Encrypted Backups
Background#
The COLDCARD® is unique in that we offer a backup feature to save your wallet seeds to the MicroSD card(s) or Virtual Disk. Settings and other meta is saved as well. The encrypted file can be treated as any other file because we use AES-256 encryption, with a strong passphrase.
Even when using this feature, you should still have an offline-only copy of your seed words, ideally on a SEEDPLATE. Use the encrypted backup feature for convenience and extra duplication.
Create Backup#
Backup Workflow Behavior by Firmware Version#
Starting with firmware 5.6.1 on Mk4/Mk5 and 1.5.1Q on Q, Backup System, Clone Coldcard, and Key Teleport's Full COLDCARD Backup capture the wallet currently in effect and its associated settings. Each workflow warns before exporting an active Temporary Seed or BIP-39 passphrase wallet.
Before those releases, the workflows differed:
Backup Systemalready captured an ordinary active Temporary Seed. With a BIP-39 passphrase wallet active, however, it defaulted to the base Master Seed. Firmware versions supporting passphrase-wallet backups offered the effective passphrase-wallet XPRV only as an alternate choice.Clone Coldcardand Key Teleport'sFull COLDCARD Backupcaptured the base Master Seed and its settings even when a Temporary Seed or passphrase wallet was active.
Steps to Create a Backup
-
From the Main Menu, go to:
Advanced/Tools > Backup > Backup System.

-
The backup captures the wallet currently in effect and the supported settings and data associated with that wallet. If a BIP-39 passphrase wallet or Temporary Seed is active, the COLDCARD warns which effective wallet will be backed up before continuing.
-
With the base Master Seed active, the backup includes its Seed Vault and its associated settings and data. With a Temporary Seed or passphrase wallet active, the backup uses that wallet's separate settings: it does not include the parent wallet's Seed Vault, multisig wallets, Secure Notes & Passwords, or other parent settings. Restore the Master Seed and create a separate backup to preserve that parent-wallet data.
-
A passphrase-wallet backup contains the effective XPRV. It does not contain the parent seed words or the passphrase. Keep the parent seed and exact passphrase if your recovery plan depends on reconstructing the original BIP-39 wallet structure.
-
-
COLDCARD will pick 12 words as a password. These words have nothing to do with your wallet seed and are chosen randomly.

-
While viewing the 12 words, press 1 on the Mk4 or the QR key on the Q to display the words as a QR code.

-
If you previously saved a backup password to the device, COLDCARD will offer to reuse it. If accepted, the password quiz is skipped.
-
-
Next you will have to pass a quiz, proving you've made a backup of the words. We have made the quiz easier, as it does not verify every word.
-
After successfully completing the password quiz, you may save the words to the COLDCARD for future use by pressing 1.

-
The new file is written to the MicroSD card, or the Virtual Disk, if it is enabled and no SD card is inserted.

-
The file will be named
backup.7z. If there was already a backup file, a number is appended to the filename. The most recent backup file should have the highest number. -
Q Only: If two MicroSD cards are inserted, the file will be saved to the card in Slot A. If there is only one card inserted, then the file will save to it no matter which slot it is in.
-
-
To make a second copy of the backup, put in another MicroSD card and press 2.
Important
We strongly recommend using real Industrial Grade MicroSD cards for backups: At least 2 cards and write 3 times to each card to mitigate future issues.
You can find them at the Coinkite store.
True SLC design with wear-leveling & block management, and environmentally tested for bend, torque, salt spray, solar radiation, and harsh temperatures: -40°C to +85°C.
Verify Backup#
This command does a quick CRC32 check over the file. It's useful to check the file was not truncated or damaged in transit. It is not cryptographically secure, meaning the file maybe artificially created or deliberately tampered with. However, it's still a useful feature when you are confident of the chain of custody of your file.
No password is required since the file is not decrypted in this process.
Steps to Verify a Backup
-
From the Main Menu, choose:
Advanced/Tools > Backup > Verify Backup.

-
Select the backup you wish to verify from the list.

Restore Backup#
The backup file can be used to restore the seed and settings as the Master Seed of a COLDCARD, or as a Temporary Seed.
Restore Backup as Master Seed#
To restore the backup as the Master Seed, you must use a new COLDCARD with no wallet defined, or wipe the seed from the COLDCARD, which is naturally a dangerous operation.
Consequences of Wiping Seed Words
Wiping your seed words will result in the loss of access to your Bitcoin, passwords, notes, and settings stored on your device. You can regain access to them by restoring your seed words from backup.
Steps to Restore a Backup as the Master Seed
-
With a COLDCARD that has no Master Seed, navigate to:
Import Existing > Restore Backup.

-
Choose your backup file from the list.
-
Enter the 12 word password for the backup encryption that was saved when the backup was created.
- Q Only: Press the QR key during the password entry prompt to scan a QR code of your 12 words.

-
The COLDCARD displays the master fingerprint of the seed stored in the backup. Compare it with the expected XFP from your recovery records. Press ✔/ENTER only if it matches and you intend to load it as the Master Seed; press X to abort.
-
Review the secure hardware defaults applied during restoration, continue to the success screen, and press ✔/ENTER to reboot with the restored seed and settings.
Restore Backup as Temporary Seed#
Restoring as a Temporary Seed can be useful to test your backup without having to wipe your Master Seed.
Steps to Restore a Backup as a Temporary Seed
-
Starting at the Main Menu, navigate to:
Advanced/Tools > Temporary Seed > Coldcard Backup.

