The checklist
-
Set up away from cameras.
Open the package somewhere private. No livestream, no screen share, no phone camera. Seed words and backup passwords never go into another device.
-
Inspect the bag and run the genuine check.
Check the tamper-evident bag, then follow the device prompts. COLDCARD shows anti-phishing words after the PIN prefix; learn them before you enter the suffix on future logins.
-
Create a new seed on COLDCARD.
After installing and verifying current firmware, generate a new seed using fresh device entropy plus one required method: 65 key presses with unpredictable timing, 50 physical dice rolls, or 128 physical coin flips. Dice Rolls Only is a separate advanced workflow requiring 50 rolls for 12 words or 99 for 24 words.
-
Write the seed offline.
Paper is fine while setting up. Long term, use metal. No photos, cloud notes, printers, or typing the words into a computer.
-
Export a watch-only wallet.
Export the wallet file, xpub, or descriptor. Sparrow, Cove, Nunchuk, and Specter can build transactions while COLDCARD keeps the keys.
-
Verify a receive address on-device.
Your computer or phone can lie. Before sending even the test amount, compare the address shown in the wallet app with the address shown on COLDCARD.
-
Sign one small transaction.
Create an unsigned PSBT in the wallet app. Move it by MicroSD, Virtual Disk, NFC, or QR on Q. On COLDCARD, check destination, amount, fee, and change before signing.
-
Restore, then apply the passphrase.
Restore the base wallet from its backup first. Before depositing a meaningful balance, apply a strong, unique BIP-39 passphrase, back it up separately, record the new wallet fingerprint, power-cycle, and test the complete recovery path.
Leave for later
Duress wallets, Brick Me PIN, countdown PIN, SeedXOR, BIP-85, and multisig are not first-hour tasks. Add them only after their recovery plans are understood. A meaningful-balance passphrase belongs after the plain-wallet recovery test, not before it.
You're ready when
You can log in, recognize the anti-phishing words, match a receive address, sign a small PSBT, and recover from backup.