Oleg Galeev, founder of OCryptoCanada

Oleg Galeev

Coldcard Q Review 2026: Why I No Longer Recommend It

Last updated October 3, 2026

Fact-checked by Canadian crypto tradersHow we testWe may earn a commission

Coldcard Q is not one I recommend today. My #1 pick: Trezor Safe 7Buy Trezor Safe 7

I can no longer recommend the Coldcard Q, or any Coldcard. In July 2026 it came out that a build error from 2021 made affected Coldcards create weak, guessable seeds, and attackers used that to empty thousands of wallets. Updating the firmware fixes new seeds but does not repair an old one. If you made your seed on an affected Coldcard, create a new seed on a different device and move your coins now.

  • Who is affected: Mk2 and Mk3 seeds made on firmware 4.0.1 to 4.1.9, and Mk4, Mk5 and Q seeds made before firmware 5.6.0 (Mk4 and Mk5) or 1.5.0Q (Q), unless you used 50 or more private dice rolls or a strong passphrase
  • What to do: generate a new seed on a different, trusted wallet and move your funds. My current picks are in best crypto wallets for Canadians, led by the Trezor Safe 7
  • Buying new: I do not link to Coinkite's store, and I do not suggest buying a Coldcard right now
Coldcard Q
Not recommended
  • PriceUSD 319 sale (USD 369 list) on the Coinkite store snapshot dated 2025-09-10, so confirm current price
  • Secure Elementdual Secure Elements from different vendors: Microchip ATECC608 and Maxim DS28C36B, plus the main microprocessor
  • ConnectionUSB-C, NFC (tap-to-sign and PushTx), 2 microSD slots, QR; USB and NFC data can be irreversibly blocked
  • BackupmicroSD or paper BIP-39; Seed XOR bundle sold; passphrase backup planning guide on site
Video: my Coldcard Q reviewWatch my video review
My Coldcard Q video review on the OCryptoCanada YouTube channel
Coldcard Q Crypto Wallet Review: made in Canada by Coinkite
The Coldcard Q, made in Canada by Coinkite.

What Happened To Coldcard Seeds In July 2026?

Here it is in plain terms. A hardware wallet makes your seed from random numbers, and the randomness is the whole security. Coinkite says a link-time build error in 2021 meant the setting meant to turn off the software random number generator did nothing, so affected firmware used MicroPython's software generator instead of the hardware one. That left roughly 72 bits of entropy, which can be guessed offline. Attackers regenerated keys and swept funds starting July 29 and 30, 2026. Coinkite says the devices were not hacked, the seeds were weak.

The first wave took 594 BTC (about USD 38 million) from roughly 500 wallets in 25 minutes. Galaxy Research later put the theft above 1,596 BTC (over USD 100 million) from about 7,300 addresses, and estimates vary by outlet and date. CoinDesk reports one Toronto victim lost 18.25 BTC. Coinkite published its own advisory, halted shipments and destroyed its remaining vulnerable inventory. I found no compensation programme.

Coinkite says Opendime, Tapsigner and Satscard are not affected.

What Should Coldcard Owners Do Now?

  1. Work out when your seed was made. Check the firmware you had when you generated it against the versions above. If you are not sure, assume it is affected.
  2. Skip the dice and passphrase exceptions unless you are certain. Coinkite says seeds made with 50 or more private dice rolls or a strong passphrase are not at risk. If you cannot say for sure that you did that, move the coins.
  3. Create a new seed on a different device. Updating the firmware does not repair an existing seed. Use another wallet, such as the Trezor Safe 7.
  4. Move your funds to the new wallet. Send a small test first, then the rest.
  5. Keep your records. The CRA says transfers between wallets you own are not a taxable disposition, and it wants records kept for at least six years. If you lost coins to theft, I have not verified how the CRA treats that, so ask an accountant. See my guide to crypto taxes in Canada.
Coldcard Q Quick Facts
DetailInfo
My VerdictNot recommended since the July 2026 seed generation flaw
Price Before The Shipment HaltUSD 369, or USD 319 on sale (US dollars, no CAD price listed)
CoinsBitcoin only
Secure ElementsTwo, from different vendors: Microchip ATECC608 and Maxim DS28C36B
Screen And Input3.2-inch LCD, full QWERTY keyboard
Air-Gap ToolsQR scanner with LED illumination, dual MicroSD slots, NFC
PowerUSB-C, or three AAA batteries. Batteries and USB cable are not included
FirmwareOpen and published on GitHub. Fixed for seed generation in 1.5.0Q, and 1.5.1Q now requires user-added entropy
SoftwareDesktop wallets such as Sparrow and Nunchuk. No phone app
AvailabilityCoinkite halted shipments after the flaw

