Current-model and standards-sensitive answers verified on July 17, 2026. Legacy models are labeled where connector or firmware behavior differs.
How many seed words does it use?
COLDCARD generates either 12- or 24-word BIP-39 seeds. It can also import 12-, 18-, and 24-word BIP-39 seeds that other wallets may have created.
Can I have multiple wallets in each COLDCARD?
Yes. The active seed defines a wallet, and each exact BIP-39 passphrase used with that seed selects a different wallet. A forgotten or mistyped passphrase cannot be recovered from the seed, so preserve every passphrase and test its receive addresses before funding.
Current COLDCARD models also support Temporary Seeds and Seed Vault, plus BIP-85-derived duress wallets configured with Trick PINs. These features have different persistence and backup behavior. Read the relevant recovery instructions before treating any additional wallet as recoverable.
What's new in the Mk5 COLDCARD?
We have a complete table of differences here but the highlights: huge industrial design upgrades, including a new larger screen protected by Gorilla Glass, better NFC (tap), USB-C connector at bottom.
Is my trusted Mk4 obsolete now?
No. Mk4 remains supported and uses the same Mk firmware family as Mk5. Check the current release notes before assuming a feature applies to both models, because hardware-specific exceptions can exist.
Can I change my PIN?
Yes, the PIN is independent of the funds being held. It can be changed at any time as long as you have the original PIN.
BIP-39 passphrases cannot be changed because the text of the passphrase is part of the private key.
Which blockchains do you support?
Bitcoin and Bitcoin Testnet are supported. COLDCARD does not support altcoins.
Why does it have a MicroSD slot?
- The COLDCARD can backup the seed into an encrypted file.
- New transactions to be signed can be imported from the card.
- Public key data (XPUB, payment addresses) can be written onto the card.
- Firmware upgrades can be done by copying the new firmware file onto a card.
- A skeleton Electrum wallet can be created on the card which allows Electrum to "pair" with the COLDCARD without it ever connecting to a USB port.
- Multisig wallets can be joined using files transferred via cards.
How do I connect to a computer?
COLDCARD Q, Mk5, and Mk4 use USB-C. Mk3 and earlier models use Micro-USB. A cable is not included with current Q or Mk5 purchases.
USB data is not required for seed setup or for QR and MicroSD signing. If you choose a wired workflow, unlock the COLDCARD and enable the required USB function. The Q can also run from three AAA batteries; the Mk5 requires continuous USB-C power.
For model dimensions, power, and connectors, see COLDCARD Specifications. For current interface controls, see Settings.
Do I need to use MicroSD cards?
You don't have to use MicroSD cards with COLDCARD. It works over an optional USB data connection, and supported models can also use NFC to send and receive data. The Q additionally supports QR transfer. You can change transports later if your security needs change.
Where do I tap my phone for NFC?
The NFC antenna is in a different location on each model: the center of the Q screen, the top-right corner of the Mk5, and the keypad around the 8 key on the Mk4. The phone's own NFC antenna location also varies by model.
Hold the phone flat against the correct area and move it slowly until the devices connect. See NFC Tools for current model-specific instructions and diagrams.
What is PSBT?
A Partially Signed Bitcoin Transaction (PSBT) is the standard format defined by BIP 174 for passing transaction data among coordinators and signers. PSBT version 2 is defined by BIP 370.
COLDCARD reads and signs PSBTs created by compatible coordinator software. After review and approval on the COLDCARD screen, it can return a PSBT containing the new signature or a finalized Bitcoin transaction when finalization is possible.
See What is a PSBT? and Ready To Sign for the current workflow.
How do I backup?
Insert a MicroSD card, and go to Advanced/Tools > Backup > Backup System.
You'll be shown a 12-word password to be recorded, and have to pass a short quiz to prove you did that.
Then the file is saved as an AES-encrypted 7Z file on the MicroSD card.
We suggest keeping the password and file in different locations. The backup file is useless without the 12-word passphrase. Each backup will have a different backup phrase, and it has no relationship with the wallet seed words.
Backups can also be verified (checked for completeness) from the menu system.
Can COLDCARD use a BIP-39 passphrase?
Yes, COLDCARD supports BIP-39 passphrases.
This unlocks approximately 5.9 × 10197 more wallets based on your seed words.
Is there a factory reset?
There is no way to do a factory reset on a COLDCARD due to the secure elements. However, you can come close to a factory reset if you know the current Main PIN. To accomplish this you would do the following:
- Manually reset any current settings.*
- Wipe the file system:*
Advanced/Tools > Danger Zone > Wipe LFS - Delete all Trick PINs:
Settings > Login Settings > Trick PINs > Delete All - Destroy the seed:
Advanced/Tools > Danger Zone > Seed Functions > Destroy Seed - Change the Main PIN to something easy:
Settings > Login Settings > Change Main PIN
* Manually changing the settings, and wiping the file system are only necessary on firmware older than Q: 1.2.1Q and Mk4: 5.3.1. Newer firmware does this automatically during the seed destruction step.
How do I know desktop software is showing a payment address that truly is a deposit into this COLDCARD?
COLDCARD can display the payment address after it has independently calculated what it should be. Without this, it would be hard to make a "deposit" into the wallet of the COLDCARD without the possibility of someone misleading you.
In Electrum, click on the "eye" icon shown near the payment address. Check the value shown on the COLDCARD screen, compared to the value Electrum is showing.
