Trading Education Platform SystemSubscribe for FreeSupport
Wallets / Coldcard Q
HARDWARE WALLET REALITY CHECK · READ 11 OCT 2026

Coldcard Q: what the sources say

Current 5 disclosed weaknesses 3 company incidents

Key facts

The questions, with sources

QuestionWhat the sources saySource
Status
Current — Listed in stock on the official Coinkite store on 2026-10-11 (Clear plus colour variants). Firmware 1.5.1Q listed as the fix for the 2026 advisory.
Company
Coinkite Inc., Canada
List price
n/v — Official store shows two unlabeled prices for the Q: $369 and $319 (store page does not state which is list vs sale); batteries and USB cable not included; a 10% promo for on-chain BTC payment is also advertised. No EUR price shown.
Secure element
Yes: Two secure elements from different manufacturers, 'same model as the Mk4' per Coinkite (Mk4 chips: Microchip ATECC608B and Maxim DS28C36B)
Firmware code
Partial (MIT + Commons Clause (per Coinkite about page; the Commons Clause is not an OSI open-source license)); reproducible build: yes. Main firmware source and Docker-based reproducible build published (README). Coinkite states the secure elements are closed source and the SE-communication bootloader is set at the factory and not upgradeable (2022 blog). LICENSE file itself not opened.
Companion app
Not verified. No first-party companion app confirmed; device works with third-party wallet software.
—
Connections
USB: USB-C (data; virtual-disk mode); can be permanently disabled by cutting a PCB trace. Bluetooth: n/v. NFC: NFC-V (PSBTs, addresses, XPUBs); can be permanently disabled. QR: yes (built-in QR scanner with LEDs). microSD: yes (two push-pull slots).
Screen
2.3-inch colour LCD, 320x240, with 50-key QWERTY keyboard; touch: no (physical keyboard)
Assets
Bitcoin only; Bitcoin-only option: Bitcoin-only by design
Multisig and PSBT
Yes. Coinkite states all Mk4 features work on the Q; multisig supported on Mk4. Q adds QR/BBQr PSBT exchange.
Passphrase
Yes. Coinkite names BIP-39 passphrases as a key use of the Q keyboard.
Shamir backup (SLIP-39)
Not verified. SLIP39/Shamir not found in documentation read. Coinkite documents a different split scheme, Seed XOR (since firmware 4.1.0).
Recovery phrase standard
BIP39 24 words
Optional recovery service
Not verified. No recovery/backup service found in pages read.
—
FIDO / passkeys
Not verified. Not mentioned in pages read.
—
Bug bounty
Yes

"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.

Summary

Five facts

  • The Coldcard Q is listed in stock on Coinkite's official store on 2026-10-11 with two unlabeled prices, $369 and $319 [source 4].
  • It has a 2.3-inch colour LCD, a QWERTY keyboard, a QR scanner, NFC, USB-C and two microSD slots, and uses the same two secure elements as the Mk4 per Coinkite [source 16].
  • Firmware is published with reproducible builds (Q1 makefile) under MIT plus the Commons Clause, not an OSI license [source 11][source 12].
  • Coinkite's advisory of 2026-07-30 says Q seeds generated on firmware before 1.5.0Q used a weaker software RNG; press reports roughly 1,400 to 1,600 BTC stolen across Coldcard models [source 5][source 7][source 8].
  • Updating firmware does not fix seeds already generated on affected firmware; Coinkite advises migrating them [source 5].
Independent checks

