Signing devices are scored on six dimensions weighted toward key generation, rather than on the rubric used for custody services. Assessment as of August 3, 2026.
A firmware defect caused affected devices to bypass the hardware random number generator and fall back to a predictable software generator. Every model line proved affected: Coinkite's advisory, updated August 1, estimates roughly 40 bits of effective entropy on Mk2 and Mk3 and roughly 72 bits on Mk4, Q and Mk5, against an intended 128. The defect shipped in March 2021 and remained undetected in public source for roughly five years. A dedicated dice-entropy path of at least 50 independent rolls is the documented exception, and patched firmware protects new seeds only.
Source-available with reproducible builds and a secure element, which is meaningful. The counterweight is that the entropy defect sat in publicly readable code for five years without being caught, which is evidence about the practical limits of that transparency rather than the intent behind it.
Tamper-evident packaging, direct sales, and device attestation are strong and unaffected by this incident.
This score reflects conduct in both directions. Initial public reports were dismissed as FUD before being acknowledged and reversed the same day, and the first advisory told Mk4, Q and Mk5 owners they were unaffected, which was wrong. Against that, remediation has been unusually decisive: a technical backgrounder within a day, corrected scope by August 1, patched firmware across every model line, remaining vulnerable inventory destroyed, shipment halted, and users pointed to competitor devices including one made by the firm that published the competing analysis. The residual criticism is that the incorrect model guidance was replaced rather than visibly annotated as a correction.
Standard multisig with published descriptors is well supported and recoverable with independent tooling. Miniscript support ships only in Edge developer-preview firmware, which the vendor itself warns should not be used for a main stash.
No known breach of customer purchase records.
Air-gapped signing. Open source firmware. Most security-focused hardware wallet.
Full self-custody responsibility. Physical device exposure. Kidnapping and extortion risk.
Coldcard's custody insurance is not publicly disclosed.
Coldcard uses a hardware wallet model and scores 58/100 in our independent review, including 58/100 on custody security. No single institution can unilaterally move funds. Safety depends on your priorities; see the full score breakdown above.
Coldcard's custody insurance is not publicly disclosed in a form we can verify. Where it exists, custody insurance covers specific named events up to shared limits and does not cover price loss. Confirm coverage in writing before relying on it.
Coldcard's architecture distributes control, so no single institution's failure alone can move or lose your bitcoin. Recovery depends on the specific structure; see the custody section above.
Coldcard does not advertise a dedicated inheritance or beneficiary feature in the data we track. Confirm current options with the provider, since custody inheritance handling changes.