Tools/Explorers

Bitkey vs Coldcard: Consumer vs Power-User Bitcoin Signer

Compare Bitkey and Coldcard hardware wallets: security model, multisig capability, air-gapped signing, backup, and which is right for you.

Spark Team

Bitkey vs Coldcard Overview

Bitkey and Coldcard represent two fundamentally different philosophies for Bitcoin self-custody. Bitkey, built by Block (formerly Square), targets first-time self-custodians with a guided 2-of-3 multisig experience that eliminates seed phrases entirely. Coldcard, built by Coinkite, targets security-maximalist Bitcoiners with fully air-gapped signing, dual secure elements, and deep control over every aspect of key management.

Both devices are Bitcoin-only signing devices, but they make opposite tradeoffs between usability and sovereignty. The right choice depends on your technical comfort level, threat model, and how much third-party trust you are willing to accept.

FeatureBitkey (2026)Coldcard Mk5Coldcard Q
Price$250$189$289
Security model2-of-3 multisig (phone + device + Block server)Single-sig or user-controlled multisigSingle-sig or user-controlled multisig
Air-gappedNo (requires NFC to phone)Yes (microSD, NFC)Yes (microSD, NFC, QR)
Secure elementSilicon Labs EFR32MG24Dual: ATECC608B + DS28C36BDual: ATECC608B + DS28C36B
AuthenticationFingerprint biometricPIN with anti-phishing wordsPIN with anti-phishing words
DisplayOLED touchscreenMonochrome OLED, Gorilla Glass3.2" color LCD (320x240)
Seed phraseNoneBIP-39 (12 or 24 words)BIP-39 (12 or 24 words)
Companion appRequired (Bitkey app)None requiredNone required
Open sourceFirmware: MIT; server: proprietaryFully open sourceFully open source
Coins supportedBitcoin onlyBitcoin onlyBitcoin only

For a broader view of the signing device market, see our Bitcoin hardware wallet comparison and multisig setup comparison.

Security Architecture

The core difference between these devices is where trust lives. Bitkey distributes trust across three keys using a threshold signature scheme: a phone key (stored in the mobile app and backed up to iCloud or Google), a hardware key (generated in the device's secure enclave and protected by fingerprint), and a server key (held by Block on AWS Nitro Enclaves). Any two of three keys authorize a transaction.

For routine spending below a user-configured limit, the phone key and Block's server key co-sign without requiring the hardware device. This means Block's infrastructure sees transaction details and participates in signing for day-to-day payments. Transactions above the limit require the hardware key's fingerprint confirmation. This design eliminates the single point of failure that destroys many beginners (losing a seed phrase), but it introduces a dependency on Block's continued operation.

Coldcard takes the opposite approach: zero manufacturer involvement after purchase. Private key material is split across the main microprocessor and two secure elements from different vendors (Microchip ATECC608B and Maxim DS28C36B). The dual-vendor approach means a vulnerability in one chip vendor's silicon does not automatically compromise the key. A dedicated hardware LED circuit (not software-controlled) verifies firmware integrity at boot: green means authentic firmware, red means tampered.

Key tradeoff: Bitkey protects against user error (lost seed, forgotten passphrase) by adding Block as a trusted co-signer. Coldcard protects against institutional risk (vendor compromise, server seizure) by eliminating all third parties. Neither approach is universally better: the right model depends on your threat model.

Signing Flow and Daily Use

Bitkey's signing flow is designed for mobile-first simplicity. The user opens the Bitkey app, constructs a transaction, and taps the hardware device via NFC to authorize. For smaller transactions within the configured spending limit, the hardware tap is skipped entirely and Block's server co-signs with the phone key. Setup takes minutes: pair the device via NFC, enroll a fingerprint, and the app handles wallet creation. There is no seed phrase to write down, no passphrase to configure, and no PSBT workflow to learn.

Coldcard's signing flow prioritizes air-gapped security. The typical workflow involves exporting an unsigned PSBT from a watch-only wallet (Sparrow, Electrum, Nunchuk, or Specter), transferring it to the Coldcard via microSD card, reviewing and signing on-device, then returning the signed transaction to the watch-only wallet for broadcast. The Coldcard Q adds a built-in QR scanner for camera-based PSBT transfer, and all current models support NFC tap-to-sign (which can be permanently disabled for stricter air-gap policies). The Mk5 also offers a Virtual Disk mode that presents the device as USB mass storage for file transfer without a data connection.

