{
  "slug": "coldcard",
  "category": "crypto-wallets",
  "name": "COLDCARD",
  "description": "Bitcoin-only hardware wallet from Coinkite designed for air-gapped signing using a microSD card or NFC, with secure elements, PIN protection and multisig support.",
  "website": "https://coldcard.com",
  "source": "https://github.com/Coldcard/firmware",
  "license": null,
  "platforms": [],
  "jurisdiction": {
    "code": "CA",
    "name": "Canada",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 50,
  "coverage": 100,
  "summary": "COLDCARD scores 50 out of 100 (grade D) on the crypto wallets criteria. It meets 2 of 4 criteria: open source and no ads or data sales. It does not meet no trackers or telemetry and independent audit. It is based in Canada: Five Eyes member.",
  "url": "https://privacyratings.com/crypto-wallets/coldcard/",
  "markdown": "https://privacyratings.com/crypto-wallets/coldcard/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/Coldcard/firmware/blob/master/COPYING-CC",
      "note": "All firmware code is public under the MIT license with the Commons Clause, a source-available combination that is not OSI-approved."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "The coldcard.com website loads Google Analytics through Google Tag Manager."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://coinkite.com/privacy",
      "note": "Funded by hardware sales. The privacy policy states personal information is not sold or rented to third parties."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": "https://coldcard.com/security/status",
      "note": "No independent audit is published. The security status page lists only scoped reviews and states no complete independent audit of the firmware is established."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Cloudflare Web Analytics",
        "host": "static.cloudflareinsights.com",
        "effect": "partial"
      },
      {
        "name": "Google Analytics",
        "host": "inline code",
        "effect": "no"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      },
      {
        "name": "YouTube embed",
        "host": "www.youtube.com",
        "effect": "none"
      }
    ],
    "tested_at": "2026-10-01T06:59:53.149Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}