Hardware

COLDCARD Q: first-time setup

Unbox and check the tamper evidence, set a PIN, generate a seed on the device, and take a backup you have verified.

Beginner About 45 minutes Updated Aug 17, 2026

The COLDCARD Q is a deliberately awkward device. It has a full keyboard and a slot for a memory card, and no way at all to talk to your computer over the internet. That awkwardness is the product — every inconvenience in this guide is a connection somebody decided not to give an attacker.

Setting one up properly takes about forty-five minutes. Most of that is not fiddly; it is writing things down carefully and resisting the urge to hurry. Read the whole page once before you start, then work through it.

The COLDCARD Q still in its sealed tamper-evident bag, serial number visible, resting on a plain dark surface next to a microSD card and a pen.

Image to come

Check the bag before you open it. It is the first security step, not packaging.

Before you start

  • The COLDCARD Q, unopened, bought from Coinkite or an authorised reseller.
  • Two microSD cards — one for the encrypted backup, one spare.
  • A pen and the supplied backup card, or a metal backup plate.
  • A private room, an uninterrupted hour, and no camera pointed at the desk.
  • No bitcoin. Nothing here requires funds, and you should not move any until the check at the end passes.

1Check the packaging before you power it on

Coinkite ships the Q in a sealed bag with a serial number printed on it. During first boot the device shows you a number of its own, and the two are meant to match. That is the whole trick: a bag that has been opened and resealed around a substituted device will not produce a matching number.

Read the number on the bag and keep it to hand. Inspect the bag for cuts, re-glued seams, or a second seal laid over the first, and look at the case seam and screen edge for scratches that suggest it has been opened.

  • If anything about the packaging looks wrong, stop. Contact the vendor before continuing, and do not use the device.
  • A device that arrives already showing a wallet, a PIN, or a set of recovery words is compromised. There are no exceptions to this and no innocent explanations worth gambling on.

COLDCARD Q quick start

2Set the PIN, and understand why it comes in two halves

The COLDCARD PIN is entered in two parts, and the gap between them is doing real work. You type the first half, the device responds with two words, and only then do you type the second half.

Those two words are derived from your prefix combined with a secret held inside that specific device. They will be the same two words every time you log in — which means if you are ever handed a device that shows you different words, you have caught a substitution before giving away the rest of your PIN. It is a small piece of design that quietly defeats a whole class of attack.

  • Choose a PIN you can recall under stress, not one you will need a note to remember.
  • Write the two anti-phishing words down and keep them with your backup material.
  • Record the PIN somewhere durable, and somewhere separate from your recovery words.

The PIN protects the device, not the seed

Anyone holding your recovery words can rebuild this wallet without ever seeing the PIN. The PIN buys you time if the device is physically stolen. The words are the thing that actually has to stay secret.

3Generate a new seed on the device

Choose the option to create a new wallet rather than importing one. The Q generates the seed itself, using its own entropy, and it never leaves the secure element in plaintext. Nothing you type into a computer is involved at any point.

  • Select new wallet, not import, and let the device produce the words.
  • Write the words down in order, on paper or metal, exactly as displayed.
  • Complete the word-confirmation quiz the device runs afterwards — it catches transcription errors while you can still fix them.
  • Decide your passphrase policy now, and write down whether you used one.

If you would rather supply the randomness yourself rather than trust the device's generator, the Q accepts dice rolls at this step — see rolling your own entropy. It is optional, and it is not the thing standing between you and losing your coins.

  • Never type these words into a phone, a computer, a password manager, or a photograph.
  • Never use words that came printed with the device or were supplied by anyone else.
  • Do not add a passphrase on a first setup unless you already understand how to recover from one.

The Q's screen showing a numbered word list during seed generation, angled so the words are not legible, with a hand writing on the backup card in the foreground.

Image to come

In order, by hand, once. The quiz afterwards is there to catch you.

4Take the encrypted backup

Separately from the words you just wrote down, the Q writes an encrypted backup file to microSD. This file is protected by a twelve-word backup password that the device displays exactly once.

That password is not your seed and does not replace it. Write it down before you dismiss the screen — without it the backup file is inert.

  • Write the twelve-word backup password down before moving on.
  • Save the backup to microSD, then repeat it onto a second card kept somewhere else.
  • Store the cards apart from the written recovery words where you practically can.

The backup file is a convenience, not the safety net

It restores your settings and any multisig configuration alongside the key, which saves real effort. Your handwritten recovery words remain the thing you genuinely cannot lose.

5Verify before you fund it

Everything up to this point is an assumption. This stage turns it into a fact, and it is the stage people skip.

  • Run the device's own verify-backup option against the file you just wrote.
  • Export the public keys to microSD and load them into your wallet software as a watch-only wallet.
  • Compare the master key fingerprint shown on the Q with the one shown in the software — they must match.
  • Send a small test amount, confirm it arrives, then send it back out before committing real savings.

If the fingerprints do not match, stop and work out why before going further. It means the software is watching a different wallet from the one the device will sign for, and every address it shows you would be wrong.

Next: pair it with Sparrow

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.