A Coldcard wallet has always been sold on a particular kind of trust. Bitcoin only, two secure element chips from different vendors, firmware published so that an owner who cares can rebuild it and compare. For years that pitch drew the people who read the source before they read the marketing. Then on 30 July 2026 somebody started emptying Coldcard wallets, and the cause turned out to be a build mistake from 2021 that nobody had caught in five years.
That history now sits between you and the spec sheet, because the two devices Coinkite currently sells are good hardware with a bad quarter behind them. This is what each one does, what the entropy bug means for anyone who already owns one, and where the single-object problem survives both models.
What a Coldcard wallet is
Coinkite, a Canadian company, builds the Coldcard as a Bitcoin-only signing device. Its own product pages describe two secure elements from different vendors, Microchip's ATECC608 and Maxim's DS28C36B, used together to store the master secret, plus firmware the company calls open source and reproducible so advanced users can verify what runs on the device. No altcoin support exists and none is coming, which is deliberate: a narrower codebase is a narrower target.
The other defining habit is working without a cable. You can carry an unsigned transaction to the device on a microSD card and carry the signed version back out, which keeps the signing machine off your computer entirely, and on the pricier of the two models you can do that job with QR codes instead of cards.
The entropy bug, and what it cost
In March 2021, Coldcard firmware 4.0.1 shipped with a build configuration error that made affected devices fall back on weak software randomness instead of hardware entropy while generating a seed. TRM Labs, which traced the resulting theft, found the mistake cut key strength from 128 bits to as little as 40, weak enough to brute-force without anybody touching your device. Technical write-ups of the flaw put pre-patch seeds on the Mk4, Mk5 and Q nearer 72 bits than the intended 128.
Draining started on 30 July 2026 and ran in four waves. The first took 594 BTC, about 38 million USD, from roughly 500 wallets inside 25 minutes, and TRM Labs puts the full total at around 1,816 BTC, near 116 million USD, across more than 5,200 addresses. It became the third-largest crypto theft of the year.
Coinkite moved quickly, and that deserves saying as plainly as the failure does. Firmware 5.6.0 arrived on 31 July 2026 and rebuilt seed generation so that a new wallet cannot be created without entropy the owner supplies: 65 keypresses with unpredictable timing, 50 dice rolls or 128 coin flips, all mixed with output from the secure elements and the hardware random number generator.
One detail gets missed, and it is the one that costs money. Installing the fix does not repair a seed that was already generated on affected firmware, so an owner whose wallet was created between March 2021 and that patch needs a freshly generated seed and has to move every coin across to it.
Coldcard Q vs Mk5
Coinkite lists two devices today, and the Mk4 that most reviews still discuss has been retired from the lineup. Prices below were taken from coldcard.com on 7 October 2026, both running at a discount off list.
| COLDCARD Q | COLDCARD Mk5 | |
|---|---|---|
| Price | 319 USD (listed down from 369) | 219 USD (listed down from 269) |
| Screen | 3.2-inch colour LCD, 320 x 240 | Brighter display behind Gorilla Glass |
| Input | Full QWERTY keyboard, 50 keys | Refined numeric keypad |
| Offline route | Built-in QR scanner with its own light, two microSD slots | One microSD slot, NFC |
| Wired port | Yes | Yes, repositioned for easier access |
| Battery | Runs on AAA cells for fully offline use | None listed |
| Secure elements | Two, from different vendors | Two, from different vendors |
| Assets | Bitcoin only | Bitcoin only |
The gap between them is interaction rather than security, since Coinkite applies the same dual-secure-element model to both. What 100 USD buys on the Q is a screen big enough to read an address without squinting, a keyboard that makes a long passphrase bearable to type, and a camera so you can stay off cables and cards completely while the AAA cells keep the device alive away from a port.
COLDCARD Q is best for a Bitcoin holder who wants a fully offline workflow and expects to type passphrases often. Worth knowing: it is the bulkiest option in its class, it costs more than most multi-asset devices, and the QWERTY keyboard adds moving parts that a keypad does not have.
COLDCARD Mk5 is best for someone who wants the same chip-level design in a travel-sized body and does not mind a numeric keypad. Worth knowing: entering a long passphrase on a number pad is slow work, and the smaller screen makes careful address checking a deliberate chore rather than a glance.
What the migration asks of your backup
If you own either device and your seed predates the patch, the job in front of you is the one every holder hopes to avoid: generate a new wallet, write down a new set of words, and move your coins while your old addresses are still yours to spend from. Nothing about that is complicated. It is the moment, though, when whatever arrangement you made for your written words gets tested in a hurry, and hurry is where seed phrases go wrong.
This is also where the standard advice runs out. A metal plate is the sensible upgrade from paper and survives heat and damp that would destroy a card, so treat it as the floor for a long-term position. What stamping steel cannot change is that your recovery still depends on one object staying both undamaged and unseen, and a plate in a drawer is as findable as the card it replaced. TapSafe Recovery exists to remove that shape of risk rather than harden it, and the next section covers how.
Where Ryder One sits
A Coldcard owner choosing between the Q and the Mk5 is choosing how to interact with a key that one written list can give away. We took a different route with the Ryder One, and the honest framing is that no vendor is immune to the kind of error Coinkite shipped: firmware is code, code carries bugs, and the useful question is who checks it and what happens to you when something slips.
Our firmware was independently audited by Halborn, whose full report is public. Keys are generated inside an EAL6+ certified Infineon SLC38 secure element and never leave the chip. Every transaction renders in readable detail on a 1.6-inch AMOLED touchscreen before you approve it, receive addresses are verified on the device, and the button that authorises a signature is wired directly to the secure element, so no software path can sign on its own. Communication is NFC only, with no Bluetooth radio and no Wi-Fi.
Where we differ most is recovery. TapSafe splits it using our own implementation of Shamir's Secret Sharing: the Recovery Tag holds half, your paired phone holds the other half encrypted into your own iCloud or Google Drive rather than on the handset, and optional Recovery Contacts hold a quarter each without learning anything about your holdings. No single piece opens the wallet, and your seed phrase stays readable on the device as a last resort under the BIP-39 standard, so you keep the exit that paper gave you.
On the question a Coldcard owner asks first: every Ryder One wallet is generated with 256 bits of entropy drawn exclusively from the hardware true random number generator inside the Infineon SLC38 secure element, using a noise source designed in accordance with AIS 31. No software pseudorandom generator sits anywhere in that path, and the TRNG output is never mixed with another source, which is the exact substitution that cost Coldcard owners their coins. If the secure element cannot acquire the random data it needs, generation stops with an error instead of falling back to something weaker. We run standardised statistical tests on the TRNG output across multiple sample sizes, and Halborn audited the applet code that does the generating. We do not currently let you supply your own entropy through dice rolls or coin flips the way firmware 5.6.0 now requires, and the full write-up is in How Ryder One Generates and Protects Your Wallet.
Setup runs three taps in about 60 seconds. The Starter Combo is 149 USD and the Super Safe Combo is 179 USD, each shipping with the Recovery Tag, a Qi wireless charger and a pouch. Supported assets are Bitcoin, Ethereum, Solana and a growing list of top ERC-20 and SPL tokens, so a Bitcoin-only holder should weigh that breadth against the focus Coldcard sells, and anyone holding other chains should check the list before buying any hardware, ours included. Get your Ryder One.




Share: