Both devices sign Bitcoin transactions offline. The difference is where your trust goes: into a secure element from one manufacturer, or into commodity parts and code you can read. This is a comparison from a shop that sells only one of the two, so we name the downsides first.
No secure element. A Coldcard stores your seed in a dedicated chip that resists physical extraction. A SeedSigner stores nothing; your seed lives on paper, steel or a SeedQR, and you load it every time. If someone steals your backup, they have your coins, with no PIN in the way. The protection is where you keep the backup, not the device.
More friction per transaction. Load seed, scan, sign, scan back, power off. A Coldcard with a PIN is ready in ten seconds. If you sign several times a week, that adds up.
QR only. No microSD transfer, no NFC, no USB data. If your wallet software cannot show and scan QR codes, a SeedSigner is useless to you. Sparrow, Specter, BlueWallet, Nunchuk and Keeper can.
Commodity parts are commodity parts. A Raspberry Pi Zero was not designed as a security device. There is no tamper evidence, no anti-glitching, no supply-chain attestation. The argument for it is different: because the parts are generic, there is nothing specific to attack, and you can buy them anywhere.
You can verify it. SeedSigner is open source under the MIT licence; hardware, software and build instructions are public, and the project is maintained by a community, not a company. Coldcard firmware was GPLv3 until November 2020; since then it ships under MIT plus the Commons Clause, which lets you read, build and modify it but not sell anything based on it. The Commons Clause FAQ says it in one line: this is not open source. Coinkite accordingly calls the code “verifiable” now, not open source.
Nothing to seize, nothing to break. A stateless device holds no secret when it is off. Lose it, have it stolen, have it searched at a border: there is nothing on it. Your backup is the only thing that matters, and you decide where that is.
No vendor dependency. If the company behind a hardware wallet disappears, changes its licence or ships a bad firmware update, you depend on them. A SeedSigner is a Pi Zero, a display and a camera. In ten years you can still build one from spare parts and the public code.
You see what you sign, every time. Address, amount and fee on a display that has no connection to the computer that built the transaction. That is what both devices promise; the SeedSigner delivers it without you having to trust a secure element you cannot inspect.
Price. A DIY kit costs from 85.00 €, an assembled SeedSigner+ from 169.00 €. A Coldcard Mk5 lists at 219 US$, the Q at 319 US$ (autumn 2026), before shipping from Canada, customs and import VAT; landed in the EU that is roughly 230 to 350 €.
The summer 2026 wake-up call. On 20 August 2026 Coinkite disclosed that a bug from March 2021 had cut the entropy of newly generated seeds on several Coldcard generations from 128 to about 40 bits: a function-name collision silently swapped the hardware random-number generator for MicroPython's software one. Attackers brute-forced the weak seeds from 30 July on and took roughly 1,800 BTC from more than 8,000 addresses before the fixed firmware (5.6.1 / 1.5.1Q) shipped and owners had to move to fresh seeds. The bug sat in publicly readable code for five years. That is the case for a device where you bring the randomness yourself, from dice, and where the code that turns it into words is open for anyone to build and test.
| SeedSigner | Coldcard | |
|---|---|---|
| Licence | MIT, fully open source | source-viewable, modification and commercial use not allowed |
| Seed storage | none, stateless; loaded per session | secure element, PIN protected |
| Data transfer | QR codes only | microSD, NFC, USB; QR on the Q |
| Hardware | Raspberry Pi Zero, Waveshare display, Pi camera; printed case | proprietary board, single manufacturer |
| Entropy | dice, camera image, or device; verifiable | device RNG, dice optional |
| Multisig | yes | yes |
| Price | kit from 85.00 €, assembled from 169.00 € | 219 / 319 US$ list price, about 230 to 350 € landed in the EU |
| Ships from | Germany, EU-wide | Canada |
Take a Coldcard if you sign often, want a PIN instead of a backup ritual, and are fine with trusting one manufacturer and its secure element. It is a good device; this page exists because people ask us for the alternative, not because the Coldcard is bad.
Take a SeedSigner if you want to verify instead of trust, sign a few times a month, already have or plan a solid steel backup, and like the idea that the device itself is worthless to a thief. It is also the cheaper way into multisig: three SeedSigners cost less than one Coldcard Q.
Take both if you run multisig. Different devices from different makers in one quorum is the setup where a flaw in any single one does not cost you anything.
It is secure in a different place. A secure element protects a seed that is stored on the device. A SeedSigner stores no seed, so there is nothing for the chip to protect. The question moves to your backup: steel, hidden, maybe split or with a passphrase. If your backup is sloppy, a Coldcard is safer. If it is good, the SeedSigner has nothing to lose.
Yes, it is a standard BIP39 seed. Type the words into the SeedSigner, add the passphrase if you used one, export the xpub and compare the first receive address with your existing wallet. If they match, both devices control the same coins. Many people run exactly this as a recovery test.
Because a pre-flashed card would make you trust us. You download the image from the SeedSigner project, verify the signature and flash it yourself. Our step-by-step guide covers that in about ten minutes.
SeedSigner+, Rugged Pill, aluminium edition or the DIY kit. Printed and assembled in Germany, 7 % off when paying with Bitcoin.