Migrate From COLDCARD to OneKey: Create a New Seed Phrase and Transfer Bitcoin Safely

OneKey TeamOneKey Team
/Updated Aug 7, 2026

Key Takeaways

  • Importing a legacy COLDCARD seed phrase into OneKey only restores the same private keys. Handling an affected legacy seed requires creating a completely new seed phrase on OneKey and transferring the funds on-chain.
  • The correct order is to verify the device and software source, back up the new phrase offline, check the receiving address on the hardware screen, make a small test transfer, and then migrate the remaining UTXOs.
  • A multisig migration must create and back up a new policy using the new OneKey key. Merely changing the physical device, its name, or the coordinator configuration does not rotate the keys.

There are two completely different ways to switch from COLDCARD to OneKey:

  • Importing the original seed phrase into OneKey merely restores the same private keys on a new device.
  • Creating a completely new seed phrase on OneKey and transferring the bitcoin on-chain to a new address is a genuine key migration.

If the legacy seed phrase may have been generated by affected COLDCARD firmware, the first method does not solve the problem. New hardware does not re-randomize the legacy seed; it simply derives the original wallet according to the same standard. This article covers the second method: create new keys, verify the destination, test the transfer, migrate the balance, and retire the old keys.

OneKey confirmed in an official statement that OneKey devices and codebases are not affected by this COLDCARD RNG defect. The recovery-phrase entropy required to create a new wallet on a OneKey device is generated inside the device’s EAL6+ secure element. The correct value of migrating to OneKey is therefore not switching devices while continuing to use the old phrase, but creating completely new keys from an independent hardware entropy source and then completing an on-chain transfer.

Before You Begin, Confirm Whether You Really Need to Rotate Keys

Coinkite’s security advisory instructs users to assess risk based on the model, firmware branch and version, dice input, and BIP-39 passphrase at the time the seed phrase was generated. Confirm these conclusions before beginning a migration:

  • Fixed firmware corrects only subsequent seed generation; it cannot repair a legacy seed phrase.
  • An affected legacy seed that does not qualify for the official independent-dice exception should be replaced.
  • A strong, unique passphrase adds a barrier, but Coinkite still recommends migrating promptly.
  • Follow the conservative path if the generation version or dice conditions are unknown.

If your seed phrase is outside the advisory’s scope and you merely want another device to serve as a backup signer for the same wallet, importing the legacy phrase is technically a “recovery,” not the key rotation covered here. Do not mix these two objectives in one operation.

Migration Preparation: Do Not Search for Tools Under Pressure

First set aside an uninterrupted period and prepare the following:

PreparationWhy it is needed
A device obtained from OneKey or a clearly authorized channelReduces supply-chain replacement and preset-seed risks
The official OneKey App and latest stable firmwareUsed for device authentication, account creation, and address verification
The legacy COLDCARD wallet, still able to sign normallyUsed to initiate the on-chain transfer from the old addresses
A trusted backup and account information for the old walletPrevents a device failure during migration from blocking completion
Offline backup media for the new walletRecords the completely new recovery phrase and optional passphrase
A small test amount and enough miner feesVerifies the complete path before the main balance is transferred
A place to record transaction IDs, wallet fingerprints, or multisig descriptorsSupports verification and recovery, but must never contain a plaintext seed phrase

Do not store the new or old seed phrase in a chat window, web form, cloud document, screenshot, photo album, or internet-connected note. Legitimate OneKey, COLDCARD, and coordinator support teams do not need your recovery phrase.

If an unauthorized spend has already appeared from an old address, a general tutorial may not fit the situation. Do not destroy the device or logs first. Preserve transaction IDs, wallet fingerprints, firmware versions, and lawfully obtained records, and consider using a trusted professional incident-response channel.

Step 1: Verify the Source of the Destination OneKey Device and Software

After receiving the OneKey device, first inspect the packaging and tamper-evident state. The official OneKey Pro Getting Started Guide clearly warns users not to use a device with a preset PIN or recovery phrase. Stop and contact official support if the packaging or seals appear abnormal.

Get the app from the official OneKey download page. After connecting the device, follow the device anti-counterfeiting verification procedure to confirm on-device and review the result. Anti-counterfeiting verification is one part of the supply-chain check; it does not make the backup, host computer, or every later transaction automatically safe.

Advanced users can also follow OneKey’s firmware-consistency verification documentation to compare checksums for officially signed files, GitHub CI build artifacts, and CDN files. If you do not perform manual verification, at minimum use only updates delivered by the official app or official firmware website. Do not install firmware files forwarded in a group chat.

Step 2: Choose “Create New Wallet” on OneKey

On a new or securely reset OneKey device, select Create New Wallet, not Import Wallet. For OneKey Pro, the official workflow asks the user to choose a supported recovery-phrase length, set a new PIN, read and record the recovery phrase from the device screen, and complete the word-order check.

