transaction is online.
Who found the weaknesses listed for Coldcard Q?
The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.
Where this comes from
- [1] COLDCARD Mk4 product page (coldcard.com) accessed 2026-10-11
- [2] Mk4 compared to Mk3 (coldcard.com docs) accessed 2026-10-11
- [3] Coinkite store: hardware category accessed 2026-10-11
- [4] Coinkite store: COLDCARD Mk5 and Q listings accessed 2026-10-11
- [5] Coinkite: Security disclosure history accessed 2026-10-11
- [6] Bitcoin Optech Newsletter 2026-07-31 accessed 2026-10-11
- [7] Privacy Guides: Nearly 1,400 Bitcoin hacked from Coldcard wallets accessed 2026-10-11
- [8] Decrypt: Hardware wallet firms warn of phishing surge as Coldcard losses near $130M accessed 2026-10-11
- [9] PhishFort: How attackers weaponized the Coldcard entropy incident accessed 2026-10-11
- [10] Coinkite blog: Coldcard Mk5 launch accessed 2026-10-11
- [11] Coldcard firmware repository README (GitHub) accessed 2026-10-11
- [12] Coinkite about page (coldcard.com) accessed 2026-10-11
- [13] Coinkite blog: Understanding the Mk4 security model accessed 2026-10-11
- [14] Coinkite responsible disclosure / bug bounty accessed 2026-10-11
- [15] Coldcard docs: Other features and tools accessed 2026-10-11
- [16] Coldcard Q overview (coldcard.com docs) accessed 2026-10-11
- [17] Coinkite newsletter: Meet the COLDCARD Q1 accessed 2026-10-11
Not verified: Not verified: whether a Bluetooth radio is absent (not stated by maker); passkeys/FIDO support (not mentioned in docs read); SLIP39/Shamir (only Seed XOR found in search listing, not opened); recovery-service existence (no mention found); the firmware 'open source' status is source-available under MIT + Commons Clause per Coinkite about page and secure-element firmware is closed per Coinkite 2022 blog; app: no first-party app confirmed. Incident/vulnerability coverage is limited to the Coinkite disclosure list and news pages read; independent academic papers were not opened. Funds-lost totals for the July 2026 theft differ across sources and were still rising. Q-specific professional audit not found (Coinkite's list shows a 2022 Mk4 review only). Q price: list vs sale not labeled on the store page, so left null. Q secure-element chip models taken from Coinkite's 'same as Mk4' statement.
See how we check. To report an error, use corrections and right of reply.