Backup and Recovery

Bitkey eliminates the seed phrase, replacing it with four recovery mechanisms. Cloud Backup encrypts the app key to iCloud or Google Drive. Delay and Notify allows recovery with a single key after a configurable waiting period (default: 7 days), with alerts sent to warn of unauthorized attempts. Social Recovery lets a designated trusted contact assist in recovery if both the phone and hardware device are lost. Inheritance provides a built-in protocol for passing Bitcoin to a beneficiary. These overlapping paths reduce the risk of permanent loss, but they also expand the attack surface compared to a single seed backup.

Coldcard uses the standard BIP-39 seed phrase (12 or 24 words) as the primary backup. Users can also create AES-256 encrypted backups on microSD. For advanced splitting, Seed XOR lets users divide a seed into multiple parts that must be physically combined to reconstruct the original. BIP-85 support enables deriving child seeds for other wallets from one master backup, reducing the number of seed phrases a user needs to protect. All recovery is sovereign: Coinkite has no involvement and no ability to assist. For more on Bitcoin backup strategies, see our Shamir secret sharing backup guide.

Advanced Features

Coldcard's feature set caters to power users and institutional operators. HSM Mode turns the device into a programmable spending policy engine: it can enforce transaction amount limits, velocity limits, and destination address whitelists, then auto-sign conforming transactions without human interaction. This is valuable for businesses that need automated treasury operations with hardware-enforced guardrails.

Physical security features include Duress PIN (opens a convincing decoy wallet with separate funds), Brick-Me PIN (permanently destroys both secure elements), configurable Trick PINs with countdown timers ranging from 5 minutes to 28 days, and Login Countdown that forces a waiting period before granting access. MicroSD 2FA requires a specific SD card to be present as a second authentication factor. The Q model adds an encrypted password manager and secure note storage.

Bitkey's advanced feature is its social recovery model itself. The combination of spending limits, delayed recovery, and trusted-contact recovery handles edge cases that typically defeat new self-custodians: lost devices, forgotten credentials, and inheritance. Bitkey also publishes proof of reserves and open-sourced its firmware under the MIT license, though Block's server-side co-signing infrastructure remains proprietary.

Multisig Flexibility

Both devices support multisig, but with very different constraints. Bitkey's 2-of-3 multisig is mandatory and fixed: Block is always one of the three cosigners. Users cannot export keys, add different cosigners, or use Bitkey in a custom multisig arrangement with other signing devices. The keys are locked to the Bitkey ecosystem.

Coldcard supports arbitrary multisig configurations with any PSBT-compatible coordinator software. Users can build 2-of-3, 3-of-5, or any m-of-n setup using Coldcards alongside Trezors, Ledgers, SeedSigners, or any other signing device. Key material follows standard BIP-39 and BIP-44 derivation, so seeds work in any compatible hardware wallet or software wallet. This portability is a core sovereignty property: if Coinkite ceased operations, users could restore their keys on any BIP-39 compatible device.

Price and Value Comparison

DevicePriceDisplayInputAir-Gap MethodsBest For
Bitkey (2026)$250OLED touchscreenFingerprint + touchNone (NFC to phone)Self-custody beginners
Coldcard Mk4~$148128x64 monochrome OLEDNumeric keypadMicroSD, NFCBudget-conscious power users
Coldcard Mk5$189Improved OLED, Gorilla GlassNumeric keypadMicroSD, NFC, Virtual DiskPower users wanting latest hardware
Coldcard Q$2893.2" color LCDFull QWERTY keyboardMicroSD, NFC, QR scannerMaximum capability and convenience

For the Coldcard Mk4 specifically, see our detailed Coldcard vs BitBox comparison and the broader signer selection guide.

Who Should Choose Bitkey

Bitkey is the right choice for people who are moving Bitcoin off an exchange for the first time and want a safety net. If losing a seed phrase is a realistic risk, Bitkey's cloud backup, social recovery, and delayed-recovery mechanisms provide meaningful protection against permanent loss. The mobile-first UX eliminates the learning curve of PSBT workflows, watch-only wallets, and coin selection.

The tradeoff is explicit: you trust Block to operate the server key honestly and indefinitely, you accept that keys cannot be exported, and you rely on Block's app for all wallet operations. For users whose primary threat is self-inflicted loss rather than institutional attack, this is a reasonable tradeoff.

