Coldcard MK4:
a five-year-old firmware bug just cost real users over $100 million.
We tore apart Coinkite's Bitcoin-only, air-gapped hardware wallet across seven weighted categories; from a genuinely thoughtful dual-secure-element, PSBT-based air-gap design built for serious Bitcoiners, to a self-disclosed, five-year-undetected entropy failure that produced catastrophically weak seeds and has already resulted in over $100 million in confirmed, real-world theft; and landed on a score the marketing page won't show you.
Our take, up front: the Coldcard MK4's underlying design has real, genuine merit: dual secure elements meant to require both chips be compromised for an attacker to extract keys, a fully air-gapped workflow using MicroSD or NFC instead of a data cable, and historically open-source firmware that let anyone audit the code. That design earned it a loyal following among serious Bitcoiners for years. What we can't set aside is what just happened: a firmware error Coinkite itself introduced in March 2021 went undetected for five years, quietly weakening the randomness behind newly-generated seeds, and in late July 2026 attackers began systematically draining wallets as a direct result, with independently-tracked losses climbing past $100 million across multiple waves. Updating the firmware does nothing to protect funds already sitting behind a weak seed generated before the fix, and Coinkite has yet to publish its own verified victim count or loss total despite the scale of independently-documented harm. We weighted all of it below, and we can't recommend a new purchase while this remains this recent and this unresolved.
The MK4's underlying architecture has real merit: dual secure elements (an ATECC608A or, in later units, the improved ATECC608B) with the seed split between both chips, meaning an attacker needs to compromise both, not just one, to extract keys. The device is genuinely air-gapped by design, MicroSD, NFC, or USB in power-only mode with data lines physically disabled, and its firmware has historically been open-source and independently auditable. None of that prevented a real, catastrophic failure: a firmware bug Coinkite introduced in March 2021 rerouted seed generation away from proper hardware randomness toward a weak, deterministic software process, undetected for roughly five years. Effective key strength fell from a 128-bit target to as little as 40 bits on Mk2/Mk3 devices and roughly 72 bits on Mk4, Mk5, and Q devices, both catastrophically brute-forceable. Beginning July 30, 2026, attackers exploited this in coordinated waves, and independently-tracked losses across multiple sources have climbed past $100 million from thousands of affected addresses. Fully-patched firmware wasn't released until August 20, 2026, roughly three weeks after the first public disclosure. Updating firmware does not protect funds already sitting behind a seed generated before the fix; those must be treated as compromised and moved to a newly-generated seed. Independent analysis from Block suggests the true vulnerability window may be wider than Coinkite's own advisory acknowledges, and Coinkite has not published its own verified victim count or total loss figure despite the scale of independently-documented harm. One real, useful mitigation: seeds generated via independent dice rolls, or protected by a strong BIP-39 passphrase, were never at risk, since neither depends on the device's internal randomness.
Pros
- Genuine dual secure-element design with keys split across both chips
- Fully air-gapped workflow with no required data-cable connection
- Historically open-source, independently auditable firmware
Cons
- A self-introduced, five-year-undetected entropy flaw has directly resulted in over $100 million in confirmed real-world theft
- Fixed firmware took roughly three weeks to ship after public disclosure, during which the exploit remained active
- Independent analysis suggests Coinkite's own disclosed scope may understate the true exposure
- No company-published victim count or loss total despite the scale of documented harm
The Coldcard is Bitcoin-only, by explicit, deliberate design rather than an oversight. That's a real, coherent philosophy for the specific Bitcoin-maximalist audience this device targets, and it works with established Bitcoin-focused software like Sparrow, Specter, and Electrum.
Pros
- Deep, purpose-built compatibility with established Bitcoin software (Sparrow, Specter, Electrum)
Cons
- Bitcoin-only; no support for any other cryptocurrency
There's no mobile app by design; you transact through third-party desktop software like Sparrow, Specter, or Electrum. The small numeric keypad is independently described as "genuinely painful" for passphrase entry specifically. Real, deliberate air-gapped interaction methods exist: MicroSD (recommended, zero internet exposure), NFC tap-to-sign, and USB in power-only mode. Multiple independent sources explicitly recommend beginners start with a simpler wallet (Trezor Safe 5, BitBox02) and "come back to Coldcard after six months" once they understand seed phrases, derivation paths, and PSBT workflows.
Pros
- Multiple genuine air-gapped interaction methods (MicroSD, NFC, USB power-only)
Cons
- No mobile app; requires third-party desktop software to transact
- Numeric keypad independently described as painful for passphrase entry
- Real setup complexity multiple sources recommend beginners avoid initially
The MK4 ships in a bag with a unique "bag number" recorded in the device's own secure memory, a genuinely thoughtful anti-tampering measure that lets buyers verify their unit hasn't been opened or modified in transit. No independently-documented physical durability complaints turned up in our research, though the overall design reads as more basic and utilitarian than the premium builds found on some pricier competitors in this series.
