Hardware Wallet Comparison
Coldcard Q vs. Mk5
Same security model. Same open-source codebase. Same sovereignty. Two different workflows.
The choice comes down to form factor, signing methods, and how you use a signing device on a regular basis.
Last updated: July 2026. Product facts checked against official COLDCARD documentation on July 20, 2026.
Short answer: Which Coldcard should I buy?
Coldcard Q and Coldcard Mk5 share the same open-source codebase, security architecture, and Bitcoin self-custody features. The decision is about form factor and signing workflow, not security.
The Q adds a full QWERTY keyboard, built-in QR scanner, large color display, and battery power for untethered operation. QR signing means no physical media to manage, as PSBTs are scanned directly from a coordinator screen. It is the better fit for regular signers, passphrase users, and anyone coordinating a multisig wallet.
The Mk5 is credit-card sized with MicroSD and NFC signing. NFC tap-to-sign works naturally with compatible mobile wallet apps. At a lower price point, it is also a solid choice for multisig setups that require multiple devices.
Three things to consider when choosing your Coldcard
The below considerations provide a framework for deciding which device fits your workflow.
Signing workflow
Do you prefer signing air-gapped transactions with QR codes, swapping MicroSD cards, or tapping with NFC to a mobile wallet? The Mk5 covers MicroSD and NFC signing, whereas the Q adds support for QR code signing. Your transaction frequency and wallet setup may lead you to a preferred method.
Keyboard and display
Do you enjoy a full QWERTY keyboard and large color screen, or a compact numeric interface? Frequent signers and passphrase users will feel this difference most. The Q's display and full keyboard reduce friction across every session, while the Mk5's numeric keypad is compact and capable.
Portability and power
Does your signing device need to travel with you, fit in a pocket, or stay discreetly out of sight? The Mk5's credit card-sized form factor is built for portability. If your device lives on a desk, the Q's larger form is designed for ergonomics and can run on three AAA batteries or a USB power bank.
Coldcard Q vs. Coldcard Mk5
More information can be found on their respective product pages. Select any feature below for a plain-language explanation.
Swipe to compare →
| Feature | Coldcard Q | Coldcard Mk5 |
|---|---|---|
| Form Factor and Signing Workflow | ||
QR code scanner (air-gap via QR) | ||
| A built-in camera enables QR-encoded PSBT import and export. The signing workflow becomes: scan the unsigned transaction from your coordinator, review and approve on-device, display the signed transaction as a QR for the coordinator to scan back. No cable and no physical media required. An alternative to MicroSD and NFC for fully air-gapped transaction signing. | ||
Full QWERTY keyboard | ||
| A physical QWERTY keyboard enables direct, easy text entry on the device. Entering passphrases, reviewing transaction labels, and navigating text-heavy menus become significantly faster. Without a full keyboard, text entry requires cycling through characters on a numeric grid, which is functional but slower for anything longer than a few characters. | ||
Large color display | ||
| A large color display provides enough screen real estate to show full transaction details, complete addresses, and multisig signing summaries at a comfortable reading size. A smaller monochrome screen conveys the same essential information but requires more scrolling and offers less visual context for careful verification. | ||
Battery powered | ||
| Three AAA batteries let the device operate without any connection to a wall outlet or computer. This enables signing sessions in power-isolated environments where no mains power is present or desired. A USB power bank also works. | ||
Pocketable form factor | ||
| A credit-card sized form factor fits in a wallet, pocket, or travel bag without drawing attention. Compact size matters for users who carry their signing device with them, take it to a secure location to sign, or treat discreet portability and storage as part of their security model. | ||
NFC tap-to-sign | ||
| NFC enables tap-to-sign with compatible mobile wallets such as Nunchuk. A brief tap transfers the unsigned transaction to the signing device, which approves and returns the signed result over the same connection. No cable or physical media is required, making it particularly well-suited to mobile-first signing workflows. | ||
MicroSD slots | ||
| A MicroSD slot enables air-gapped PSBT signing by transferring the unsigned transaction on a physical card rather than over a wireless or wired data connection. The slot also stores encrypted wallet backups. The Q has two slots, which can reduce card swapping during backup, clone, and file-transfer workflows. | ||
USB-C | ||
| USB-C serves as a power input and enables optional wired connection to a host computer. When connected via USB, the device can appear as a virtual disk for PSBT file transfers, or connect directly to compatible coordinator software. | ||
| Multisig and Advanced Features | ||
Key Teleport | ||