I bought and tested the Coldcard Q with my own money, and I am keeping what I wrote about it, because the hands-on part is still true. It is made right here in Canada by Coinkite, and for a long time the Coldcard had the strongest reputation in the crypto community. That reputation is the reason this page changed.

Coldcard crypto wallet packaging
The Coldcard Q out of the box.

But they do not care about marketing. The packaging is basic, you will not find many YouTube reviews because they do not send free samples, and there are no referral links, so no surprise many YouTubers simply ignore this wallet. It will not make them any money. So I spent my own money to properly test the Coldcard Q. I said at the time that I absolutely hate one thing about it, and that its security was top-notch. Only one of those two sentences has aged well.

Fair warning, there are scam websites selling fake Coldcard wallets, and an old unit from a third party is a bad idea now for another reason. Do not buy a used or discounted Coldcard to save a few bucks.

What It Did Well

  • Fully air-gapped operation
  • Dual secure elements from two vendors
  • Dedicated QR scanner with LED
  • Open firmware on GitHub
  • Duress PIN and brick-me PIN
  • Dual MicroSD slots and battery operation

Why I Cannot Recommend It

  • Seed generation flaw: seeds made on affected firmware are guessable
  • Updating does not fix an existing seed
  • Over USD 100 million reported stolen, with no compensation programme found
  • Bitcoin only
  • Complex setup and no mobile support
  • Expensive, and Coinkite halted shipments

What Did The Coldcard Q Do Well?

This section describes the design as I tested it. None of it is a reason to buy now, but it is still my honest hands-on view.

Fully Air-Gapped Operation

The Q never needs to connect to your computer for normal use. You do everything through QR codes or MicroSD cards, which keeps your private keys offline. That design is good. It could not help with the weakness in how the seed was made, which happened before any of that mattered.

Dual Secure Elements

The Q uses two security chips, the Microchip ATECC608 and the Maxim DS28C36B, from two different manufacturers. Chips protect keys that exist. They cannot make a weak seed strong.

A Dedicated QR Scanner With LED

The scanner is built for reading Bitcoin transactions, and its LED light means it works in a bright office or a dim room. It scans PSBTs reliably, which makes air-gapped transactions practical for daily use.

Open-Source Firmware

Coldcard publishes its firmware on GitHub, and in crypto we live by "do not trust, verify." The July failure is a fair test of that idea: Coinkite's own account says the bug sat in public, open-source code for about five years before anyone caught it.

Duress PIN And Brick-Me PIN

With a duress PIN, if someone forces you to open your wallet, you open a fake wallet with a small balance. The Brick Me PIN goes further and destroys the device. These are unusual features aimed at high-risk situations that most wallets do not consider.

Dual MicroSD Slots, Key Teleport And Battery Operation

Two push-pull slots are more convenient than they sound. Key Teleport moves seeds, passwords or multisig transactions between Q devices by QR code or NFC. And the Q can run on three AAA batteries, so you can sign a transaction during a power outage.

QWERTY Keyboard And Large Screen

The full keyboard is a game-changer for entering BIP-39 passphrases, and the large colour screen means you can read the amount, address and fees clearly.

The Cons - What to Consider Before Buying
The Coldcard Q keyboard and screen.

What Are The Downsides Of The Coldcard Q?

The Seed Generation Flaw

This now outweighs everything else on the page. If you made a seed on an affected Coldcard, someone can regenerate it offline. Firmware updates fix new seeds only. That is why the advice is a new seed on a different device.

