Coldcard Backup: How to Back Up Your Seed the Right Way
By Simon Bumford, Founder · · 9 min read
A plain-English Coldcard backup guide for UK holders: seed words, the encrypted microSD backup, passphrases, and how to restore if your device breaks.
How do you back up a Coldcard?
Back up a Coldcard in two layers. The first is the seed phrase: during setup, the device shows 12 or 24 words on its own screen. Write them down by hand, in order, on paper, and store that record somewhere safe and offline. Those words are the master key to your bitcoin, and they work in any BIP-39 compatible wallet, not just a Coldcard. The second layer is Coldcard's built-in encrypted backup. From the backup menu the device writes a file called backup.7z to a microSD card, locked with a 12 word password that the Coldcard picks for you. Write that password down too, and keep it away from the card. Do both, store the pieces in separate places, and test a restore before you move serious money. Never type your seed words into a computer or phone, and never photograph them. If you want the general method first, start with our guide to backing up a hardware wallet, then come back here for the Coldcard specifics.
Your seed words are the wallet, not the device
A Coldcard never holds your bitcoin. The coins live on the bitcoin network itself; the device holds the private keys that control them, and the seed words are a human readable copy of those keys. That is why a broken, lost or stolen Coldcard is an inconvenience rather than a disaster, provided your backup is good. Equally, anyone who restores those words on any compatible wallet controls the coins. It also explains the Coldcard's slightly stern personality. It is a bitcoin only device with no altcoin firmware at all, designed so the keys never touch an internet connected machine. Signing happens on the device, and transactions travel by microSD card, NFC tap or, on the Coldcard Q, QR codes. The device can go its whole life without being plugged into a computer. Understand that one idea, keys not coins, and every backup decision gets easier. You are not protecting a gadget. You are protecting 12 or 24 words, and everything else in this guide is about doing that well.
Coldcard Mk5, Q or Mk4: which one do you have?
Coinkite currently sells two models. The Coldcard Mk5, launched on 10 March 2026, is the compact flagship: numeric keypad, USB-C, NFC and a microSD slot, at about $189 on the official store and often a little less on sale. It has no camera, so its air gap works by shuttling a microSD card rather than scanning QR codes. The Coldcard Q, which shipped in 2024, is the larger option at about $289 list, with a UK reseller price of about £189. It adds a full QWERTY keyboard, a big screen, a built-in QR scanner and dual microSD slots, and it runs on three AAA batteries, so it never needs a cable at all. The Mk4 was superseded by the Mk5 in March 2026 and is no longer sold on the official store, though it still receives firmware updates. If you already own one, it remains safe to use, and everything in this guide applies. New buyers should simply get the Mk5 or the Q. The backup process is the same across the family; only the input method differs.
Writing down your Coldcard seed phrase, step by step
Set up in a private space with no cameras about, including your own webcam and phone. When the Coldcard generates a wallet it displays the seed words on its own screen as one numbered list, and that screen is the only place those words should ever appear. Copy each word onto paper by hand, in order, exactly as shown. Write clearly: a scruffy n can read as an m years later. The device will quiz you on a few of the words before it lets you continue, which catches most transcription mistakes. Then the rules that keep the backup safe. Never type the words into a computer or phone, not even once, not even into a file you plan to delete. Never photograph them. No cloud storage, no email drafts, no password managers: those are exactly the places thieves look first. Paper kept somewhere safe is good; many holders go further and stamp the words into steel so fire and flood cannot take them. Keep the record somewhere separate from the Coldcard itself, so one burglary cannot collect both. For the wider principles we follow at Bitzo, see our security page.
The Coldcard microSD backup: what backup.7z actually is
Alongside the words, the Coldcard offers something most wallets do not: a proper encrypted backup. Choose the backup option from the menu and the device writes a file called backup.7z to a microSD card. Inside is everything the device knows, including the master seed and your settings, sealed with strong encryption. The clever part is the password. The Coldcard picks 12 words at random to act as the encryption password for the file. They look like a seed phrase but they are not one; they have nothing to do with your wallet and only unlock this file. Write them down and store them well away from the card itself. Split this way, neither piece is dangerous alone. A microSD card found in a drawer is useless without the 12 word password, and the password is useless without the file. That makes the encrypted backup far more forgiving to store than raw seed words. The official Coldcard backup documentation walks through the exact menus. Refresh the backup whenever you change something that matters, such as adding a multisig setup, and label the card so future you knows what it is.
Do I need to write down the passphrase separately?
Yes. A BIP-39 passphrase is an extra word or sentence you choose yourself, added on top of the seed. Enter it and the Coldcard opens a completely different wallet; leave it out and you get the base wallet. It is a powerful feature, and the Coldcard Q's QWERTY keyboard makes long passphrases genuinely practical. But it changes your backup maths. The passphrase is not part of your 24 words, and if you forget it, a perfect seed backup will not bring those coins back. Nobody can recover it for you. So record the passphrase, and store it separately from the seed words, so that no single discovery exposes the full wallet. One more habit worth stealing from the official passphrase documentation: note the wallet fingerprint shown when you enter the passphrase. A passphrase typed with one wrong character silently opens a different, empty wallet, and the fingerprint is how you confirm you are in the right one.
Seed XOR: is it worth doing?
