COLDCARD Security Update Fixed firmware is available. Check if you need to migrate your seed. Learn more
Newsletter Blog OpResearch Careers Resellers Contact Store
Response-time notice: We are currently experiencing a higher-than-usual volume of security reports. Submissions are triaged based on the reported risk and available information, but responses may be delayed. Reports indicating an immediate risk to user funds, private keys, or customer data are prioritized. Do not disclose sensitive findings publicly.

Responsible Disclosure


Coinkite welcomes private reports of security vulnerabilities. Good-faith research helps us protect our users and improve our products.

Our Security & Transparency directory links current product status, active advisories, verification resources, disclosure records, and company notices. Our Security Disclosure History records public security research, coordinated disclosures, professional reviews, internal findings, and security advisories affecting COLDCARD.

Scope

The following are in scope for review:

  • Security vulnerabilities in Coinkite hardware, firmware, and bootloaders.
  • Security vulnerabilities in first-party production applications, protocol libraries, and source code maintained by Coinkite that directly affect a Coinkite product, user funds, private keys, or other secrets.
  • Vulnerabilities in Coinkite-operated production websites and services that demonstrate unauthorized access, code execution, exposure of customer or order data, or compromise of an official software release or update process.

The following generally are not eligible for a reward unless they demonstrate a direct security impact within the scope above:

  • Third-party applications, websites, and services that Coinkite does not control.
  • Missing security headers, clickjacking, email-authentication configuration, or automated scanner output without a reproducible security impact.
  • Duplicate or previously known issues, and theoretical weaknesses without a reproducible security effect or demonstrated path to exploitation.

If you are unsure whether a system or test is in scope, contact us before testing.

Prohibited testing activities

  • Do not test devices, accounts, funds, data, or systems that you do not own or have explicit permission to test.
  • Do not access, retain, alter, destroy, disclose, or use customer data, private keys, seed phrases, credentials, third-party funds, or other confidential data.
  • Do not initiate unauthorized transactions, use social engineering or phishing, commit fraud, cause denial of service, or otherwise disrupt Coinkite or its users.
  • Do not exploit a vulnerability beyond the minimum necessary to demonstrate its existence and impact.

How do I report a vulnerability?

Email security@coinkite.com. Do not send sensitive exploit details in the first cleartext message.

To request the Coinkite security team's PGP key and full fingerprint, contact us at that address first. You may include your own public key and full fingerprint. Confirm the fingerprint before sending sensitive material.

Please include:

  • The affected product, hardware revision, firmware or software version, and repository.
  • A concise impact assessment and the conditions required to reproduce the issue.
  • Reproduction steps and, when safe, a minimal proof of concept.
  • Any actions you have already taken and whether you believe users face immediate risk.
  • Your name or handle, whether you want public credit, and your preferred contact method.

Never send a funded seed phrase, private key, PIN, passphrase, wallet backup, customer record, or other production secret as proof.

What happens after I report?

We review reports based on severity, user impact, reproducibility, and the evidence provided. Reports indicating an immediate risk to user funds, private keys, or customer data may be prioritized. Coinkite may request additional information or take defensive action while assessing a report.

Response times depend on the report and current volume. Receipt, acknowledgement, discussion, or a related code change does not mean that a report has been validated, accepted, or approved for a reward, and does not guarantee further communication.

How is the disclosure timeline set?

Coinkite may investigate, remediate, or make defensive changes at its discretion. If a report is validated, Coinkite may propose a coordinated-disclosure plan based on the risk, exploitability, affected products, and work required to provide a safe fix. No acknowledgement, remediation, or disclosure timeline is promised.

Researchers are asked to keep sensitive findings private while publication would create an avoidable risk to users. Any public attribution is determined case by case.

Are rewards available?

Coinkite evaluates rewards case by case and at its sole discretion. It may offer a Bitcoin bounty, personalized Bugmug, public credit, or replacement hardware, but no report creates an entitlement to payment, attribution, replacement hardware, expense reimbursement, or any other benefit.

Coinkite may consider novelty, severity, demonstrated impact, reproducibility, and report quality. Duplicate, previously known, out-of-scope, or unproven reports may not qualify. Coinkite may change or discontinue the rewards program at any time.

Design subject to change. While supplies last.

---

Updated: August 2026

× Home Blog OpResearch Security & Transparency Careers Contact Store