Bitcoin Only

This is the thing I hate the most. The Q supports only Bitcoin, with no Ethereum, no altcoins and no NFTs. If you have a diverse portfolio, you need additional wallets for your other assets.

A Steep Learning Curve

If you are coming from a simple mobile wallet, setup may feel overwhelming. You are dealing with two-part PINs, anti-phishing words, seed phrases and export procedures. The configuration of Sparrow and the air-gapped transfers took me about an hour.

Limited Software Compatibility

Sparrow and Nunchuk work great with the Q, but your options are limited compared to other wallets.

Price

At USD 369, or USD 319 on sale, the Q was one of the most expensive hardware wallets on the market. A card wallet like Tangem costs far less and does not carry this incident.

Size And No Mobile Support

The Q is noticeably larger than pocket-sized wallets like the Ledger Flex or the Trezor, and there is no phone app. You need a desktop computer with Sparrow for most operations. That was a deliberate security choice, and it is less convenient.

What Veterans Say

Some veterans had gripes even before July. Reddit's r/Bitcoin called the Q overkill for casual users, since features like duress PINs feel niche. Others questioned supply chain security despite the tamper-evident bag. Researchers have also pointed to physical attacks on secure element chips of this class, which are lab-style attacks needing possession of the device. Those worries were small next to what happened in July.

How Does The Coldcard Q Work?

What Coins Does Coldcard Q Support?
How the Q fits together.

The Q is a Bitcoin-only signing device that keeps your private keys offline in two secure elements. It is fully air-gapped and moves PSBTs by QR code or MicroSD card, so it never touches the internet. The screen shows transaction details, and you confirm with the keyboard. Your Bitcoin stays on the blockchain, and the Q just signs transactions offline.

How Did Setup Work On The Coldcard Q?

This is kept for people who already own a Q. If you are setting up a new seed, use the latest firmware: Coinkite says 1.5.1Q now requires you to add your own entropy (65 key presses, 50 dice rolls or 128 coin flips) when making a seed. Better still, make your new seed on a different wallet.

How to Use the Coldcard Q: Detailed Step-by-Step Guide
The Q during setup.

Step 1: Power On And Verify The Tamper Bag

Insert three AAA batteries or connect USB-C, then press and hold the power button on the top left for a second. Accept the terms, then check that the bag number on screen matches the number printed on your tamper-evident bag. If the numbers do not match, stop and contact support immediately.

Step 2: Set Up The Two-Part PIN

The Coldcard uses a two-part PIN to protect against evil-maid attacks and fake devices. You enter a prefix of 2 to 6 digits, and the device then shows two anti-phishing words unique to your device and that prefix. Write them down and check them every time you log in. If they do not match, stop. If they match, enter the suffix, also 2 to 6 digits. The Duress PIN opens a decoy wallet, and the Brick Me PIN permanently destroys the secure elements, so use it only when you would rather destroy access than reveal it.

Step 3: Create Your Seed Phrase

Choose New Seed Words, then 12 or 24 words. I strongly recommended 24, and I still would. At the time I wrote that the hardware random number generator was already cryptographically secure. That turned out to be wrong for affected firmware, which is the whole story of this page. Write the words on the provided card, or stamp them on a metal backup, and never photograph them or store them digitally. Mixing in your own dice rolls was always an option, and it is now effectively required.

Step 4: Export To Sparrow Wallet

The Coldcard keeps your private keys, but it cannot check your balance alone. You give Sparrow your public keys so it can show your balance and build unsigned transactions. QR method: from the main menu, go to Advanced/Tools, then Export Wallet, choose Sparrow or Generic JSON, then press the QR key. In Sparrow, choose File, New Wallet, Airgapped Hardware Wallet and scan the code. MicroSD method: save the export to a card and import it into Sparrow. You are sharing only the extended public key, never your seed words.

Step 5: Receive And Send Bitcoin

To receive, use the Receive tab in Sparrow and verify the address on the Coldcard through Address Explorer. When you buy from a registered Canadian exchange such as NDAX, generate the address in Sparrow first. To send, create the transaction in Sparrow, show the PSBT as a QR code and scan it with the Coldcard. Check the amount, fee, recipient and change on the Coldcard screen before you press Enter, then scan the signed QR back into Sparrow and broadcast.

