Hardware

COLDCARD: the features worth turning on next

Trick PINs, duress wallets, the brick-me PIN, and the login countdown. What each one actually does, and the honest accounting of which of them can cost you your own coins.

Advanced About 30 minutes Updated Aug 18, 2026
DuressPIN policy

Once a COLDCARD is set up and holding coins, the settings menu offers a second layer: alternate PINs that open decoy wallets, wipe the seed, stall an attacker for days, or destroy the device outright. It is the most interesting menu on the device and the one most likely to lose you money.

Not because the features are badly built — they work exactly as described. The problem is that every one of them trades a defence against somebody else for a new way to lock yourself out, and the device will let you configure all of it without ever asking whether your backup is real.

This page explains what each option does and then does the accounting nobody enjoys: which of them you can walk back, and which are permanent.

A COLDCARD face down on a desk beside a fireproof document bag and a metal seed plate, lit hard from one side, nobody in frame.

Image to come

Everything on this page assumes the plate exists and has been tested. Without that, none of it is a safety feature.

1The rule that governs everything else

Before any of this, one fact about the main PIN, because it is the ground every other feature is built on.

There is no PIN reset and no factory reset. Coinkite cannot recover it, and neither can you. After thirteen wrong attempts the secure element destroys its contents and the device is finished — permanently, by design, with no appeal.

That is not a bug to be nervous about. It is the reason the device is worth owning: a thief with your COLDCARD and no PIN gets thirteen guesses and then a paperweight. But it means the written recovery words are not a fallback for this device. They are the only copy of your wallet that exists.

Do the restore test first, not later

If you have not already restored these words onto a wiped device and watched the balance reappear, stop and do that before enabling anything below. Every feature on this page increases the chance you will one day need that backup, and an untested backup is a guess.

2What a trick PIN actually is

A trick PIN is a second, third, or tenth PIN that you configure while logged in normally. Enter it at the login screen and the device does not log you in — it performs whatever action you attached to that PIN, while behaving as though nothing unusual happened.

The deception is the entire point. Someone standing over you sees a PIN typed and a device responding normally. They do not see which PIN it was, and the COLDCARD gives nothing away.

You can configure several at once, each with a different action. They live in the secure element alongside the real PIN, and they can only be added, changed, or removed by logging in with the main PIN first.

3The duress wallet

The best known of the trick PINs. Enter the duress PIN and the COLDCARD opens a real, working, entirely separate wallet. Balances, addresses, signing — all genuine. It simply is not your wallet.

The seed for it is derived from your own seed along a fixed BIP-85 path, using reserved indices — 1001 to 1003 for a 24-word wallet, 2001 to 2003 for a 12-word one. Two consequences follow, and they matter in opposite directions:

  • You can rebuild it. Because it is derived from your main seed, anything you leave in a duress wallet is recoverable later from your recovery words and a BIP-85 tool. It is not a black hole.
  • They cannot walk backwards. The derivation runs one way only. Somebody holding the duress wallet, its words, and all its coins has no route from there to your real wallet.

That second property is what makes the feature worth anything. The first is what stops a decoy from being a write-off.

  • An empty decoy is not a decoy. A wallet with nothing in it tells your attacker they have the wrong PIN, and you are back where you started, having burned your one deception.
  • A funded decoy is money you may actually hand over. Whatever you put in it should be an amount you would be willing to lose to end the situation.
  • It only works if you can perform. The whole mechanism rests on somebody believing you under pressure. The case against decoy wallets is worth reading before you commit to one — the argument applies just as much here.

4The wipe options

Several trick PINs destroy the seed on the device rather than hiding it. They differ only in what the attacker sees afterwards:

  • Wipe and reboot. The seed is erased and the device restarts, looking freshly unboxed.
  • Silent wipe. The seed is erased and the device shows an ordinary wrong-PIN message, so the wipe is invisible.
  • Wipe, then open a wallet. The seed is erased and a duress wallet opens, so the device looks used rather than blank.
  • Say wiped and stop. The device states plainly that it has been wiped.

These are genuinely effective against a thief who wants your coins. They are also the fastest way to destroy your own access, because a wiped COLDCARD is exactly as empty as a stolen one. Everything depends on the words on your backup plate.

