Coldcard
Best for verifiable firmware openness
How it rates
- Firmware source published in a public repository
- Device security or specification page published
- Technical documentation reachable without an account
- Terms page not found at the conventional address at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetFirmware source published in a public repository
Vendor repository reachable at this check.
github.com/Coldcard/firmware - MetDevice security or specification page published
Security or specification page reachable at this check.
coldcard.com/docs/ - MetIndependent security research or audit programme published
Security research programme published by the vendor.
coldcard.com/docs/ - MetTechnical documentation reachable without an account
Documentation open at this check.
coldcard.com/docs/quick/ - MetVendor organisation identifiable from the repository
Repository published under the vendor organisation (Coinkite).
github.com/Coldcard/firmware
- Met
- Met
- Not metLegal or terms page public
Not found at the conventional address at this check.
- Met
- MetPurchase information viewable without an account
No account required to reach the shop at this check.
coldcard.com/
- Met
- MetFirmware repository is the vendor's own
Repository published by the vendor.
github.com/Coldcard/firmware - Met
- MetDocumentation site separate from marketing
Dedicated documentation or support resource published.
coldcard.com/docs/quick/ - Met
- Met
- Met
- Met
- Not metTerms or legal documentation published
Not found at the conventional address at this check.
- Met
- Met
- Met
- Met
- Met
- Not metLegal documentation reachable
Not found at the conventional address at this check.
A Bitcoin-only signer using two secure elements from different vendors, with air-gapped microSD signing and coercion-resistant PIN options.
Our assessment
Coldcard is a Bitcoin-only signer built for people who assume the computer in front of them is compromised. It uses two secure elements from different manufacturers, signs through microSD using PSBTs so the device need never touch a USB data path, and publishes its firmware for verification.
Two chips, two vendors
Most devices in this comparison rely on a single secure element. Coldcard uses a Microchip ATECC608 alongside a Maxim DS28C36B, so a break in one vendor's part is not by itself a break in the wallet. That is a supply-chain argument as much as a cryptographic one, and it is unusual enough to justify the price difference for a large holding.
Coercion is treated as a real threat
A duress PIN opens a decoy wallet holding a token amount, and a brick-me PIN destroys the secure elements permanently. Very few consumer devices model the scenario where the attacker has both the device and the owner. Whether you need that depends entirely on your circumstances — but the design assumes you might, which is a different starting point from most of this table.
Bitcoin only, and awkward on purpose
There is no multi-chain support and no attempt at a friendly app experience. The Q model adds a QWERTY keyboard, QR scanner and battery power for a genuinely air-gapped workflow at a higher price. If you hold anything other than Bitcoin this is not a candidate; if you hold only Bitcoin, the narrower attack surface is the point.
Who it suits
Coldcard fits self-custody-serious Bitcoin holders comfortable with PSBTs, microSD workflows and Sparrow or Electrum on the desktop side. Beginners, and anyone holding a portfolio across chains, should look at Trezor, BitBox or Keystone.
How rivals compare
| Service | Score | Best for | |
|---|---|---|---|
| Trezor | 9.9 | verifiable firmware openness | Read → |
Frequently asked
Does this score mean Coldcard is secure?
No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.
Why does firmware openness matter so much here?
It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.
What would raise this score?
Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.