Step 6: Security Habits

  • Check the green security light when it boots. A red light means something is wrong.
  • Verify the anti-phishing words every login.
  • Keep the firmware up to date, and update before you generate a seed.
  • Store seed words offline on paper or metal, and keep your PIN and seed backup in separate places.

Is The Coldcard Q Safe?

No, not for a seed made on affected firmware. The air-gapped design, the two secure elements and the duress PIN all work as described, but a seed that can be guessed is not protected by any of them. Coinkite fixed the firmware on July 30 and 31, owned the problem publicly and published a chronology of past security fixes, which counts for something. A fuller post-mortem had not appeared as of October 3, 2026, I found no compensation programme, and updating does not help existing seeds. For a coin holder, that is the part that matters.

How Much Does The Coldcard Q Cost In Canada?

Before the flaw, Coinkite's store listed the Q at USD 369, or USD 319 on sale, with no CAD price, so conversion and shipping added to the cost. Coinkite has since halted shipments, so I do not link to its store and I do not give you a current price to chase. If you want a wallet today, a lower-priced one with a clean record is a better use of the money.

How Does The Coldcard Q Compare With Ledger And Trezor?

Coldcard Q Compared With Ledger And Trezor
FeatureColdcard QLedger FlexTrezor Safe 5
CoinsBitcoin onlyMulti-coinThousands of coins and tokens
Price (Vendor's USD)369 (319 on sale), shipments haltedCheck Ledger's site129 (CAD 199)
HardwareQWERTY keyboard, QR scanner, dual MicroSD, NFC, AAA batteriesE Ink touchscreen, Bluetooth, USB-C, NFCColor touchscreen, USB-C, microSD slot
SecurityTwo secure elements, open firmware, air-gapped. July 2026 seed generation flawSecure element, closed-source OSEAL6+ secure element, open-source architecture
SoftwareSparrow or Nunchuk, desktopLedger LiveTrezor Suite

See my Trezor Safe 7 review, the Trezor Safe 5 review and the Ledger Flex review for the wallets I do recommend.

Should You Buy A Coldcard Q Or Mk5?

Neither. Coinkite's two current models, the Q and the Mk5, are both Bitcoin only with the same dual secure elements and open firmware, and the seed flaw touched Mk2, Mk3, Mk4, Mk5 and Q alike. I tested the Q, so everything above is about the Q, and my verdict covers the family.

Who Should Still Use A Coldcard?

Only people who already own one and made their seed with enough dice rolls or a strong passphrase, or who have already moved to a fresh seed made on the fixed firmware. Everyone else, move on. If you are starting out, begin with a registered exchange from my best crypto exchanges for Canadians list and a simpler wallet like the Trezor Safe 7 or the Trezor Safe 5.

What Did I Dislike About The Coldcard Q From Experience?

As of June 2025, Coinkite introduced CCC (Coldcard Co-Signing Key),
After my test of the Coldcard Q.

The Q is a well-built device, but it was never flawless. The Bitcoin-only focus is a dealbreaker if you trade altcoins, since it leaves my Ethereum and NFTs elsewhere. The price feels steep for a single-asset wallet. The setup is technical, and the calculator-like design is bulky compared with sleeker wallets. There is no internal battery, so you carry AAA batteries or a USB-C cable. The lack of tax software integration means manual CRA tracking. Customer support can lag during busy periods, in my experience and in what I read from other users, and Coinkite's helpdesk and YouTube tutorials are detailed and helpful.

Final Thoughts: Why I No Longer Recommend The Coldcard Q

I have tested over 20 hardware wallets on my channel, and I used to say nothing came close to Coldcard's security. I cannot say that any more. A random number bug that sat unnoticed for years let thieves empty thousands of wallets, and I cannot honestly point you to a company that has not yet fully explained it or compensated the people hurt. That is my opinion, and the facts above are why.

The duress PIN that opens a fake wallet and the brick PIN that destroys the device were not gimmicks, and physical crypto robberies are real. But a strong lock on a door with a guessable key does not help. If you own a Coldcard, make a new seed on a different device and move your funds. If you are shopping, see the best crypto wallets for Canadians and the Trezor Safe 7.

