Skip to content
Crypto Almanac Daily
C
Hardware Wallets

Coldcard

Best for verifiable firmware openness

Firmware repository:PublicSecurity or spec page:PublishedDocumentation:OpenVendor:CoinkiteRubric:v2.0 · verified 9 Aug 2026
Last verified August 9, 2026
Confidence ARubric v2.0Verified August 9, 2026
9.2
out of 10
Open account
Scorecard

How it rates

Key security & openness · 40%10.0
Purchase transparency · 10%8.0
Product openness · 20%10.0
Vendor transparency · 20%8.0
Public documentation surface · 10%8.0
Pros
  • Firmware source published in a public repository
  • Device security or specification page published
  • Technical documentation reachable without an account
Cons
  • Terms page not found at the conventional address at this check
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Key security & openness · 40% weight10/10 points · 10.0/10
  • Met
    Firmware source published in a public repository

    Vendor repository reachable at this check.

    github.com/Coldcard/firmware
  • Met
    Device security or specification page published

    Security or specification page reachable at this check.

    coldcard.com/docs/
  • Met
    Independent security research or audit programme published

    Security research programme published by the vendor.

    coldcard.com/docs/
  • Met
    Technical documentation reachable without an account

    Documentation open at this check.

    coldcard.com/docs/quick/
  • Met
    Vendor organisation identifiable from the repository

    Repository published under the vendor organisation (Coinkite).

    github.com/Coldcard/firmware
Purchase transparency · 10% weight8/10 points · 8.0/10
  • Met
    Shop or purchase page public

    Reachable without an account at this check.

    coldcard.com/
  • Met
    Model-specific product page public

    Model page reachable at this check.

    coldcard.com/docs/
  • Not met
    Legal or terms page public

    Not found at the conventional address at this check.

  • Met
    Support or help resource public

    Reachable at this check.

    coldcard.com/docs/quick/
  • Met
    Purchase information viewable without an account

    No account required to reach the shop at this check.

    coldcard.com/
Product openness · 20% weight10/10 points · 10.0/10
Vendor transparency · 20% weight8/10 points · 8.0/10
  • Met
    Vendor site resolves to automated verification

    HTTP 2xx at this check.

    coldcard.com/
  • Met
    Vendor entity identifiable

    Vendor organisation identifiable as Coinkite.

    github.com/Coldcard/firmware
  • Met
    Security or disclosure page published

    Published by the vendor.

    coldcard.com/docs/
  • Not met
    Terms or legal documentation published

    Not found at the conventional address at this check.

  • Met
    Product range documented publicly

    Product information published.

    coldcard.com/docs/
Public documentation surface · 10% weight8/10 points · 8.0/10

A Bitcoin-only signer using two secure elements from different vendors, with air-gapped microSD signing and coercion-resistant PIN options.

Our assessment

Coldcard is a Bitcoin-only signer built for people who assume the computer in front of them is compromised. It uses two secure elements from different manufacturers, signs through microSD using PSBTs so the device need never touch a USB data path, and publishes its firmware for verification.

Two chips, two vendors

Most devices in this comparison rely on a single secure element. Coldcard uses a Microchip ATECC608 alongside a Maxim DS28C36B, so a break in one vendor's part is not by itself a break in the wallet. That is a supply-chain argument as much as a cryptographic one, and it is unusual enough to justify the price difference for a large holding.

Coercion is treated as a real threat

A duress PIN opens a decoy wallet holding a token amount, and a brick-me PIN destroys the secure elements permanently. Very few consumer devices model the scenario where the attacker has both the device and the owner. Whether you need that depends entirely on your circumstances — but the design assumes you might, which is a different starting point from most of this table.

Bitcoin only, and awkward on purpose

There is no multi-chain support and no attempt at a friendly app experience. The Q model adds a QWERTY keyboard, QR scanner and battery power for a genuinely air-gapped workflow at a higher price. If you hold anything other than Bitcoin this is not a candidate; if you hold only Bitcoin, the narrower attack surface is the point.

Who it suits

Coldcard fits self-custody-serious Bitcoin holders comfortable with PSBTs, microSD workflows and Sparrow or Electrum on the desktop side. Beginners, and anyone holding a portfolio across chains, should look at Trezor, BitBox or Keystone.

Alternatives

How rivals compare

ServiceScoreBest for
Trezor9.9verifiable firmware opennessRead →
Reference

Frequently asked

Does this score mean Coldcard is secure?

No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.

Why does firmware openness matter so much here?

It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.

What would raise this score?

Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.