Skip to content
Back to skills

Coldcard

ASecurity

Coldcard hardware wallets (Coinkite): Mk4, Mk5, Q. Bitcoin-only firmware, airgap support via SD card / NFC / QR, BIP85, MuSig2 (Edge firmware), Trick PINs, and the July 2026 seed-entropy advisory. USE WHEN: integrating with Coldcard, supporting Mk4 / Mk5 / Q, designing airgap signing flows, assessing whether a seed was generated by affected firmware.

  • 31 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 8, 2026
ai-agentspythongoapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add claude-dev-suite/claude-dev-suite --skill coldcard --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Coldcard?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Coldcard
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/claude-dev-suite-coldcard/badge)](https://www.skillsdirectory.com/skills/claude-dev-suite-coldcard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: bitcoin-hardware-coldcard
description: |
  Coldcard hardware wallets (Coinkite): Mk4, Mk5, Q. Bitcoin-only
  firmware, airgap support via SD card / NFC / QR, BIP85, MuSig2 (Edge
  firmware), Trick PINs, and the July 2026 seed-entropy advisory.
  USE WHEN: integrating with Coldcard, supporting Mk4 / Mk5 / Q,
  designing airgap signing flows, assessing whether a seed was generated
  by affected firmware.
allowed-tools: Read, Grep, Glob
---

# Coldcard (Coinkite)

Bitcoin-only hardware wallet. Industry favorite for **airgapped**
signing. Models: Mk4, Mk5, Q.

## Security advisory: weak seed generation (2021-2026)

> Critical. Any seed generated on a COLDCARD between March 2021 and July
> 2026 must be treated as compromised.

Coinkite published an advisory on 30 July 2026 (expanded 1 August 2026)
plus a technical backgrounder. In the March 2021 libNgU migration, seed
generation moved from `ckcc.rng_bytes()` to `ngu.random.bytes()`.
`MICROPY_HW_ENABLE_RNG` was set to `0` to disable the software path, but
the preprocessor guard tested whether the macro was *defined* rather
than its value, so `rng_get()` linked to MicroPython's Yasmarang
software PRNG instead of the hardware TRNG. The TRNG never failed at
runtime; the build linked the wrong symbol, and both implementations had
the same signature so nothing complained.

Effective search space, against a design target of 128 bits:

| Models | Affected firmware | Effective entropy |
|--------|-------------------|-------------------|
| Mk2 / Mk3 | 4.0.1 - 4.1.9 | ~40 bits |
| Mk4 / Mk5 | Standard < 5.6.0, Edge < 6.6.0X | ~72 bits |
| Q | Standard < 1.5.0Q, Edge < 6.6.0QX | ~72 bits |

Mk4/Mk5/Q fare better only because SE1/SE2 entropy was still mixed into
the PRNG state. TAPSIGNER, OPENDIME and SATSCARD use different codebases
and are unaffected.

Fixed firmware:

| Line | Fixed at | Latest as of 15 September 2026 |
|------|----------|--------------------------------|
| Mk2 / Mk3 Standard | 4.2.0 | 4.2.0 (final release for Mk2/Mk3) |
| Mk4 / Mk5 Standard | 5.6.0 | 5.6.2 (2026-09-03) |
| Q Standard | 1.5.0Q | 1.5.2Q (2026-09-03) |
| Mk4 / Mk5 Edge | 6.6.0X | 6.6.1X (2026-08-31) |
| Q Edge | 6.6.0QX | 6.6.1QX (2026-08-31) |

**Updating firmware does not fix an existing seed.** From the technical
backgrounder: "Updating the firmware does not repair a seed that was
generated by affected firmware. A new seed must be generated and the
funds migrated to the new wallet."

Exemptions and mitigations:
- A seed mixed with >= 50 fair, independent, private dice rolls is not
  at risk from this bug alone (99+ rolls is ~256 bits of dice entropy).
- A strong, unique, secret BIP-39 passphrase is an independent barrier,
  but Coinkite still says to migrate to a newly generated seed as soon
  as practical.

Migration: upgrade firmware first, generate a new seed on the fixed
build, verify the backup, test with a small transaction, then move the
remaining funds. Regenerate every secret derived on-device during the
affected window, not just the master seed - BIP85 sub-seeds and
duress/decoy wallets included.

