The Coldcard Q is Coinkite's flagship Bitcoin signer, and it makes no attempt to be for everyone. It has a full 50-key QWERTY keyboard, a larger 320x240 LCD, a built-in QR scanner, dual microSD slots, NFC, and runs on AAA batteries so it need never touch a computer. Everything about it is oriented around one idea: keep the private keys air-gapped and let signed transactions travel out as PSBTs over QR, SD card or NFC. It is Bitcoin-only on purpose — Coinkite argues that supporting only Bitcoin shrinks the attack surface, and there is real merit to not carrying thousands of lines of altcoin parsing code near your keys.
The security model is unusually layered. The Q uses two secure elements from two different manufacturers, so the secret is split such that compromising a single chip does not hand over your seed. On top of that sits a genuinely paranoid feature set: anti-phishing words that prove the device isn't swapped, a duress PIN that opens a decoy wallet, a brick-self PIN that destroys the device on demand, a login countdown timer, and automatic bricking after repeated wrong PINs. For someone modeling coercion or a '$5 wrench' scenario, these are not gimmicks — they are the reason people choose Coldcard.
Coinkite's track record here is relevant and, on balance, reassuring. When Ledger's Donjon lab disclosed a laser fault-injection attack against the older Mk2's ATECC508A chip around 2020, Coinkite responded publicly and had already moved newer models to the ATECC608A, which was not affected — and the attack required over $200,000 of equipment and physical possession. That is roughly how responsible disclosure is supposed to go. It is a point in Coinkite's favor that the weakness was in an older model, acknowledged openly, and already superseded.
The honesty caveat is the license. Coldcard firmware is source-available and reproducibly built, which is genuinely valuable — you can verify the code running on your device. But it ships under a Commons Clause that revokes the right to sell the software, which means it is not open source in the OSI sense. Critics in the Bitcoin community have pushed back on Coinkite marketing that blurs 'source-available' into 'open source.' It is more transparent than a closed device like Ledger, and less free than fully open firmware like Trezor's or BitBox's. Know which one you're buying.
Usability is where the Q asks the most of you. Independent reviews are enthusiastic about its security (scores like 9/10 are common) but uniform in warning that the learning curve is steep. There is no Coldcard app; the device is a signer that you pair with third-party software like Sparrow, Electrum or Bitcoin Core. At roughly $249 it is also priced well above mainstream wallets and above earlier Coldcards. The keyboard and bigger screen make it far more pleasant than the old Mk-series for entering long passphrases and reviewing transactions, but 'more pleasant' still means 'aimed at people who enjoy this.'
The verdict is that the Coldcard Q is one of the best cold-storage tools in Bitcoin — for the right owner. If you are a serious, technically comfortable Bitcoiner who wants a truly air-gapped, verifiable, feature-dense signer and you will take the time to learn PSBT workflows and pair it with Sparrow, few devices serve you better. If you want something you can hand to a relative, or you hold coins other than Bitcoin, or you don't want to read the manual, this is the wrong purchase and you should feel no shame skipping it.