What Changed For The Coldcard Q Recently?

  • The seed generation weakness and mass theft came to light. Coinkite shipped fixed firmware for every model on July 30 and 31 (Mk3 4.2.0, Mk4 and Mk5 5.6.0, Q 1.5.0Q).
  • Coinkite published its account of how the bug arose, a link-time build error that left the software random generator active, and launched a public security chronology.
  • Coinkite shipped 5.6.1 and 1.5.1Q with further security fixes, and they now require user-added entropy when making a seed.

Has Coinkite Had Security Problems?

Here is every documented security issue I could confirm for Coinkite (Coldcard), newest first, with what it meant for owners and what was done about it.

  • : Follow-up security fixes in 5.6.1 and 1.5.1Q. A three-week review and outside reports led to fixes for a staged-PSBT swap by a compromised USB host, USB staged-memory access, multisig duplicate-key enrolment, dice entry counting held-key repeats as rolls, malformed QR data, a callgate bounds check, SIGHASH_SINGLE defaults and RNG error recovery. Some of these could affect signing safety on USB-connected or multisig setups; no public thefts tied to them were found. Shipped in Mk4/Mk5 5.6.1 and Q 1.5.1Q, which also now require user-added entropy when making a seed (65 key presses, 50 dice rolls or 128 coin flips). (source)
  • : Customer data retention reversal. After the incident Coinkite paused its 120-day automatic blanking of customer records, so emails and countries are kept for legal reasons. Customers who bought expecting records to be wiped now have data retained; opt-out to existing policy offered via support form. Temporary, with standard blanking to resume when legally permitted. (source)
  • : Coinkite's account of how the bug arose, and who else saw it. Coinkite published that a link-time build error meant the setting meant to disable the software PRNG did nothing, and that its own AI-assisted code review before the exploit had not caught it. Block's engineers independently analysed the flaw. Explains root cause: no intentional fallback, but also no one caught it for about five years in public, open-source code. Coinkite launched a public security chronology and promised a fuller post-mortem; none was found as of October 3 2026. (source)
  • : Seed-generation RNG weakness and mass theft of funds. A 2021 build error made seed generation use MicroPython's software PRNG instead of the hardware random generator, so seeds made on affected firmware were guessable offline. Attackers regenerated the keys and swept funds, starting July 29-30 2026. Coinkite says the devices were not hacked; the weak seeds were. Mk2/Mk3 seeds made on firmware 4.0.1 to 4.1.9 and Mk4/Mk5/Q seeds made before 5.6.0 / 1.5.0Q (about 72 bits of entropy) are at risk unless 50+ private dice rolls or a strong passphrase were used. First wave: 594 BTC (about $38M) from roughly 500 wallets in 25 minutes. Galaxy Research later put theft above 1,596 BTC (over $100M) from about 7,300 addresses; CoinDesk reports one Toronto victim lost 18.25 BTC. Estimates vary by outlet and date. Fixed firmware for every model on July 30-31 (Mk3 4.2.0, Mk4/Mk5 5.6.0, Q 1.5.0Q, Edge 6.6.0X/6.6.0QX). Updating does NOT repair an existing seed: affected users must generate a new seed and move funds. Coinkite halted shipments, destroyed its remaining vulnerable inventory and said it accepts that hard questions are owed; no compensation programme was found. (source)
  • : Legacy input-amount spoofing fixed. A researcher credited as Damir showed witness-UTXO-only PSBT data could be used where a non-SegWit input was expected, spoofing the input amount. Input-amount spoofing risk; no public proof of concept or loss report was found. Fixed in Mk4/Mk5 5.5.1 and Q 1.4.1Q. (source)
  • : Delta PIN allowed private-key recovery from two signatures. Karma-X's Nathan Landon reported that the Delta PIN feature repeatedly signed a fixed digest, letting someone with two signatures recover the full private key. Affected users of that feature on Mk4/Mk5 and Q; no public theft reported. Coinkite says a full affected-version matrix was not published. Coinkite patched the same day and shipped firmware 5.4.4 and 1.3.4Q the next day. (source)
