Skip to content
COLDCARD Security Update Fixed firmware is available. Check if you need to migrate your seed. Learn more

Upgrade COLDCARD firmware#

Update before wallet setup

For a new COLDCARD, inspect the tamper-evident bag and set a PIN, then stop at the main menu. Install and confirm the recommended standard firmware before choosing a seed or restore option. Do not fund the wallet until the update is complete.

Updating changes the device software; it does not alter an existing seed. If the security status says that a seed requires migration, update first and then follow the published migration guidance.

Use these live pages for current firmware files and release details:

Video: How to Upgrade Firmware

Upgrade using MicroSD#

What you need#

  • One COLDCARD
  • microSD card (up to 32 GB capacity, FAT32 or FAT12 format)
  • Compatible USB power cable, power-only preferred
  • COLDPOWER or an AC USB power adapter
  • Internet-capable device for downloading and saving files

1. Check the installed version#

  1. Connect the COLDCARD to a power source to turn it on.
  2. Enter your PIN to unlock the COLDCARD.
  3. Select Advanced/Tools > Upgrade Firmware > Show Version.
  4. Compare the version shown with the current standard release for your model on the downloads page.
  5. Check the model printed on the back. If it says Mark 1, stop: firmware newer than 3.0.6 will brick it.

2. Download the current firmware#

  1. Go to the current firmware downloads page.
  2. Choose the current standard release for your model. Edge firmware is for advanced users and has a separate warning.
  3. Save the complete .dfu file and the signed signatures.txt release manifest.
  4. Verify the signed manifest and firmware hash before loading the file.

3. Verify the download#

Verify the OpenPGP signature on signatures.txt, then compare its SHA-256 hash for the firmware file with the hash you calculate locally. This confirms that the file matches the signed release manifest. Choose your operating system below.

Note: PGP signature verification requires GPG. Debian and other Linux distributions include GPG. Mac and Windows users who have not already installed GPG will need to do so. Operating system-specific instructions contain links to tool downloads.

macOS#

These instructions use GPG Keychain, a component of the GPG Suite from GPGTools.

You can also follow along with our video tutorial, How to Verify COLDCARD's Firmware.

Confirm the Hash

  1. Open signatures.txt so you can view its contents.
  2. Open Terminal, navigate to the directory where you saved the firmware and use the command shasum -a256 20...-coldcard.dfu.
  3. Resize or reposition the windows so you can see both the Terminal and signatures.txt file at the same time.
  4. Compare the output values in Terminal with the line of text in the signatures.txt file next to the firmware version you saved. The hash is confirmed if the values are the same.

Verify the PGP Signature

  1. Save the signatures.txt file in the same location as the new firmware file.
  2. Save the public key 4589779ADFC14F3327534EA8A3A31BAD5A2A5B10 as a new-pubkey.txt file in the same location as the firmware and signatures.txt files.
  3. Open GPG Keychain.
  4. Click the Import button and navigate to new-pubkey.txt. Select the file and click Open. A pop-up message should appear saying "Import successful".
  5. Open Terminal and enter gpg --verify signatures.txt.
  6. The output in Terminal should include Good signature from.... It is normal to see WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. You may ignore the warning, the signature is verified.

Once the hash and signature are verified, load the latest firmware on your COLDCARD.

Linux#

Confirm the Hash

  1. Open signatures.txt so you can view its contents.
  2. Use the command line to navigate to the directory where you saved the firmware and enter the command sha256sum 20...-coldcard.dfu.
  3. Resize or reposition the windows so you can see both the command output and signatures.txt file at the same time.
  4. Compare the output value from the command with the line of text in the signatures.txt file next to the firmware version you saved. The hash is confirmed if the values are the same.

Verify the PGP Signature

  1. Save the signatures.txt file in the same location as the new firmware file.
  2. On the command line, enter curl "https://keyserver.ubuntu.com/pks/lookup?op=get&search=0xA3A31BAD5A2A5B10" | gpg --import to import the public key.
  3. Next, enter gpg --verify signatures.txt to verify the file's signature versus its content.
  4. The command output should include Good signature from.... It is normal to see WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. You may ignore the warning, the signature is verified.

Once the hash and signature are verified, load the latest firmware on your COLDCARD.

Windows#

These instructions use Kleopatra, which is a part of Gpg4win (GNU Privacy Guard for Windows). You only need the GnuPG Privacy Guard and Kleopatra components to verify the PGP signature.

Kleopatra requires you to have an OpenPGP signature to complete verification. If you don't have a signature to import, you can make one in Kleopatra.

