Wallet Coverage

Coldcard (Coinkite)

MODERATE RISK
Review opened July 31, 2026 · Updated August 13, 2026 · Framework: LISR v1.0 + QRR

Scored September 1, 2026 after a 32-day review. The review opened July 31 and was held while the evidence base moved. The notice published during that period, the scoring deadline set in advance on August 20, and the reasoning behind the score are all on the changelog.

At a Glance

MODERATE RISK
LISR — Custody Risk
4.7
MODERATE RISK
/ 10.0 · higher = higher risk
Review
32 days open
Opened Jul 31 · scored Sep 1, 2026
0.0 — LOW RISK 10.0 — CRITICAL RISK
What this score covers

THIS SCORE ASSESSES THE DEVICE AS IT SHIPS ON FIRMWARE 5.6.1 / 1.5.1Q. It does not describe the risk carried by a seed generated on affected firmware. Coinkite states twice that installing the update does not make an existing vulnerable seed safe, and that full user-driven migration to a new seed is required. A holder in that position faces a materially different and higher exposure than this score represents. Refer to Coinkite's advisory for affected models and firmware versions.

Key Risk Flags

  • CRITICAL: Seed generation entropy collapsed to as low as 40 bits for five years (2021-2026), enabling private key compromise and fund theft from thousands of addresses
  • SYSTEMIC: Critical defect survived five years undetected in publicly readable, source-available code that had passed external security audit, evidencing QA and review process gaps
  • DISCLOSURE-HANDLING: Bitcoin developer James O'Beirne publicly states he raised randomness concerns in May 2025 and received argument from absence rather than technical rebuttal, fourteen months before exploit
  • REMEDIATION BURDEN: Existing vulnerable seeds require full user-driven migration; firmware upgrade insufficient; customer bears complete remediation responsibility
  • LEGACY RISK: Thousands of vulnerable seeds remain in field; users must self-identify and migrate with high-friction, high-risk process
  • LICENSE RESTRICTION: Commons-clause license since 2020 restricts redistribution despite source availability, limiting fork-based community response to defects

Mitigating Factors

  • EXEMPLARY POST-INCIDENT DISCLOSURE: Six substantive public posts July-August 2026, public Security Status page with machine-readable status.json, SECURITY.md added to repository, external researchers credited by name
  • RIGOROUS POST-FIX ARCHITECTURE: Post-remediation entropy generation among most rigorous in category—mandatory user input (65 keypresses/50 dice/128 coin flips), triple hardware RNG sources (STM32 TRNG, SE1, SE2), integrated self-tests, boot-time RNG path verification with device halt on failure
  • HONEST LIMITATIONS DISCLOSURE: Manufacturer transparently states testing 'does not independently prove the quality of every output,' and twice states 'installing this update does not make an existing vulnerable seed safe'
  • COMPREHENSIVE REMEDIATION SCOPE: Firmware 5.6.1/1.5.1Q addresses not only RNG defect but also PSBT modification detection, dangerous SIGHASH flags, USB download security, Delta Mode restrictions, and passphrase-wallet backup improvements
  • SUSTAINED POST-INCIDENT REVIEW: Three weeks of review including AI-assisted analysis by Kimi and other frontier models after defect known, demonstrating commitment to comprehensive remediation

Category Breakdown

CategoryScoreRisk
Security Architecture4.8
Firmware Integrity4.2
Supply Chain Risk3.5
Key Management6.2
Operational Security4.0
Recovery Risk5.8

Category breakdown reflects several structural risk properties assessed under the LISR framework. Weights and methodology are proprietary.

Analyst Notes

Coldcard presents a sharp paradox: post-remediation architecture is among the most rigorous in the hardware wallet category, yet a five-year undetected catastrophic entropy failure in the seed generation path evidences a systemic quality assurance gap. The defect was not exotic—it was a build configuration error in publicly readable code that had passed external audit, suggesting review processes lacked sufficient depth or adversarial focus on the root of trust. The reported May 2025 warning from James O'Beirne, if accurate, constitutes a disclosure-handling finding: answering a randomness concern with an argument from absence rather than technical rebuttal fourteen months before exploitation represents a missed opportunity for early remediation. Post-incident disclosure behavior was exemplary—transparent, sustained, technically detailed, with honest limitation statements and external researcher credit. The manufacturer correctly places remediation burden on users, stating twice that upgrade alone is insufficient. Thousands of vulnerable seeds remain in field, and migration is high-friction. The commons-clause license since 2020, while preserving code verifiability, restricts community fork-based response. Calibrated against index: significantly higher risk than BitBox02 (3.4) due to realized key compromise and five-year detection gap; higher than Trezor/Passport/Ledger (4.0-4.5) due to severity and duration of root-of-trust failure; lower than SafePal/ELLIPAL/Tangem (6.2-6.8) due to strong post-fix controls, air-gap model, and transparent disclosure. Score reflects the systemic nature of the QA gap, the realized harm, and the legacy risk population, balanced against architectural strengths and disclosure integrity. SCOPE: this score assesses the device as it ships on firmware 5.6.1/1.5.1Q. It does not describe the exposure of a seed generated on affected firmware, which remains vulnerable until migrated regardless of the firmware now installed.

Why the review was opened

On July 30, 2026, a large volume of Bitcoin was swept from single-signature addresses in a narrow window, reported by on-chain analysts. Coinkite subsequently issued a security advisory concerning seed entropy generation on affected Coldcard firmware and published a technical backgrounder. Independent technical analysis has been published by Block's Bitkey team and by Galaxy Research. The reported figures have been revised upward repeatedly as analysis has continued; refer to those sources for current numbers.

Coinkite has stated that its investigation is ongoing and has not confirmed that the entropy issue caused the observed movement of funds. Security researchers have identified it as the most plausible explanation. Linkmerica records that distinction rather than collapsing it.

For affected firmware versions and device models, refer to Coinkite's own advisory and technical backgrounder. That scope has been revised during the disclosure and is the vendor's to state, not ours to restate.

Why no score is being published today

A LISR score is a deterministic assessment produced under a versioned methodology against a stable evidence base. Coinkite's investigation is ongoing, the scope of affected devices has been revised upward since initial disclosure, and the loss figures have moved substantially within 48 hours. Publishing a score against facts still in motion would produce a number that reflects a news cycle rather than an assessment, and would already require correction.

The review will complete when the evidence base is stable. The score, when published, will be dated, versioned, hash-verified, and will reference the disclosure that opened this review. Linkmerica scores move in both directions on evidence: one hardware wallet's risk rating was raised within 48 hours of an unpatchable fault-injection disclosure this month, and another's was lowered when the manufacturer shipped production post-quantum firmware.

For affected users

Follow Coinkite's official guidance directly. Linkmerica does not publish operational security instructions, and will never ask any user for a seed phrase, private key, or wallet access under any circumstances.

All Wallet Scores Methodology Changelog

Linkmerica is a trade name of CASPO LLC. LISR scores and research are for informational purposes only and do not constitute financial or investment advice. This notice is based on publicly available information as of July 31, 2026.