Who Should Choose Coldcard

Coldcard is the right choice for users who want maximum sovereignty and are willing to invest the time to learn proper key management. If your threat model includes government seizure, vendor compromise, or long-term storage spanning decades, Coldcard's air-gapped architecture, dual secure elements, and standard BIP-39 seeds provide stronger guarantees. The device works with any coordinator software, so you are never locked into a single vendor's ecosystem.

Coldcard also serves institutional and business use cases that Bitkey cannot: HSM mode for automated policy-enforced signing, arbitrary multisig configurations with mixed signing devices, and cold storage setups where the device never connects to any network. For users building custom custody infrastructure or running a multi-institution custody arrangement, Coldcard's flexibility is essential.

How Both Fit Into a Bitcoin Custody Stack

Some Bitcoiners use both devices for different purposes. Bitkey can serve as a convenient spending wallet for day-to-day transactions, while a Coldcard secures long-term savings in a fully air-gapped configuration. This layered approach mirrors how people use checking and savings accounts: convenience for small amounts, maximum security for the bulk of holdings.

For users building on Bitcoin Layer 2 networks like Spark, the base-layer signing device remains critical for channel funding transactions and on-chain security. Understanding the tradeoffs between consumer and power-user signers helps inform how you structure your overall custody architecture.

Frequently Asked Questions

Is Bitkey a hardware wallet or a multisig service?

Bitkey is both. It includes a physical signing device with a secure enclave and fingerprint sensor, but it operates as part of a 2-of-3 multisig system where Block holds one of the three keys. Unlike a traditional hardware wallet where you control all keys, Bitkey distributes key custody across your phone, the hardware device, and Block's servers.

Can I use Coldcard without ever connecting it to a computer?

Yes. Coldcard supports fully air-gapped operation using microSD cards for PSBT transfer. You can power the Coldcard Q with AAA batteries and transfer transactions entirely via SD card or QR codes, with no USB, NFC, or network connection. Both NFC and USB data modes can be permanently disabled in firmware for strict air-gap policies.

What happens to my Bitkey funds if Block goes out of business?

Bitkey's Delay and Notify recovery path allows you to move funds with just one key after a waiting period, so Block's server is not strictly required for recovery. However, the Bitkey app is required for wallet operations, and keys cannot be exported to other wallet software. Block has published the app source code under MIT license, which means the community could theoretically maintain it, but this has not been tested in practice.

Does Coldcard support multisig with other hardware wallet brands?

Yes. Coldcard natively supports multisig with any PSBT-compatible signing device. You can build a multisig vault using Coldcards alongside Trezors, Ledgers, SeedSigners, Jade, or Keystone devices using coordinator software like Sparrow, Nunchuk, or Specter Desktop. The standard BIP-39 seed format ensures cross-device compatibility.

Which device is better for Bitcoin inheritance planning?

Bitkey includes a built-in inheritance feature that allows designating a beneficiary. Coldcard does not have a dedicated inheritance mode, but its standard BIP-39 seed phrase can be included in any inheritance plan using sealed envelopes, safe deposit boxes, or Shamir secret sharing. For non-technical heirs, Bitkey's guided inheritance flow is simpler. For heirs who understand Bitcoin, a well-documented Coldcard seed backup provides greater flexibility.

Can I recover a Coldcard wallet on a different brand of hardware wallet?

Yes. Because Coldcard uses the standard BIP-39 seed phrase with standard derivation paths (BIP-84 for native SegWit, BIP-86 for Taproot), you can enter the same seed words into any compatible hardware or software wallet and access the same funds. This portability is a core advantage of the standard seed-based approach over Bitkey's proprietary key management.

Is Bitkey open source?

Partially. Bitkey's mobile app and hardware firmware are published on GitHub under the MIT license. However, Block's server-side co-signing infrastructure, which holds one of the three multisig keys, is proprietary. Coldcard's firmware and hardware schematics are fully open source, and the firmware supports deterministic builds for independent verification.

This comparison is for informational purposes only and does not constitute financial advice. Specifications, pricing, and features may change. Always verify current product details on the manufacturer's website before purchasing. Neither Bitkey nor Coldcard is affiliated with Spark.

Build with Spark

Integrate bitcoin, Lightning, and stablecoins into your app with a few lines of code.

Read the docs →