Confirm the Hash

  1. Open signatures.txt so you can view its contents.
  2. Open Command Prompt and enter certutil -hashfile C:\..\20...-coldcard.dfu SHA256, where C:\..\20...-coldcard.dfu is the full path to the saved firmware file.
  3. Resize or reposition the windows so you can see both the Command Prompt output and signatures.txt file at the same time.
  4. Compare the output values in Command Prompt with the line of text in the signatures.txt file next to the firmware version you saved. The hash is confirmed if the values are the same.

Verify the PGP Signature

  1. Save the text from signatures.txt with an .asc file extension in the same location as the saved firmware file. Do not save the file as .txt, Kleopatra will not recognize it.
  2. Save the public key 4589779ADFC14F3327534EA8A3A31BAD5A2A5B10 as an .asc file in the same location as the firmware and signatures.asc files.
  3. Open a browser and go to keybase.io/DocHex. Click on the text next to the key icon to open the public key window. You will need this window for a later step.
  4. Open Kleopatra and click Import....
  5. Navigate to the public key .asc file and open it.
  6. You will be asked to check the fingerprint of the file and given suggested options. The Keybase public key window is the trusted website. Click Yes.
  7. A Certify Certificate window will show the file's fingerprint, your certification, and the fingerprint's owner - in this case, Peter D. Gray. Resize or reposition the Certify Certificate window and the browser window opened in step 3 so you can see them both at the same time.
  8. Make sure the fingerprints in each window match and click Certify. If you have a passphrase on your certificate, you'll be asked to enter it. A pop-up box should appear saying, "Certification successful." Click Ok.
  9. Click Decrypt/Verify... and open signatures.asc.
  10. Kleopatra will verify the signature. You may save or discard the file Kleopatra generates, it is not needed. The signature is verified.

Once the hash and signature are verified, load the latest firmware on your COLDCARD.

4. Install the firmware#

  1. Save the 20...-coldcard.dfu file to your microSD card if you haven't done so already and eject the card once the file is saved.
  2. Make sure your COLDCARD is turned on and unlocked.
  3. Select Advanced/Tools > Upgrade Firmware > From MicroSD.
  4. Press OK (✔) on your COLDCARD when you are prompted to pick the firmware image.
  5. Select the firmware file.
  6. The screen will say "Loading. . .". Be patient, this process takes time.

Note: When the screen changes to Verifying, the red LED will light up and stay lit until the firmware upgrade is complete. The red CAUTION LED lets you know changes are being made or have been made to your COLDCARD. If the COLDCARD is turned off after the new firmware is installed but before the first successful login, you will need to bless the firmware to turn the red LED off.

Do not turn off power to a Mk4 during its 15-second flash-write phase. If power is lost during this phase and the screen shows Insert Card, insert a FAT32-formatted MicroSD card containing the same firmware file to recover.

5. Confirm the version#

  1. Enter your PIN prefix when prompted after the COLDCARD reboots.
  2. Verify whether or not you recognize the two words displayed on the screen. These words are hardware-specific to ensure you have the correct device. A different COLDCARD will display different words.
  3. Enter the rest of your PIN when prompted.
  4. The COLDCARD will perform another verification and the green GENUINE LED will light up.
  5. Select Advanced/Tools > Upgrade Firmware > Show Version and confirm the version you installed.

Red CAUTION LED after restart#

The red CAUTION LED is a safety feature warning you of unconfirmed changes to your COLDCARD. Only the main PIN holder can confirm changes. If you load new firmware and turn off the device before confirming the upgrade, the CAUTION LED will be lit the next time you turn on your COLDCARD. Blessing the firmware tells the COLDCARD that you are aware of and approve of the firmware upgrade.

  1. Follow the prompts on the screen to log in to your COLDCARD.
  2. Select Advanced/Tools > Danger Zone > Bless Firmware.
  3. The screen will say Verifying the green GENUINE LED will light up confirming your approval of the new firmware.

Once the firmware is blessed, your COLDCARD will light up the green LED on future startups.

Other upgrade methods#

These instructions use a microSD card to upgrade the firmware. You can also upgrade by using the command-line tool or the Electrum plugin. On the Mk4, if USB drive emulation is enabled, you can simply copy the dfu file onto the COLDCARD.

Release channels and history#

Use the firmware downloads page to identify the current recommended release for your model. Do not rely on a version number copied from an older guide, video, or social post.

  • Standard firmware is recommended for most users. Download it from the current firmware page and verify it using the instructions above.
  • Edge firmware is a preview channel for developers, testers, and users who specifically need an unreleased feature. It has not been qualified and tested to the same standard as a normal release.
  • Previous and legacy releases remain available for older hardware, recovery, and historical reference. Do not downgrade unless you have a specific reason and understand the limitations.

Download Edge firmware, browse all firmware files, or review the version history and standard firmware release notes. Edge changes are recorded in the separate Edge release notes.


Last update: August 31, 2026