Follow four boundaries:

  1. The destination OneKey device must generate the recovery phrase on the spot. Do not enter the legacy COLDCARD phrase into OneKey.
  2. Read it only from the device screen. The app or a website should not ask to display a hardware-wallet recovery phrase.
  3. Record it offline in the exact order. Correctly spelled words in the wrong positions will not restore the original wallet.
  4. Complete on-device verification. Before transferring the main balance, confirm that the paper or metal backup passes the device’s word-order check.

If you have only one destination device, do not reset it repeatedly for a “test recovery” before understanding the process. At minimum, complete the device’s built-in recovery-phrase check. For a full recovery rehearsal, prefer another trusted, blank, compatible hardware device and complete the rehearsal before transferring substantial funds.

Step 3: Decide Whether to Use Bitcoin-only, AirGap, and a Passphrase

These options change the daily workflow, so decide before sending the main funds to a receiving address.

Bitcoin-only Mode

OneKey’s documentation says that when the app and firmware meet the required versions, OneKey Pro can switch to Bitcoin-only mode, leaving only Bitcoin and related functions in the interface, and later return to standard mode. The switching process requires confirmation that the recovery phrase has been backed up. Version requirements may change, so do not follow an old screenshot blindly.

Bitcoin-only mode reduces the currently enabled feature set, but it does not replace address verification, backups, or host security. If you also need to manage other networks on the same device, first decide whether standard mode better fits your needs.

QR AirGap

The OneKey Pro AirGap documentation says that enabling AirGap disables USB, Bluetooth, and NFC data transfer and uses QR codes to exchange requests and signed results between the app and device. The documentation currently explicitly covers Bitcoin and EVM addresses, so this path can be used for a Bitcoin migration.

AirGap reduces direct data connections, but a QR code still carries a transaction that must be parsed. Whether you use QR, USB, or Bluetooth, verify the address, amount, and fee on the OneKey device screen.

A New Passphrase

A passphrase is an advanced feature that combines with the recovery phrase to derive a different wallet. If you decide to configure one for the new wallet, use completely new, unique content that can be recovered accurately, and store it separately from the recovery phrase. OneKey’s passphrase documentation warns that losing the passphrase makes the corresponding wallet inaccessible and that any different character opens another valid address space.

Do not add a passphrase during a rushed migration if you cannot back it up reliably. Complexity by itself is not a security benefit.

Step 4: Connect OneKey App and Verify the Receiving Address on the Hardware Screen

After initializing the new wallet, connect OneKey to the official app and create a Bitcoin hardware account. Open Receive, select Bitcoin mainnet and the account you plan to use, then choose device verification.

According to OneKey’s send-and-receive documentation and the Pro getting-started guide:

  1. The app displays the receiving address.
  2. The OneKey device displays the complete address at the same time.
  3. Compare the two character by character and confirm on the device.
  4. Give the old wallet only an address that has been verified on the device.

A new seed phrase should generate new addresses, so do not expect them to match the legacy COLDCARD addresses. If an address is unexpectedly identical, stop and confirm that you did not import the old phrase by mistake, connect the wrong account, or continue viewing the old watch-only wallet.

Also verify that the network is Bitcoin mainnet, not a test network or a different network carrying an identically named asset. Compare the address with the device screen again after copying and pasting to detect clipboard malware.

Step 5: Send a Small Test From the Old Wallet

Use the original COLDCARD and your familiar Bitcoin coordinator to create a transaction that sends a recognizable small test amount to the new address verified on the OneKey screen. Before signing, check that:

  • The destination matches the address verified on the OneKey device.
  • The amount and miner fee match your expectations.
  • Change returns to a change address you recognize in the old wallet.
  • The selected UTXO and account are correct, and no funds outside the migration plan are moved accidentally.

After broadcast, save the transaction ID, wait for the confirmation condition you set in advance, and then check receipt in OneKey App. A balance in the app is only the first layer of verification. Confirm again that the device can open the correct wallet and that the new recovery phrase and optional passphrase you saved correspond to the same account.

Do not use “the test amount is displayed” as a reason to skip checking the backup. Receiving funds does not prove that you will be able to recover or spend them later.

Step 6: Transfer the Remaining Bitcoin

After the test is complete, list every UTXO and account in the old wallet that is still controlled by the legacy seed. Decide whether to migrate in one transaction or several according to your privacy, fee, and accounting requirements. Do not blindly combine UTXOs that you did not want to link merely because the guide uses the word “all.”

Repeat the same checks for every batch:

  1. Display and confirm the destination address again on the OneKey device; do not copy it from an old screenshot or chat history.
  2. Verify transaction outputs, the amount, and miner fee on the legacy COLDCARD before signing.
  3. Record the transaction ID after broadcast and confirm that the funds enter the intended new account.
  4. Check the old wallet for omitted UTXOs, other accounts, passphrase wallets, or unconfirmed change.

Bitcoin transactions are generally irreversible. If the address, account, passphrase, balance, or device fingerprint does not match, stop. Do not “try again” with a larger transaction.

Multisig Migration: Replacing a Device Is Not Replacing a Cosigning Key

Multisig users need an additional step: create a completely new policy that contains the new OneKey key. Importing the legacy COLDCARD seed into OneKey, or changing a device label from COLDCARD to OneKey in a coordinator, does not rotate the cosigning key.