| Key Teleport is an encrypted Coldcard Q feature for transferring seeds, notes, passwords, full backups, or multisig PSBTs between Q devices over BBQr. It uses ephemeral keys and requires transfer passwords to be shared separately from the QR channel. | ||
Secure notes and passwords | ||
| The Coldcard Q can function as an encrypted password manager and secure text vault for storing sensitive information alongside your private keys. All entries are protected by AES-256-CTR encryption linked to your master seed and are automatically included in your standard device backups. | ||
Multisig coordinator (on-device) | ||
| Both devices can create, import, verify, and manage multisig wallet configurations. The Q's larger screen and full keyboard make reviewing cosigner details and navigating setup more ergonomic. The Mk5 supports the same core workflow through its smaller screen and numeric keypad. | ||
PSBT (BIP-174) | ||
| PSBT is the standard format for passing unsigned transactions between coordinator software and a signing device. It is the foundation of COLDCARD's air-gapped signing workflows and is supported by many compatible coordinators. | ||
PSBT v2 (BIP-370) | ||
| PSBT v2 is an updated format with additional fields for improved coordinator workflows and better support for complex spending conditions. | ||
Taproot (BIP-341) | ||
| Taproot support is available for both devices in COLDCARD Edge firmware. Edge is an advanced release channel; confirm the current release notes and coordinator compatibility before using it. | ||
Miniscript (BIP-379) | ||
| Miniscript support is available for both devices in COLDCARD Edge firmware. Miniscript provides a structured way to express and analyze Bitcoin spending policies, but the complete wallet and recovery configuration still has to be preserved. | ||
| Security Fundamentals | ||
Bitcoin-only firmware | ||
| This firmware implements only the Bitcoin protocol. Every additional asset requires additional signing code, adding audit complexity and potential attack surface. A single-purpose codebase is smaller, simpler, and easier to verify. | ||
Open-source firmware | ||
| The firmware source is public and the repository documents reproducible builds. Rebuilding a release and comparing it with the published binary lets technical users check that the binary corresponds to the reviewed source; it does not prove the source is free of defects. | ||
Dual secure elements | ||
| Two secure elements from different vendors and secrets held by the main microcontroller jointly protect the encrypted seed. The design reduces dependence on any single component or chip vendor; its documented goal is to require compromise of all three components plus the PIN to recover the seed. | ||
Anti-phishing protection | ||
| After the PIN prefix is entered, COLDCARD displays two device-specific anti-phishing words. Check that they match the words recorded during setup before entering the PIN suffix; unexpected words are a reason to stop. | ||
On-screen destination verification | ||
| The device displays the destination address on its own screen before signing, independent of the connected computer. Careful on-device review can detect clipboard malware and address substitution before approval. | ||
| Trick PINs | ||
Self-destruct PIN | ||
| A Trick PIN can be configured to wipe the seed or irreversibly brick the device. These actions are destructive and should be configured and tested only after the recovery material is complete. | ||
Duress / decoy wallet PIN | ||
| A secondary PIN opens a decoy wallet with a small balance, designed to look convincing under pressure. The real wallet stays hidden, providing plausible deniability under physical coercion. | ||
Countdown PIN | ||
| A Trick PIN can trigger a countdown, optionally combined with wiping or bricking. COLDCARD also has a separate Login Countdown that delays access after the correct Main PIN; review the documented limitations before relying on either behavior. | ||
| Seed Management | ||
BIP-85 child seeds | ||
| Independent child seeds are derived from a single master seed. Each child works on its own device without exposing the master, enabling a clean key hierarchy from one securely stored root. | ||
Seed XOR | ||
| A seed can be split into two or more XOR-encoded parts, each individually useless. All parts are required to reconstruct the original seed. This enables geographic seed splitting without the recovery complexity of Shamir's Secret Sharing. | ||
User-contributed entropy | ||
| Independently generated entropy can be contributed during key generation, reducing sole reliance on the device's hardware RNG. Weak or patterned human input does not improve security, so follow the documented dice-roll process. | ||
| Supply Chain and Physical Transparency | ||
Numbered tamper-evident bag | ||
| Each unit ships in a tamper-evident bag with a unique bag number recorded in the device at the factory. Inspect the bag before opening and confirm that its numbers, tear-off tab, and the number shown by the device agree. | ||
Viewable internal electronics | ||
| A clear case helps you inspect the visible components for unexpected additions or modifications. Visual inspection is one supply-chain check; it cannot prove that a device was never altered. | ||
| Pricing | ||
| Price (USD) | $249.21 store.coinkite.com | $169.94 store.coinkite.com |
What makes the Coldcard Q different from the Mk5?
