Coldcard has spent since 2017 building a reputation as the signer for people who take custody seriously, and the Mk4 is the maturation of that philosophy. It is Bitcoin-only on purpose: Coinkite argues that dropping every other asset shrinks the attack surface and keeps the firmware focused. Whether or not you agree, the result is a device whose entire design budget goes toward one job — protecting Bitcoin keys — rather than chasing a long list of supported tokens.
The security architecture is the headline. The Mk4 stores your seed across two secure elements sourced from different manufacturers, Microchip's ATECC608 and Maxim's DS28C36B. The logic is defense in depth: even if a flaw is found in one vendor's chip, the other still stands between an attacker and your keys. That dual-vendor approach is uncommon and genuinely thoughtful. The honest caveat is that secure-element silicon is proprietary and shipped under NDA, so that specific layer cannot be fully open-sourced the way the rest of the firmware is — a trade-off Coldcard makes deliberately and explains openly.
Air-gap is where the Mk4 shines in daily use. You can run the entire signing flow over a microSD card using PSBTs, so the device never touches a USB data connection or the internet. For a threat model that assumes your computer is compromised, that physical isolation is the whole point. Note the nuance: the Mk4 also includes USB and NFC, and purists point out that a device with wireless capability isn't 'air-gapped' in the strictest sense. NFC is optional and can be fully disabled, and you can simply never use USB — but the isolation is something you choose and maintain, not something the hardware forces.
The feature depth is where power users fall in love and beginners bounce off. BIP85 for deriving child seeds, duress PINs and a 'brick-me' PIN, Seed XOR for splitting backups, robust multisig, and granular PSBT handling are all here. Used correctly, these are serious tools for serious threat models. Used carelessly, they are also ways to lose access to your own funds. The documentation is thorough but written for someone who already speaks the language, which is exactly why we keep flagging the learning curve.
Price and positioning round out the picture. At roughly $160 it costs about double a typical mainstream wallet, and it does one thing — Bitcoin — where others juggle hundreds of assets. Neither is a flaw so much as a statement of intent: you are paying a premium for depth, isolation and a long, battle-tested lineage, not for breadth or hand-holding.
Our verdict lands at 4.4 because the Mk4 is close to the best in class at what it targets, and the points it loses are almost entirely about accessibility. If you are experienced, want air-gapped signing, and value advanced backup and duress features, few devices match it. If you want to hand a relative a wallet they can use without a manual, look elsewhere — and that mismatch is a fit problem, not a quality one.