Draft:Coldcard
Review waiting, please be patient.
This may take 4 weeks or more, since drafts are reviewed in no specific order. There are 2,096 pending submissions waiting for review.
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
Reviewer tools
|
Comment: This is promising but may run into the requirement for ongoing coverage. Was there anything at all written about this wallet prior to the compromise?As it stands I don't think this is an article about Coldcard as it has almost no information on the wallet: it's an article about "Coldcard compromise" and that might be a better name. M kuhner (talk) 06:22, 28 August 2026 (UTC)
- Thanks. Yes, there was earlier coverage: Bitcoin Magazine in 2019, Decrypt in 2020, Bitcoin.nl in 2021 and Finder in 2023. I started with the incident because it was such a strange failure. The devices were not remotely compromised. A C macro was set to zero but still counted as defined, so the build linked the wrong RNG function. The weak seeds were then attacked offline. I got too interested in that and wrote the wrong article. I have rewritten it as a short article about Coldcard, with the incident under security. NoDicenocoin (talk) 22:42, 30 August 2026 (UTC)
Coldcard is a line of Bitcoin-only hardware wallets made by the Canadian company Coinkite. The first model went on sale in September 2018.[1]
The device holds the keys used to spend bitcoin and signs transactions prepared by separate wallet software. A transaction can be moved to the device on a MicroSD card in PSBT format, so signing does not require a USB data connection.[2]
In July 2026, Coinkite disclosed a bug that had reduced the randomness of some seed phrases. The resulting theft was estimated at more than $100 million in bitcoin by early August.[3][4]
Design and use
[edit]The Mk models look like small calculators. They have a screen and numeric keypad, and the PIN is entered on the device. The Mk3 could exchange data over USB or by MicroSD card.[2]
Coldcard supports Bitcoin rather than a range of cryptocurrencies. Bitcoin Magazine liked the full keypad in its 2019 review.[5] Decrypt found that the Mk3 gave users a lot of control but took more steps to sign a transaction.[2] Bitcoin.nl described the same trade-off in 2021 and said the wallet was better suited to experienced users.[6]
Models
[edit]The Mk3 was released in October 2019.[2] Finder reviewed the Mk4 in 2023. Its review noted the two secure elements and the MicroSD workflow, and listed the price and need for accessories among its drawbacks.[1]
The larger Coldcard Q was released in 2024. It has a keyboard, larger screen, QR scanner, battery power and two MicroSD slots.[7][8] The Mk5 followed in 2026 and used the same firmware as the Mk4.[9]
Security history
[edit]In 2020, Ledger's Donjon laboratory published a physical attack against the secure element in the Coldcard Mk2. It required opening the device, removing and exposing the chip, and equipment estimated at about $200,000. Ledger said the attack did not apply to the secure element used in the Mk3.[10]
The 2026 bug was in seed generation. Attackers searched the reduced set of possible seeds and recovered the keys offline; they did not need the devices.[11] Coinkite's affected-release table included Mk2/Mk3, Mk4/Mk5 and Q firmware.[12]
Firmware released in August 2026 required key presses, dice rolls or coin flips when making a standard new seed.[13] The update only changed future seed generation. Existing affected seeds still had to be replaced and the funds moved.[12]
References
[edit]- 1 2 Corva, Frank (January 8, 2023). "COLDCARD Mk4 review". Finder. Retrieved August 30, 2026.
- 1 2 3 4 Phillips, Daniel (April 5, 2020). "Coldcard Mk3 wallet review: Maximum security for your Bitcoin". Decrypt. Retrieved August 30, 2026.
- ↑ Franceschi-Bicchierai, Lorenzo (August 4, 2026). "Hackers steal over $130M by exploiting bug in offline hardware wallets". TechCrunch. Retrieved August 23, 2026.
- ↑ CBC News (August 4, 2026). "What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin". CBC News. Retrieved August 23, 2026.
- ↑ Taiberg, Michael (November 4, 2019). "Video Review: Coldcard Mk3". Bitcoin Magazine. Retrieved August 30, 2026.
- ↑ van der Schaar, Marlies (March 23, 2021). "Review: Coldcard Mk.3 hardware wallet". Bitcoin.nl (in Dutch). Retrieved August 30, 2026.
- ↑ "Coldcard Q". WalletScrutiny. February 8, 2024. Retrieved August 30, 2026.
- ↑ "COLDCARD Q". COLDCARD. Coinkite. Retrieved August 30, 2026.
- ↑ "Mk5 Compared to Mk4". COLDCARD Documentation. Coinkite. Retrieved August 30, 2026.
- ↑ Ledger Donjon (May 18, 2020). "Lit by Laser: PIN Code Recovery on Coldcard Mk2 Wallets". Ledger. Retrieved August 30, 2026.
- ↑ Tasca, Elisa (August 4, 2026). "A $116 million bitcoin theft: hackers break into one of the safest places to store cryptocurrencies". El País. Retrieved August 23, 2026.
- 1 2 "Current COLDCARD Security Status". COLDCARD. Coinkite. August 30, 2026. Retrieved August 30, 2026.
- ↑ Malwa, Shaurya (August 21, 2026). Alpher, Stephen (ed.). "Coldcard ships firmware after $114 million bitcoin theft; says AI helped catch more bugs". CoinDesk. Retrieved August 23, 2026.
