Coinkite welcomes private reports of security vulnerabilities. Good-faith
research helps us protect our users and improve our products.
Our Security & Transparency directory links current product status, active advisories, verification resources, disclosure records, and company notices. Our Security Disclosure History records public security research, coordinated disclosures, professional reviews, internal findings, and security advisories affecting COLDCARD.
The following are in scope for review:
The following generally are not eligible for a reward unless they demonstrate a direct security impact within the scope above:
If you are unsure whether a system or test is in scope, contact us before testing.
Email security@coinkite.com. Do not send sensitive exploit details in the first cleartext message.
To request the Coinkite security team's PGP key and full fingerprint, contact us at that address first. You may include your own public key and full fingerprint. Confirm the fingerprint before sending sensitive material.
Please include:
Never send a funded seed phrase, private key, PIN, passphrase, wallet backup, customer record, or other production secret as proof.
We review reports based on severity, user impact, reproducibility, and the evidence provided. Reports indicating an immediate risk to user funds, private keys, or customer data may be prioritized. Coinkite may request additional information or take defensive action while assessing a report.
Response times depend on the report and current volume. Receipt, acknowledgement, discussion, or a related code change does not mean that a report has been validated, accepted, or approved for a reward, and does not guarantee further communication.
Coinkite may investigate, remediate, or make defensive changes at its discretion. If a report is validated, Coinkite may propose a coordinated-disclosure plan based on the risk, exploitability, affected products, and work required to provide a safe fix. No acknowledgement, remediation, or disclosure timeline is promised.
Researchers are asked to keep sensitive findings private while publication would create an avoidable risk to users. Any public attribution is determined case by case.
Coinkite evaluates rewards case by case and at its sole discretion. It may offer a Bitcoin bounty, personalized Bugmug, public credit, or replacement hardware, but no report creates an entitlement to payment, attribution, replacement hardware, expense reimbursement, or any other benefit.
Coinkite may consider novelty, severity, demonstrated impact, reproducibility, and report quality. Duplicate, previously known, out-of-scope, or unproven reports may not qualify. Coinkite may change or discontinue the rewards program at any time.

Design subject to change. While supplies last.
---Updated: August 2026