  • : Mk4 secure element 2 (DS28C36) double-laser readout. Ledger Donjon researchers bypassed read protection on part of the DS28C36 chip's memory with two laser faults. Partial secret material exposed; complete seed recovery not demonstrated because Mk4 also needs the other chip and the MCU. Date is month-level. Coordinated with Coinkite and the chip vendor; Coinkite published a response, no retrofit. (source)
  • : Multisig xpub substitution. Shift Crypto and Hugo Nguyen showed Coldcard did not require one registered multisig key to be its own, so a compromised coordinator could swap in attacker keys. Remote theft of multisig funds was possible through a compromised coordinator; fixed before publication. Fixed in firmware 3.2.1. (source)
  • : Mk3 double laser plus MCU extraction chain (research, 2021 SSTIC; completed Mk3 chain shown 2023). Ledger Donjon showed two laser faults can read ATECC608A secrets and, with a separate attack on the STM32 chip, recover a seed. In 2023 it recovered one of three seeds on full Mk3 challenge units. Specialist lab attack needing physical possession; no public theft evidence. The date is year-only in Coinkite's chronology, set here to 2021-01-01 as a placeholder for year. No Mk3 retrofit; Mk4 split secrets across three chips from two vendors. (source)
  • : Testnet and mainnet isolation bypass. Shift Crypto (BitBox) showed a real mainnet spend could be displayed and signed while the Coldcard was in testnet mode. A user could unknowingly sign a real mainnet payment while believing they were testing. Fixed in firmware 3.2.1, which moved testnet into the Danger Zone with an explicit warning. (source)
  • : BIP-143 input-amount class of attack. A malicious PSBT and signing sequence could show misleading input amounts and redirect value to miner fees (a cross-wallet issue). Fee-burning risk if a user signed a hostile transaction file; no public Coldcard loss found. Coinkite blocked the reported attack class in firmware 3.1.4. (source)
  • : Ledger Donjon laser fault attack on Mk2 secure element. Ledger Donjon used laser fault injection on the ATECC508A chip to read a protected slot and, combined with MCU data, recover the PIN. Needs physical possession, chip decapsulation and specialist lab gear; no public theft evidence. Applies to Mk1/Mk2. No Mk1/Mk2 retrofit possible; Mk3 had already changed secure element. Coinkite published a response. (source)
  • : Factory-reset supply-chain path. TheCharlatan showed modified firmware could wipe the PIN and restore the 'virgin device' flow while keeping the bag number, so a tampered unit could look unused. Buyers of intercepted or second-hand units could be fooled; first-use firmware verification is the defence. Coinkite stressed firmware verification and first-use checks; the immutable bootloader was not retrofitted and the mitigation is described as disputed. (source)
  • : Multisig change-script parser confusion. Researcher Dmitry Petukhov showed appended script operations could make an attacker-controlled multisig output pass as the wallet's own change. Multisig signing before firmware 3.0.6 could have sent funds to an attacker; Coinkite reported no evidence of exploitation. Fixed in firmware 3.0.6, which simplified parsing and displayed all change outputs. (source)
  • : Change-path ransom and receive-path display manipulation. Researcher TheCharlatan showed a malicious coordinator could send change to an unreachable deep derivation path, and that a crafted path string could hide its real tail on screen. Firmware before 3.0.2; funds could be made practically unrecoverable or misdirected if a user signed a hostile file. Fixed in firmware 3.0.2, which constrained and validated derivation paths and corrected display parsing. (source)
  • : OLED power side channel (CVE-2019-14356). Researcher Christian Reitter found that power use of the row-based OLED display on Mk1 and Mk2 could leak partial screen contents, such as PIN entry or seed words. Mk1/Mk2 before firmware 2.1.2; a lab-style side channel, no public theft evidence. Coinkite shipped firmware 2.1.2 masking PIN entry and adding noise while seed words show; severity was disputed. (source)

Independent audits: Lazy Ninja (paid private reviewer) (Mar 14, 2022): Pre-release review of Mk4 PIN derivation, attempt limiting and random number generation; key recommendations adopted before Mk4 firmware 5.0.0.; Enterprise AI review run by Coinkite (Jun 26, 2026): 85 candidate findings triaged by Coinkite; one real Delta Mode path and some edge cases fixed, review closed June 26 (reported by Coinkite, not independently verified)..