The Q is Coldcard's most ergonomic and full-featured signing device, designed for users who interact with Bitcoin regularly and want the most comfortable user experience that full air-gapped security can provide.
The QWERTY keyboard. Entering a passphrase on a small numeric keypad means cycling through characters one by one, whereas on the Q you can just type it comfortably. For long passphrases, frequent unlocks, or regular text entry on the device, this difference is immediately noticeable.
QR-based signing. The workflow looks like this: a compatible coordinator displays the unsigned transaction as a QR code, you scan it with the Q's camera, review and approve on-device, then display the signed QR result for the coordinator to scan. There is no cable or card swap. For users who sign frequently, that can reduce handling compared with a MicroSD workflow.
A large, color screen. The Q's display shows complete transaction details, full Bitcoin addresses, and multisig signing summaries at a comfortable reading size. A smaller monochrome screen conveys the same essential information but requires more scrolling during address verification. A bigger screen means less friction at the step that matters most.
Advanced features. The Coldcard Q supports Key Teleport, which enables the secure transfer of seeds, multisig PSBTs, and full backups between devices via encrypted QR codes. The Q can also function as a hardened vault for sensitive data, allowing you to store passwords, secure notes, and Nostr keys alongside your private keys.
Battery power. The Q can be powered by three AAA batteries for a cord-free experience, or via a USB-C cable connected to a power bank, wall outlet, or computer. This flexibility allows you to sign in fully power-isolated environments using whichever source you prefer.
Coldcard Mk5: designed for portability, simplicity, and value
The Mk5 is Coldcard's latest iteration of the Mk-series, built around a clear set of priorities: a pocketable form factor, a proven signing workflow, and the full Coldcard security model.
The Mk5 is built for portability and a low profile. It easily fits in your pocket, a wallet, or a travel bag without drawing attention. For users who carry their signing device with them, travel with it to secure locations to sign, or treat a low-profile as part of their security model, the compact size is valuable.
The MicroSD PSBT workflow is deliberate, transparent, and proven. Every step is visible: copy the unsigned transaction to the card, sign on the device, copy the signed result back. Sparrow wallet has first-class support for this flow, and a large number of experienced bitcoiners prefer this as their primary signing method.
NFC tap-to-sign is convenient for compatible mobile wallets. A quick tap with a compatible mobile wallet like Nunchuk transfers the unsigned transaction to the Mk5, which can return the signed result over NFC. It does not need a cable or physical media, and the compact size makes tapping feel natural.
The price point is worth factoring in, especially when buying multiple devices. At $169.94, the Mk5 is noticeably less than the Q, with the same complete security foundation. For users who don't need the features or form factor of the Q, or who are buying multiple devices for multisig setups, gifts, or backups, the savings can be meaningful.
Coldcard Q vs. Mk5: which should I buy?
Both devices are fully capable and share the same security model. The decision comes down to how you use a signing device on a regular basis and your personal preference for user experience.
Transaction frequency and complexity. If you sign regularly or review transactions with multiple outputs, the Q's large screen and keyboard make each session more comfortable. Occasional, straightforward signing doesn't necessarily require a large screen or full keyboard.
Passphrase length. If you use a BIP-39 passphrase wallet, you have to enter the passphrase in each session when you select that wallet. On the Mk5 that means cycling through characters on a numeric keypad, while on the Q you type it directly. For users with a longer passphrase or frequent device use, this is often the deciding factor.
Signing workflow. The Mk5 signs via MicroSD or NFC tap, which pair naturally with desktop coordinators and mobile wallets. The Q adds support for QR code signing: scan the unsigned PSBT in, approve on-device, scan the signed result back out. Frequent transactions or usage of mobile vs. desktop signing may lead you to prefer one method over another.
Advanced features. The Q features Key Teleport via QR code as well as the ability to store sensitive data like passwords, notes, and Nostr keys. Both devices support on-device multisig coordination, but the Q's larger screen and keyboard make the setup and management workflow more ergonomic, whereas the Mk5's smaller interface requires more navigation.
Portability. If you travel with your device, take it to secure locations to sign, or want to keep a low profile during transport or storage, the Mk5's credit card-sized form factor offers clear advantages. If it simply lives on a desk or in a lock box, the ergonomics of a larger form factor may make the Q a better fit.
Price point. If budget is a primary consideration or if you're buying multiple devices for multisig setups, gifts, or spares, then the price difference is worth including in your decision.