Pros
- Tamper-evident bag-number verification system, a genuinely thoughtful supply-chain security measure
Cons
- More basic, utilitarian design than premium competitors like the Trezor Safe 7 or Tangem
Coinkite has operated since 2012, a genuinely long history. But this category is now dominated by the same real, catastrophic entropy failure detailed above: a self-introduced firmware flaw that went undetected for five years, resulting in over $100 million in independently-confirmed theft, a roughly three-week gap between public disclosure and a fully-fixed firmware release, and a real, unresolved gap between independently-documented harm and Coinkite's own public accounting. Law enforcement is reportedly investigating, per Coinkite's own acknowledgment.
Pros
- Long operating history since 2012
Cons
- Self-introduced entropy flaw undetected for five years, resulting in over $100 million in confirmed theft
- No company-published victim count or total loss figure
- Independent analysis suggests the disclosed vulnerability scope may be incomplete
Pricing across sources ranges from roughly $148 to $178 depending on configuration and retailer, broadly comparable to mid-tier competitors in this series. No subscription fee; the device price is the entire cost of ownership.
Pros
- Competitively priced against mid-tier hardware wallet competitors
- No subscription fee; device price is the entire cost of ownership
Cons
- Reasonable pricing doesn't offset the currently active, unresolved security situation
Trick PINs (duress PINs that open a decoy wallet) and spending policies with real 2FA are genuinely advanced features for power users. An advanced "Dice Rolls Only" mode lets a user generate a seed entirely independent of the device's internal randomness, ironically the one seed-generation path proven unaffected by the entropy failure detailed above, and worth using specifically for that reason going forward.
Pros
- Trick PINs and spending policies with 2FA for advanced threat models
- A "Dice Rolls Only" seed generation mode, proven unaffected by the recent entropy failure
Cons
- The safest generation mode isn't the default, and wasn't until after the disaster
Check your firmware version and seed generation date now.
If you generated a seed on any Coldcard device before installing firmware 5.6.1 (Mk4/Mk5) or 1.5.1Q (Q), treat that seed as compromised regardless of what firmware you're running today. Generate a brand-new seed on fully-patched firmware, ideally using the Dice Rolls Only mode, and move your funds to it as soon as possible. Consider a multivendor multisig setup for meaningful balances going forward.
A well-regarded design, undone by the one thing a hardware wallet can't get wrong.
Everything the Coldcard MK4 was built to prevent, remote key theft, malware exposure, single-point-of-failure chip design, it largely delivered on for years. But a hardware wallet's entire value proposition rests on one specific promise: generating keys nobody can predict. A firmware error Coinkite introduced itself broke exactly that promise for five years without anyone noticing, and the result wasn't theoretical, it was over $100 million in real money taken from real people. Good air-gap design and dual secure elements don't matter if the seed born inside them was never actually random. We're not saying the underlying architecture is worthless, we're saying we can't respond to an active, unresolved, nine-figure security failure with anything other than the lowest score we can honestly justify.
Given the active advisory, we think a "who this fits" breakdown would be misleading right now. Here's what matters instead, depending on your situation.
You generated a seed before August 20, 2026
Treat that seed as compromised regardless of your current firmware version. Generate a new seed on fully-patched firmware and move your funds as soon as possible.
You used independent dice rolls or a strong BIP-39 passphrase
Per Coinkite's own advisory, seeds generated this way were never at risk from this specific flaw, since neither method depends on the device's internal randomness.
You're holding a meaningful balance on any hardware wallet
Consider a multivendor multisig setup going forward, so a single vendor's future error can't single-handedly put your funds at risk.
You're considering a new Coldcard purchase
We'd wait for Coinkite to publish a complete, verified accounting of the vulnerability's scope and losses before treating this as a settled, safe purchase again.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the full entropy failure timeline, exactly how weak the affected seeds actually were, what to do if you're affected, and how this compares against the other wallets we've reviewed.
The entropy failure, timeline
| Date | Event |
|---|---|
| March 2021 | Firmware v4.0.1 ships, unintentionally rerouting seed generation to a weak, deterministic software PRNG |
| 2021 – July 2026 | Flaw remains undetected through roughly five years of subsequent releases and reviews |
| July 30, 2026 | Coordinated sweeps begin draining affected addresses; on-chain researchers spot the pattern |
| July 31, 2026 | Coinkite issues its first public advisory; scope expanded the following day |
| Early August 2026 | Independently-tracked losses climb past $100 million across thousands of addresses |
| August 20, 2026 | Fully-patched firmware ships: 5.6.1 (Mk4/Mk5), 1.5.1Q (Q); requires manual entropy input going forward |
| Ongoing | Independent analysis (Block) suggests the true vulnerability window may be wider than Coinkite's advisory states; no company-published victim count or loss total yet |
Updating firmware stops new weak seeds from being generated; it does nothing to protect funds already sitting behind a seed created before the fix.