This 'show address' feature is typically used online, with the COLDCARD connected on USB. To achieve a similar result offline, proceed as follows: choose Address Explorer from the main menu, and follow the instructions.
You can view ten addresses on the screen at a time (press 9 to see more), and also write out a CSV file with the first 250 addresses, onto the MicroSD card.
I found a previously-used COLDCARD online, should I buy it?
Do not rely on a used COLDCARD for secure key generation. A new COLDCARD from the factory or an authorized reseller arrives unused in its numbered tamper-evident bag. With a second-hand device, you cannot establish the same factory provenance or know how the device was handled or modified.
All legitimate resellers should be providing the COLDCARD unused and still in its original tamper-evident bag. As part of the first-use sequence, you will verify the bag number matches the factory bag number.
This random MicroSD card doesn't work!
There are so many MicroSD cards out there, it's not possible for us to test with them all. We have tested with all the cards we can find locally, and a few ultra-cheap ones from AliExpress. Still there will be some that won't work. If it's formatted as FAT32 and equal or smaller than 32GB it should work.
Please try another brand of card and if that fails, try one of our high quality true SLC cards, available in our store.
Do you support Segwit (Segregated Witness) on the COLDCARD?
Yes. We have comprehensive segwit support, and strongly recommend it, but do not require it. We will display Bech32 and P2SH (segwit wrapped) addresses appropriately.
The limiting factor is usually the wallet software generating the PSBT files for Coldcard to sign, and the BIP-32 key derivation paths involved.
For the Electrum wallet, we generate a PSBT file which will result in COLDCARD producing a segwit transaction every time (this does not relate to use of Bech32 or P2SH addresses, just the transaction's signatures).
Segwit is preferred since the cryptographic signature will cover exactly the payment details that the user has previewed on the COLDCARD screen.
In order to (safely) produce a non-segwit transaction, the COLDCARD must be provided enough data in the PSBT to completely verify the inputs and since a full copy of the transaction for all UTXO inputs is needed, the result is a much larger PSBT file. COLDCARD will refuse to sign a PSBT file where it does not have complete information on all inputs.
Is the secure element's crypto used for Bitcoin processing?
Although the ATECC608 (and the 508 used on older versions), do implement standard SHA-256, HMAC(SHA-256) and AES, we use those implementations only to secure the secrets that the chip holds. The same is true of the secondary SE (Maxim DS28C36B) on the Mk4.
Bitcoin signatures, and all other Bitcoin-specific operations are completed with the open-source software found in our open-source code. Ultimately the critical math is performed by the same libsecp256k1 code used in Bitcoin Core.
What kind of secure element is used?
The ATECC608 is a fixed-function secure element rather than a general-purpose CPU. Its operations and storage rules are defined by the chip hardware. The complete COLDCARD firmware is published here, and the PIN entry and secure-element paper describes how COLDCARD uses it.
The Q, Mk5, and Mk4 also use a second secure element, the Maxim DS28C36B. Secrets held by the two secure elements and main microcontroller jointly protect the encrypted seed, reducing dependence on any single component or chip vendor. The architecture and its assumptions are described in the dual secure elements paper.
When does the PIN attempt counter reset?
The PIN attempt counter resets to zero as soon as you enter the correct PIN code. The COLDCARD will always brick after 13 failed PIN attempts regardless of any other settings.
The number of failed PIN attempts can be reduced from 13 by navigating to: Settings > Login Settings > Trick PINs > Add If Wrong.
For more details see the Trick PINs guide.
What happens when I can't remember my PIN?
When you've failed 3 times or more, we warn you that you are in danger of bricking the device. The message encourages you to double-check the PIN entered, and even gives you a peek at what you entered, before submitting it as a login attempt.
Please note the COLDCARD will brick itself after 13 failed login attempts. There is no way to reset or recover the device.
Mk2 and earlier COLDCARDs will allow infinite attempts, but make it slower and slower each time, until at one point, you have to wait hours between each attempt.
Where does the entropy (randomness) come from?
It's very important the entropy (randomness) used to pick your master seed phrase is good quality. The COLDCARD primarily uses the hardware TRNG (True Random Number Generator), inside the main chip. This is a dedicated hardware subsystem that measures analog noise produced by a special transistor.
The TRNG from the MCU would be sufficient, but we also maintain a PRNG which is mixed (by XOR) into the TRNG output. That PRNG is seeded once at boot from the TRNG in each of SE1 and SE2. We limit use of the secure-element TRNGs because the protocol involved is complex and slow.
The 256-bit number from the TRNG⊕PRNG is then processed with SHA-256. A cryptographic hash produces a statistically uniform output when at least one input source retains sufficient unpredictable entropy; hashing cannot repair a completely predictable input.
During seed picking process, you have the option of "adding dice rolls" to increase the entropy and/or mitigate any possible manipulation. You can add as many rolls as you wish, and the entropy (about 2.5 bits per roll) will be added to the 256 bits of entropy already picked.
You may completely bypass the above seed picking method, and use just dice rolls if desired. This process is documented in great depth here on our docs and includes a number of different ways to verify our SHA256 math for yourself. We even sell a package of 100 tiny dice so you can roll 256 bits of your own entropy in a single toss.
If you do choose to roll your own dice, it is critical that you do it honestly and truly rely on how your dice fell. Do not press buttons arbitrarily or repeat the same roll a bunch of times. Humans are very bad at generating entropy!
Where do I learn all technical details?
You can read our secure element white paper, dual vendor secure element page, our online docs, and ultimately the COLDCARD source code.