Both provide the same core COLDCARD security model. The better fit is the device whose input, display, transport, size, and price match your workflow.
Passphrases and upgrade considerations for choosing
The passphrase question
A BIP-39 passphrase (sometimes called a "25th word") combines with the seed to select a separate wallet. If the seed is exposed, a strong passphrase kept separately can preserve another barrier. The tradeoff is recovery risk: every character matters, and a forgotten or mistyped passphrase opens a different wallet. You must enter it for each session in which you use that passphrase wallet. On the Mk5's numeric keypad, entering a 10-20 character passphrase means cycling through characters methodically. On the Q's QWERTY keyboard, you type it directly. For passphrase users, this difference can drive the choice.
Switching from Mk5 to Q later
Your seed phrase is not tied to a specific COLDCARD model. A Q can restore a BIP-39 seed created on an Mk5, and vice versa. The same passphrase, derivation path, address type, and multisig configuration are also required where applicable. Balance and transaction history are reconstructed by the coordinator or node; they are not stored in the seed or restored by the signing device. Test recovery before relying on a replacement, and do not treat a future model switch as a backup plan.
Both devices are Coldcard.
Every security feature that defines Coldcard, from the open-source codebase to dual secure elements to the full security architecture, is built into both devices.
-
✓
Bitcoin-only firmware
-
✓
Open-source build
-
✓
Fully air-gapped capable
-
✓
Dual secure elements
-
✓
Anti-phishing protection
-
✓
On-screen address verification
-
✓
Self-destruct PIN
-
✓
Duress / decoy wallet PIN
-
✓
Countdown PIN
-
✓
Encrypted MicroSD backup
-
✓
BIP-85 child seeds
-
✓
Seed XOR
-
✓
Seed Vault
-
✓
NFC
-
✓
USB-C
-
✓
MicroSD
-
✓
PSBT (BIP-174)
-
✓
Taproot (BIP-341, Edge firmware)
-
✓
Miniscript (BIP-379, Edge firmware)
-
✓
Sparrow Wallet compatible
-
✓
Numbered tamper-evident bag
-
✓
Viewable electronics
-
✓
User-contributed entropy
-
✓
Verifiable seed generation
Which device is right for you?
Both share the Coldcard security foundation. The decision comes down to your personal preference and workflow.
Choose the Q
- →You prefer a full QWERTY keyboard over a numeric keypad
- →You sign transactions at a desk and want the most ergonomic signing experience available
- →You want QR-based signing, with no cable or card swap needed
- →You coordinate multisig wallets and want a larger screen and keyboard for on-device setup and review
- →You want to run the device on three AAA batteries for a fully power-isolated environment
- →You want a larger screen to read full Bitcoin addresses and multisig summaries at a comfortable size
Choose the Mk5
- →You want a signing device that fits in your pocket, bag, or wallet for easy portability
- →Your workflow centers on MicroSD PSBT signing with Sparrow wallet or NFC tap with a mobile wallet
- →You are comfortable using the smaller display and keypad for on-device multisig setup and review
- →You want the full Coldcard security foundation at a lower price point
- →A smaller, more discreet form factor is part of your security model
Methodology and primary evidence
Reviewed on July 20, 2026.
Method. We compared the current Q and Mk5 product pages, model documentation, shared firmware repository, and feature guides. A table entry is marked Y only when the feature is documented for that model. Firmware-channel labels such as Edge are version-sensitive and should be rechecked against the installed release. Price values are inserted from the current Coinkite store feed rather than recorded as fixed editorial claims.
Limits. These are Coinkite primary sources, not an independent security audit. “Same security model” means the documented shared controls and codebase; it does not mean the two products have identical interfaces, parsers, physical construction, or attack surface.
Claim-to-evidence map:
- Model hardware, dimensions, power, keyboard, display, and card slots: COLDCARD Q documentation, COLDCARD Mk5 documentation, Q product page, and Mk5 product page.
- QR, MicroSD, NFC, and USB workflows: Q quickstart, PSBT signing procedure, MicroSD documentation, and hardware-interface settings.
- Shared firmware and security controls: firmware snapshot reviewed, hardware documentation, PIN and Trick PIN documentation, and physical security notes.
- Encrypted backups and seed tools: backup format, BIP-85 derivation, and Seed XOR.
- Q-only tools: Key Teleport and Secure Notes & Passwords.
- Multisig and transaction formats: multisig documentation, PSBT signing procedure, and the current firmware release history.