-
Choose your backup file.
-
Enter your 12 word password to decrypt the backup.
- Q Only: Press the QR key during the password entry prompt to scan a QR code of you 12 words.

-
The COLDCARD displays the master fingerprint of the seed stored in the backup. Compare it with the expected XFP from your recovery records. Press ✔/ENTER only if it matches and you intend to load it as a Temporary Seed; press X to abort.
-
Press 1 to save the Temporary Seed to the Seed Vault (if enabled), or press ✔/ENTER to use the Temporary Seed without saving it.
Clone COLDCARD#
You can copy the wallet currently in effect and its settings from your COLDCARD onto a blank COLDCARD to make a "clone" (aka. warm backup). This process uses the same encrypted backup file format (AES-256 in 7z) but the encryption key is chosen automatically using Diffie-Hellman key exchange.
You'll need a blank COLDCARD (PIN chosen, but no seed words) and a MicroSD card for the data transfer.
If a BIP-39 passphrase wallet or Temporary Seed is active on the source, COLDCARD warns before creating the clone. The clone captures that effective wallet rather than the parent seed. For a passphrase wallet, the transferred secret is its XPRV; the parent seed words and passphrase are not included. Only the settings and data associated with the effective wallet are included; parent-wallet Seed Vault entries, notes, passwords, multisig wallets, and other settings require a separate clone or backup made with the Master Seed active.
For more details use the full guide: Clone COLDCARD, or the dropdown below for just the simple steps.
Steps to Clone a COLDCARD
-
On a blank COLDCARD, choose:
Import Existing > Clone Coldcard, or use the top-levelMigrate Coldcardmenu item.

-
Be sure a MicroSD card is inserted, and a small file (containing an ephemeral public key) is written to it.
-
While keeping power active to the blank COLDCARD, take the MicroSD to another COLDCARD.
-
Insert the SD card into the COLDCARD you wish to clone, and go to:
Advanced/Tools > Backup > Clone Coldcard.

-
A backup file is written to the SD card.
-
Remove the SD card back and bring it to the blank COLDCARD.
-
Insert the SD card and press ✔/ENTER. After decrypting the clone data, the Empty COLDCARD displays the master fingerprint of the seed it is about to load.

-
Compare the displayed fingerprint with the expected XFP of the wallet selected on the Source COLDCARD. Press ✔/ENTER only if it matches; press X to abort.
-
Continue through the security-defaults and success screens, then reboot the COLDCARD for the cloned seed and settings to take effect.
- The key pairs used in this process are randomly picked at the time of use, and are not related to seed phrase or master secret.
- Files written to the MicroSD card are deleted as the process is completed.
- Only the two COLDCARDs involved can reconstruct the session key, so the complete back-and-forth process must be repeated to clone additional COLDCARDs.
About the Backup File Contents#
The file we create is a standard 7z archive with AES-256 encryption, in CBC mode. The 256-bit key is a SHA256 hash of a passphrase, hashed in a particular way to support 7z compatibility. We know the passphrase has at least 128-bits of entropy because the COLDCARD uses it's true random number generator (TRNG) to pick it.
Once decrypted, which is possible using any 7z archive tool, the contents are a simple text file containing the private wallet secret that was in effect when the backup was created, plus the captured settings and metadata associated with that wallet. For a BIP-39 passphrase wallet, that private wallet secret is the effective XPRV, not the parent seed words or the passphrase.
Restoring the backup file onto a replacement COLDCARD is a simple process that merely requires entering the 12 words.
Is it secure?#
We use AES-256 encryption, wrapped in a 7z archive. The passphrase is chosen at random, as 12 words from the BIP-39 word list. This gives effectively 132 bits of security without any key stretching. The 7z file format adds a 16-byte salt and random 16-byte IV (initialization vector), plus 8,192 rounds of key stretching. We are not relying on that however, because of the long key itself (128-bits).
Proving It Works#
Because we are using a standard file format, you can verify the process and that the data is in fact encrypted. Any 7z tool that supports AES256-SHA256 encryption should be able to read the files we make. Take the 12 words and put them together with a single space between each word (all lowercase). The decoded archive will contain a single text file with a random file name, which is easy to read and understand.
Primary vs. Secondary#
(Applies to Mk1 and Mk2 only)
The current wallet, along with data for the corresponding duress wallet is recorded during the backup. Details of the other wallet (secondary when using the primary, for example) are not saved. You should backup primary and secondary wallets individually, but they can be stored onto the same MicroSD card.
Limitations#
- The archive file names are not encrypted. You can see there is a single
text file
word(number).txtin the encrypted file without decrypting it. - The device PIN code is not preserved during backup.
- We produce standards-compliant files, but do not support reading any file except the ones produced by COLDCARD.
- Do not attempt to edit the file and restore it onto a COLDCARD.
- You cannot construct a file for the COLDCARD to read because we implement only enough to support reading files that we know that we've produced.
- There is no plausible deniability here: the 7z file is clearly a COLDCARD backup file. If the backup captured the parent seed, a separately stored BIP-39 passphrase remains required for its passphrase wallets. If the backup captured an active passphrase wallet, decrypting it reveals that wallet's effective XPRV; the passphrase is not an additional barrier to use of that XPRV.
- Learn more about backup files in our technical paper.