Audits

  • No independent audit found in our search.
Device record

Publicly disclosed weaknesses

  • 2026-07-30 Seed-generation flaw: since a March 2021 library migration (firmware 4.0.1 onward) the seed path used a software PRNG instead of the hardware TRNG, reducing seed search space. Coinkite states Mk4/Mk5/Q seeds had about 72 bits of effective entropy (design target 128) and that attackers exploited this offline to regenerate keys and steal funds. Affected: Mk4/Mk5 before 5.6.0, Q before 1.5.0Q. Coinkite's advisory (30 Jul 2026), analysis by Block and Galaxy Research cited by press. Updating fixes generation of new seeds only; seeds created on affected firmware must be migrated. Funds lost: yes. Mitigated source
  • 2025-09 Delta PIN private-key recovery from two signatures (coordinated disclosure, Mk4/Mk5 and Q families; Coinkite says full matrix not published). Patched in 5.4.4 / 1.3.4Q per Coinkite. Funds lost: not verified. Fixed source
  • 2026-07 Legacy input-amount spoofing (credited fix), Mk4/Mk5 before 5.5.1 and Q before 1.4.1Q; fixed per Coinkite. Funds lost: not verified. Fixed source
  • 2026-08 Staged-PSBT transaction substitution when signing over USB with PSRAM-staged PSBTs (credited fix), before 5.6.1 / 1.5.1Q; plus several input-validation, callgate and SIGHASH_SINGLE hardening reports (Aug 2026). Fixed in 5.6.1 and 1.5.1Q per Coinkite; Coinkite notes its 30-entry list is a chronology, not a count of independent vulnerabilities. Funds lost: not verified. Fixed source
  • 2023-09 DS28C36 (the second secure element used in Mk4) double-laser readout, coordinated disclosure; Coinkite describes partial exposure and no full seed recovery. Page lists it under Mk4 SE2; the Q uses the same secure elements per Coinkite. Funds lost: no. Fix status not verified source

Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.

Company record

Incidents at the maker or its service providers

  • 2026-07-30 Theft of bitcoin from wallets with seeds generated on affected Coldcard firmware (see vulnerability above). Privacy Guides reports about 1,400 BTC (c. $70M at the time) in the first days; Decrypt, citing Galaxy Research, reports 1,596 BTC high-confidence losses across three waves as of 4 Aug 2026; Optech reported over 1,000 BTC. Figures vary by source and date. Coinkite says the devices were not hacked or remotely accessed. Customer funds lost: yes. Outcome: Fixed firmware released; Coinkite advises migrating any seed created on affected firmware. Totals still developing at time of sources. source
  • 2026-08 Phishing campaigns impersonating Coinkite/Coldcard ('coordinated hardware audit') delivered a batch file installing the remote-access tool ScreenConnect (reported by Proofpoint via Decrypt on 3 Aug 2026; analysed by PhishFort, 18 Aug 2026). Campaign did not ask for seed phrases per PhishFort. Customer funds lost: not verified. Outcome: Third-party warnings; sources do not state funds lost from this campaign. source
  • 2026-08 Criticism that Coinkite emailed some customers despite stating it deletes customer data after 90 days; Coinkite reportedly responded that Canadian law requires keeping business records for eight years (as reported by Privacy Guides). Customer funds lost: no. Outcome: Reported controversy over data retention; no breach reported in the source. source

These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.

Questions

Questions about Coldcard Q

Is Coldcard Q safe?

We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 5 publicly disclosed weaknesses and 3 company incidents in our search. Read the sources above before you buy.

Does Coldcard Q need an internet connection?

Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB, QR. The companion app or software that builds the transaction is online.

Who found the weaknesses listed for Coldcard Q?

The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.

Sources

Where this comes from

Not verified: Not verified: whether a Bluetooth radio is absent (not stated by maker); passkeys/FIDO support (not mentioned in docs read); SLIP39/Shamir (only Seed XOR found in search listing, not opened); recovery-service existence (no mention found); the firmware 'open source' status is source-available under MIT + Commons Clause per Coinkite about page and secure-element firmware is closed per Coinkite 2022 blog; app: no first-party app confirmed. Incident/vulnerability coverage is limited to the Coinkite disclosure list and news pages read; independent academic papers were not opened. Funds-lost totals for the July 2026 theft differ across sources and were still rising. Q-specific professional audit not found (Coinkite's list shows a 2022 Mk4 review only). Q price: list vs sale not labeled on the store page, so left null. Q secure-element chip models taken from Coinkite's 'same as Mk4' statement.

See how we check. To report an error, use corrections and right of reply.