How weak was weak?
| Device | Intended entropy | Actual effective entropy |
|---|---|---|
| Mk2 / Mk3 | 128 bits | As low as ~40 bits |
| Mk4 / Mk5 / Q | 128 bits | ~72 bits |
| Dice-roll or passphrase-protected seeds | 128 bits | Unaffected; never depended on device randomness |
A drop from 128 bits to 40-72 bits isn't a modest weakening; it moves a seed from "computationally unbreakable" to realistically brute-forceable with modern hardware.
If you own a Coldcard, do this
| Step | Action |
|---|---|
| 1 | Check whether your seed was generated before firmware 5.6.1 (Mk4/Mk5) or 1.5.1Q (Q) |
| 2 | If so, treat that seed as compromised, regardless of your current firmware version |
| 3 | Update to the fully-patched firmware before generating any new seed |
| 4 | Generate a new seed, ideally using Dice Rolls Only mode for maximum assurance |
| 5 | Move your funds to the new seed as soon as possible |
| 6 | Consider a multivendor multisig setup for meaningful balances going forward |
If you're unsure when your seed was generated, the safest assumption is to treat it as compromised and migrate regardless.
How it compares to other hardware wallets we've reviewed
| Wallet | Worst disclosed issue | Confirmed real-world losses? | Patchable? |
|---|---|---|---|
| Coldcard MK4 | 5-year entropy failure, weak seed generation | Yes; $100M+ confirmed | Only for future seeds, not past ones |
| Tangem Wallet | Laser fault-injection attack (lab-only) | None reported | No (but requires physical possession + ~$250K lab) |
| Trezor Safe 7 | Laser fault-injection attack on TROPIC01 (lab-only) | None reported | Yes, via dual-SE architecture |
| Ledger Flex | Recover controversy, two customer data breaches | No fund losses reported | Yes |
Every other disclosed issue in this series is either lab-only, requires extraordinary resources, or involves customer data rather than funds. Coldcard's entropy failure is the only one in this series with confirmed, large-scale, real-world financial losses.
This comparison needs a bigger caveat than usual. Most numeric review scores we found for the Coldcard MK4 were published between March and June 2026, months before the entropy failure was disclosed on July 31. Their scores reflect a device that, at publication time, had a genuinely strong reputation. We've included them for reference, clearly dated, but we don't think they tell you anything useful about whether to trust this device today.
Our score lands dramatically below the aggregated industry average, and that gap is the finding, not a disagreement. Five of six sources we located predate the July 2026 disclosure entirely; the one source we found that reflects it explicitly recommends against new purchases while the advisory remains active, a stance we share.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
If you generated it using the device's default on-device randomness before firmware 5.6.1 (Mk4/Mk5) or 1.5.1Q (Q), treat it as compromised regardless of what firmware you're currently running. Updating firmware only prevents new weak seeds; it doesn't fix seeds already generated.
Yes, per the expanded advisory: Mk2, Mk3, Mk4, Mk5, and Q are all affected, though the severity differs. Mk2/Mk3 seeds fell to roughly 40 bits of effective entropy; Mk4/Mk5/Q fell to roughly 72 bits. Both are far below the intended 128-bit standard and both are considered unsafe.
A firmware update in March 2021 (version 4.0.1) unintentionally rerouted seed generation away from the device's proper hardware random number generator toward a weaker, deterministic software process. The error went undetected for roughly five years.
Independent researchers have tracked losses climbing past $100 million across multiple waves since July 30, 2026, with different outlets citing figures between roughly $70 million and $116 million depending on when they published. Coinkite itself has not published its own verified victim count or total loss figure.
Per Coinkite's own advisory, yes. Seeds generated via independent dice rolls, or protected by a strong BIP-39 passphrase, were never at risk from this specific flaw, since neither method depends on the device's internal randomness.
We don't think this is a good time to make that decision. At least one source we found explicitly advises against new purchases while the advisory remains active, and we share that view until Coinkite publishes a complete, verified accounting of the vulnerability's scope and losses.
Most numeric reviews we found were published between March and June 2026, months before the entropy failure was disclosed on July 31. Their scores reflect a genuinely different, pre-disaster reputation and haven't been updated to reflect what's happened since.
It means splitting control of your funds across hardware wallets from different manufacturers, so that a flaw in any single vendor's device can't single-handedly compromise your holdings. Several sources recommend this specifically in light of this incident for anyone holding meaningful balances.
More Reviews
BitBox02 – Hardware Wallet Review
Score: 71/100. Swiss-made, open-source, and genuinely clever, but sources disagree on whether multisig still works.
Read MoreLedger Flex – Hardware Wallet Review
Score: 76/100. Best chip Ledger makes, but closed-source firmware, the Recover controversy, and two breaches still linger.
Read MoreNGrave Zero – Hardware Wallet Review
Score: 62/100. The "EAL7 wallet" is real, but the actual secure element underneath is a lower EAL5+ chip.
Read MoreTrezor Safe 7 – Hardware Wallet Review
Score: 78/100. Fully auditable TROPIC01 chip, undercut by a real Ledger Donjon laser fault-injection disclosure.
Read More