5The brick-me PIN

This one does what it says. Enter the brick PIN and the secure element is destroyed on the spot. The COLDCARD displays the word Bricked and will do so for the rest of its existence. It cannot be repaired, reflashed, or reset. Coinkite's own advice is to discard it as e-waste.

It is worth being clear about what this buys you, because it is narrower than it first appears. Bricking does not protect your coins — a wipe already does that, and leaves you a working device. What bricking adds is certainty that this specific piece of hardware will never be analysed, coerced, or brought back.

For the overwhelming majority of people that is a threat model they do not have, purchased at the price of a device they do.

A wipe protects your coins and costs you a restore. A brick protects your coins and costs you the device. Be certain you know which problem you are solving.

6The login countdown

Rather than deceiving or destroying, this one simply refuses to hurry. Enter the PIN, and the device shows a countdown — anywhere from five minutes to twenty-eight days — and only accepts the PIN a second time once it has run out.

Against coercion this is the most quietly useful option on the menu. It converts “unlock this now” into “stand here for a fortnight”, which is not a demand most people can make good on.

There are variants that wipe first and then count down, or count down and then brick. And the obvious catch: the delay applies to you exactly as it applies to them. A twenty-eight day countdown means you cannot reach your own coins for twenty-eight days either, from the moment you set it.

7Delta mode, and why it is last

Delta mode grants apparent access to your real wallet while quietly preventing transactions from being signed properly. The attacker sees the balance they were after and cannot move it.

It carries an unusual constraint: the trick PIN must be the same length as your main PIN and identical to it except for the last four digits. Coinkite's documentation says plainly that it is not recommended for novices, and that is the right note to end the menu on. Misconfigure it and you have built a very elaborate way to confuse yourself at the worst possible moment.

8The honest accounting

Here is every option measured against the only question that matters: if this fires, by accident or by design, what does it cost you?

Consequence map

What each trigger actually costs

Your backup is the exit
FeatureWhat it costs youRecovery path
Just rebootCostNothingRecoveryYes — nothing changed
Look blankCostNothing; the seed is untouchedRecoveryYes — nothing changed
Duress walletCostWhatever you funded the decoy withRecoveryYes, via BIP-85 from your seed
Login countdownCostYour own access, for up to 28 daysRecoveryYes, once it expires
Any wipe variantCostThe seed on the deviceRecoveryOnly from your written backup
Countdown, then brickCostThe device, after the delayRecoveryOnly from your written backup
Brick meCostThe device, immediately and permanentlyRecoveryOnly from your written backup
13 wrong main PINsCostThe device, permanentlyRecoveryOnly from your written backup

The bottom half of that table is not a warning against those features. It is a statement that they all resolve to the same place: a plate with words on it, in a drawer, that you have personally tested. Every one of them is safe if that plate is real, and every one of them is catastrophic if it is not.

9What to actually turn on

A recommendation, since a menu of options is not advice.

  • For nearly everyone: none of it. A tested backup, a PIN you will not forget, and a device nobody knows you own already defeat the threats most people genuinely face.
  • If you travel or cross borders: a modest login countdown, measured in hours rather than weeks, is the option with the best ratio of protection to self-inflicted risk.
  • If you are seriously worried about coercion: a funded duress wallet, but only after reading the case against decoys and only if you are honest about performing under pressure.
  • Brick-me and delta mode: leave them alone unless you can state precisely which adversary they defeat and why a wipe would not have.

And whatever you enable, write down that you enabled it, and store that note with your recovery words. A trick PIN you have forgotten configuring is a trap you built for yourself.

The short version

Trick PINs are alternate PINs that deceive, delay, wipe, or destroy instead of logging you in. The duress wallet is derived from your own seed and runs one way, so a decoy is recoverable by you and useless to them. Wipes and bricks are only survivable because of your written backup, which means none of this is safe to enable until that backup has been tested.

If you take one thing from this page

These features do not add security to your wallet — they add ways for your device to refuse. What actually keeps the coins is the plate in the drawer. Turn on the least you need, write down what you turned on, and never let a clever configuration substitute for a backup you have proven works.

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.