How Does Coldcard Q Compare?

Coldcard Q Against Close Alternatives, Checked October 2026
WalletPriceConnectionSecure Element
Coldcard QUSD 319 sale (USD 369 list) on the Coinkite store snapshot dated 2025-09-10, so confirm current priceUSB-C, NFC (tap-to-sign and PushTx), 2 microSD slots, QR; USB and NFC data can be irreversibly blockeddual Secure Elements from different vendors: Microchip ATECC608 and Maxim DS28C36B, plus the main microprocessor
Trezor Safe 7USD 249Bluetooth (open-source encrypted), USB-C to USB-C cable, Qi2 wireless chargingTROPIC01 (auditable) plus NDA-free EAL6+ Optiga secure element plus STM32U5 microcontroller: three chips from three vendorsFull comparison
Tangem Wallet2-card set USD 54.90; 3-card set USD 69.90; Family Pack USD 129.80; Ring and 2 cards USD 160; Pro Kit USD 180 (prices shown in USD to a US visitor)NFC only (no battery, no cable)EAL6+ certified chip, Samsung-developed per Tangem; IP69KFull comparison
Ledger FlexUSD 249 and CA$369 on the Canadian storefront; free shipping, usually ships within 24 hoursBluetooth (BLE 5.2), NFC, USB-CST33K1M5 Secure Element, Common Criteria EAL6+Full comparison

Frequently Asked Questions

Do You Still Recommend The Coldcard Q?

No. After the July 2026 seed generation flaw and the thefts that followed, I cannot recommend the Coldcard Q or any Coldcard. I do not link to Coinkite's store.

What Was The Coldcard Seed Generation Flaw?

Coinkite says a 2021 build error made affected firmware use a software random number generator instead of the hardware one, leaving about 72 bits of entropy. Attackers regenerated those seeds and swept funds from July 29 and 30, 2026.

Which Coldcard Seeds Are Affected?

Mk2 and Mk3 seeds made on firmware 4.0.1 to 4.1.9, and Mk4, Mk5 and Q seeds made before firmware 5.6.0 or 1.5.0Q, unless 50 or more private dice rolls or a strong passphrase were used.

Does Updating The Coldcard Firmware Fix My Seed?

No. Updating protects new seeds only. If your seed was made on affected firmware, create a new seed on a different device and move your funds.

How Much Bitcoin Was Stolen From Coldcard Users?

The first wave took 594 BTC (about USD 38 million) from roughly 500 wallets in 25 minutes. Galaxy Research later put the total above 1,596 BTC (over USD 100 million). Estimates vary by outlet and date, and CoinDesk reports a Toronto victim lost 18.25 BTC.

What Is A Safer Hardware Wallet For Canadians?

My current picks are in my best crypto wallets for Canadians list, led by the Trezor Safe 7 and the Tangem wallet.

Is Moving Bitcoin To A New Wallet Taxable In Canada?

The CRA says transfers between wallets you own are not a taxable disposition. Keep records for at least six years.

Does The Coldcard Q Support Ethereum Or Altcoins?

No. The Coldcard Q is Bitcoin only.

See my top 7 crypto wallets for Canadians, with prices and security features

See Full List

Author

Oleg Galeev, founder of OCryptoCanada

Oleg is a Canadian citizen & crypto expert who has been trading since 2016. He started out with Coinbase, Kraken and Peer-to-Peer exchanges. After some time, centralized exchanges started charging crazy fees to their users.

He decided to review different crypto exchanges that operate in Canada and start a Youtube channel in order to educate Canadians on what kinds of things are going inside each one while giving them unbiased advice. On top of that, Oleg also has experience with NFT, airdrops, and crypto staking and he is constantly checking on new crypto assets.

His writing has been featured in popular Canadian media sources such as Toronto Sun and Ottawa Citizen. 

  • Reviews

Discover Your Perfect Canadian Crypto Exchange!