Seed XOR is a Coldcard feature that splits your seed into two, three or four parts. Each part looks and behaves like an ordinary 24 word seed phrase, which gives you plausible deniability, and you need every part to rebuild the original. It is aimed at people worried about physical coercion, or about a single hiding place being discovered. For most UK holders, the honest answer is: probably not yet. Splitting a secret multiplies the ways you can lose it; misplace one part and the whole wallet is gone. The simple combination of hand written seed words in one location plus the encrypted microSD backup in another already covers theft, fire and device failure without adding that fragility. If your holdings or threat model justify it, do a full practice restore from the parts before you destroy any original record, and never rely on memory for where the parts live. Advanced schemes fail quietly, usually years later, and usually for the person who inherits the puzzle rather than the person who built it.
What happens if my Coldcard breaks?
Nothing happens to your bitcoin. The coins sit on the network, and your backup is the key to them, so a dead device is a shopping problem, not a crisis. Buy a replacement from the official store, then restore one of two ways. With the encrypted backup, choose to restore a backup on the new device, insert the microSD card and enter the file's 12 word password; the Coldcard comes back with your seed and settings intact. With the seed words alone, choose to import a seed and enter the words on the device itself. Because the words follow the BIP-39 standard, they will also restore into other compatible wallets if you ever leave the Coldcard family. Whichever path you take, finish with two checks. Confirm your first receive address on the new device's own screen and check it matches what your computer wallet shows, then send a small test amount and watch it arrive before moving anything larger. Ten minutes of testing turns a stressful day into a dull one, which is exactly what you want from bitcoin storage.
Who a Coldcard suits, and where to buy one safely
The Coldcard is widely treated as the reference device for serious bitcoin cold storage, and the backup tooling above is a big part of why. It suits holders with meaningful sums who want depth: duress PINs, dice roll entropy, Seed XOR and genuinely air gapped signing. It is also honest to say the menu driven keypad UX intimidates plenty of newcomers. If you are backing up your first modest stack, a simpler device such as the Blockstream Jade may serve you better, and our Jade backup guide covers it. Buy only from the official Coinkite store, which ships from Canada in US dollars with UK import VAT and courier fees on top, or from a reseller that Coinkite itself links to. Never buy second hand: a tampered device can be set up to leak your keys, and no bargain is worth that. Finally, treat every email claiming to come from any wallet company as phishing until proven otherwise. Coinkite has not leaked customer data, but Trezor and Ledger both have, and those lists fed years of convincing scam emails. Real firmware updates are announced on the official site, never by an email link.
The backup that survives you
There is one failure mode this guide cannot fix with better handwriting or a second microSD card: a perfect backup that dies with you. If nobody you trust knows the coins exist, or where the seed words live, or what the 12 word backup password unlocks, then your Coldcard backup is only as durable as your own health. Families lose bitcoin this way far more often than hackers take it. You do not need to hand anyone your keys today. You need a plan that lets the right person find and use the backup when the time comes, and nobody else before then. That is what our crypto inheritance planning is built for, and the free inheritance scorecard takes a few minutes and shows where your current setup would fall down. A backup should outlive the device. The good ones outlive their owner too.
Frequently Asked Questions
Can I restore a Coldcard seed phrase on another brand of wallet?
Yes. Coldcard seed words follow the BIP-39 standard, so the same 12 or 24 words will restore your bitcoin wallet on most other hardware and software wallets. The encrypted backup.7z file is different: it is designed for restoring onto another Coldcard. If you ever switch brands, restore from the seed words, verify the first receive address on the new device's screen, and send a small test amount before moving the rest.
What is the 12 word password on a Coldcard backup?
When the Coldcard creates its encrypted microSD backup, it randomly picks 12 words to use as the encryption password for the backup.7z file. They are drawn from the same word list as seed phrases, but they are not a wallet and have nothing to do with your seed. Write them down, keep them separate from the card, and remember that without them the backup file cannot be opened.
Is the Coldcard microSD backup safe to store at home?
Reasonably, yes, because the file is encrypted and the card is useless without its 12 word password. The sensible pattern is to keep the card and the password in different places, for example the card at home and the password elsewhere. Avoid keeping the card, the password and the device together, since a single burglary would then collect everything at once.
Do I need a Coldcard Q to be air gapped, or is the Mk5 enough?
Both are genuinely air gapped. The Mk5 signs transactions by passing files on a microSD card, or by NFC tap, and never needs a USB connection. The Q adds a camera and screen based QR workflow plus battery power, which many people find quicker and more comfortable. The security model is the same across the family; the Q mainly buys convenience and a much better keyboard.
Can I still use a Coldcard Mk4 in 2026?
Yes. The Mk4 was superseded by the Mk5 in March 2026 and is no longer sold on the official store, but it still receives firmware updates and remains safe to use. Its backup process is the same as the current models. If you are buying new, choose the Mk5 instead, which sits in a similar price bracket with a better screen and keypad.
What happens if I forget my Coldcard passphrase?
The coins in that passphrase wallet become unreachable, even with a perfect seed backup, because the passphrase is an extra secret that is never stored in your 24 words. No company can reset it for you. This is why a passphrase needs its own written backup, stored separately from the seed words, and why you should check the wallet fingerprint each time you enter it.
Sources
Ready to plan your crypto inheritance?
Speak to our UK-based team about your situation. No obligation, no pressure.
Speak to us