Exploitation started 30 July 2026, the day of the advisory. As of TRM
Labs' report of 5 August 2026, Galaxy Research's running tally stood at
roughly 1,816 BTC (~USD 116 million) drained from more than 5,200
addresses across four waves. TRM calls that preliminary - funds were
still moving and a fourth wave was still in the mempool at the time of
writing. It is also cumulative, so the lower numbers in earlier press
coverage are snapshots of the first waves.

## Models

| Model | Year | Notes |
|-------|------|-------|
| Mk4 | 2022 | USB-C + microSD + NFC, no battery |
| Mk5 | 2026 | 1.54" Gorilla Glass, new keypad, bottom USB-C, NFC |
| Q | 2024 | Color touchscreen, USB-C, microSD, NFC, full keyboard, battery |

The Mk5 is a March 2026 refresh of the Mk4 and shares its firmware
builds: Coinkite ships a single Standard download covering "Mk4/Mk5"
(as of September 2026).

## Airgap support

Multiple transport options:
- **microSD card**: write PSBT to card, sign on device, write back.
- **NFC**: tap-to-transfer.
- **QR codes** (Q only): scan + display.
- **USB**: direct (less airgap).

## Bitcoin-only firmware

Coldcard intentionally supports ONLY Bitcoin. No altcoins. Smaller
attack surface, simpler mental model.

## Trick PINs

Defense against coercion:
- Set up multiple PINs.
- "Real" PIN unlocks main wallet.
- "Duress" PIN unlocks decoy wallet (real-looking but with different
  seed).
- "Login countdown" — N attempts before wallet wipe.

## BIP85

Native support for deriving sub-seeds via BIP85. UI lets you generate:
- BIP39 mnemonic (any word count).
- HEX bytes.
- WIF private key.
- xprv.

## MuSig2 (Edge firmware)

MuSig2 signing shipped in **Edge 6.5.0X / 6.5.0QX** (24 March 2026) for
Mk4/Mk5 and Q - "Ability to sign MuSig2 UTXOs", alongside BIP-322 proof
of reserves for Miniscript and MuSig2 UTXOs. Key-path aggregation means
the spend is indistinguishable on-chain from a single-signer Taproot
spend.

Edge is Coinkite's faster-moving preview branch; the download page
warns it is "Targeting developers and experimenters, the Edge version
tracks the latest changes to Bitcoin" (as of September 2026). It also
carries Taproot/Tapscript, BSMS (BIP-129), Miniscript and BIP-388
wallet policies. Standard firmware (5.6.x / 1.5.xQ as of September
2026) does not include MuSig2.

Later Edge releases hardened it: distinct nonces for different
aggregate-key derivations of the same participant set, session handling
for PSBTs with foreign MuSig2 inputs or differing witness UTXO data,
preserving incomplete sessions while waiting for cosigner public nonces,
no PSBT corruption when one participant signs multiple rounds via Key
Teleport, and a 32-participant cap.

Cross-tool support has started: HWI 3.2.0 (10 February 2026) added PSBT
MuSig2 fields.

## Backup

- Standard 24-word seed. Generate it only on fixed firmware (see the
  security advisory above), and mix in >= 50 private dice rolls if you
  want entropy that does not rest on the device alone.
- "Tarot card" backup grids for resilient recovery.
- BIP85-derived sub-seeds.
- Encrypted backups to microSD with a separate backup password.
- 5.6.2 / 1.5.2Q (September 2026) add **View TRNG Words**: shows the
  full 256-bit device-generated input as 24 BIP39 words *before* dice
  rolls or key presses are mixed in, so the mixing can be verified
  independently.

## API

`ckcc-protocol` Python:
```python
from ckcc_protocol.client import ColdcardDevice
dev = ColdcardDevice()
pk = dev.get_xpub("m/84'/0'/0'")
dev.sign_psbt(psbt_bytes)
```

## Connection

- USB-C.
- microSD (airgap).
- NFC (Mk4, Mk5, Q).
- Q only: QR code.

Third-party: HWI, Sparrow, Specter, Electrum.

## Common issues

- microSD format must be FAT32 (max 32 GB).
- USB driver issues on some Linux distros.
- NFC on iPhone limited to read-only — use Android for tap-to-sign.

## See also

- [trezor/SKILL.md](../trezor/SKILL.md)
- [ledger/SKILL.md](../ledger/SKILL.md)
- [psbt-flows/SKILL.md](../psbt-flows/SKILL.md)
- [hwi/SKILL.md](../hwi/SKILL.md)
- [../wallets/entropy/SKILL.md](../../wallets/entropy/SKILL.md)
- [../wallets/backup/SKILL.md](../../wallets/backup/SKILL.md)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…