For a 2-of-3 wallet, a cautious order is:

  1. Generate a new seed phrase on OneKey and export the corresponding cosigner public-key information.
  2. Create a new 2-of-3 wallet with the signers you intend to retain or rotate at the same time.
  3. Back up the new wallet’s descriptor, threshold, signer fingerprints, and derivation information. A descriptor is not a seed phrase, but it still must be stored carefully.
  4. Verify the new policy and receiving address on multiple signing devices.
  5. Send a small test to the new multisig address, then complete one test spend with enough signers.
  6. Perform an on-chain transfer from the old multisig policy to the new policy.

OneKey provides an official guide to BTC multisig with Sparrow, covering threshold configuration, signer addition, configuration backups, receiving, and broadcast. Multisig can reduce single-point dependency, but it also increases recovery complexity. Multisig without a complete descriptor and enough cosigner backups is not automatically safer.

Step 7: Retire the Legacy Seed Only After Confirming Completion

Before declaring the migration complete, verify every item:

  • Every intended UTXO has entered the new singlesig or multisig address and received enough confirmations.
  • The wallet fingerprint, account, and address shown on OneKey match your records.
  • The new recovery phrase has been backed up offline and verified.
  • Any new passphrase has been backed up accurately and separately.
  • The new multisig descriptor and cosigner information can be recovered.
  • The old wallet has no omitted passphrase account, change, or pending transaction.

Retain the old backup until every condition is satisfied. Afterward, clearly mark the legacy seed “retired—do not receive,” remove unnecessary digital traces, and stop giving the old address to payers. If the related device is evidence in an investigation, do not wipe or destroy it yourself.

A zero-balance legacy seed should still not be disclosed. Historical addresses, signing relationships, and future accidental receipts can continue to create privacy or asset risk.

Common Failure Paths

The most common migration problems are usually process confusion, not cryptography:

  • Assuming migration is complete after importing the legacy phrase. The private keys have not changed.
  • Checking the address only in the app. A compromised host may display an attacker’s address; hardware-screen verification cannot be skipped.
  • Transferring the entire balance in the first transaction. There is no room to recover from an address, passphrase, or account-configuration error.
  • Destroying the old backup too early. Unconfirmed change, hidden wallets, or multisig configuration may still require it.
  • Treating a PIN as a passphrase. They serve different functions; a PIN does not derive a new wallet.
  • Continuing to receive at the old address after restoring on the new device. This prevents the old keys from ever being fully retired.

A clear completion standard matters more than “switching brands.”

Conclusion

The security core of migrating from COLDCARD to OneKey is not moving a recovery phrase to another device, but creating a new relationship of key control. Verify the destination device, generate a completely new seed phrase on OneKey, complete offline backups and record any optional passphrase, verify the receiving address on the hardware screen, make a small test, and then migrate the remaining UTXOs. Multisig users must also create a new policy and transfer on-chain.

The migration should be timely, but not so rushed that verification is skipped. As long as the legacy seed can still control funds, treat the migration as incomplete. Key rotation truly ends only when the new wallet can be recovered, the funds are confirmed as received, and the balances and accounts in the old wallet have been fully reconciled.

References

  1. Coinkite: COLDCARD Security Advisory: https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/
  2. OneKey: Get Started with OneKey Pro: https://help.onekey.so/en/articles/11461081-get-started-with-onekey-pro
  3. OneKey: Anti-counterfeiting Verification of OneKey Devices: https://help.onekey.so/en/articles/11461236-anti-counterfeiting-verification-of-onekey-devices
  4. OneKey: Authenticate Firmware Consistency: https://help.onekey.so/en/articles/11461223-authenticate-the-consistency-of-firmware-files-with-the-open-source-code-released-by-onekey
  5. OneKey: Send and Receive Cryptos in OneKey App: https://help.onekey.so/en/articles/11461145-send-and-receive-cryptos-in-onekey-app
  6. OneKey: Connect to OneKey App via QR Code (Air-Gap): https://help.onekey.so/en/articles/11461088-connect-to-onekey-app-via-qr-code-air-gap
  7. OneKey: Bitcoin-only Mode: https://help.onekey.so/en/articles/13276348-what-is-bitcoin-only-mode-and-how-do-i-enable-it-in-the-onekey-app
  8. OneKey: Passphrases and Hidden Wallets: https://help.onekey.so/en/articles/11461220-passphrases-and-hidden-wallets
  9. OneKey: Using Hardware Wallets with Sparrow Wallet for BTC Multisig: https://help.onekey.so/en/articles/14084286-using-hardware-wallets-with-sparrow-wallet-for-btc-multisig
  10. OneKey X: OneKey Devices Are Not Affected by the COLDCARD RNG Issue: https://x.com/OneKeyHQ/status/2085351134538174601

Risk Disclosure

This article is provided only for general security education. It does not constitute financial, legal, forensic, or personalized migration advice. Bitcoin transactions are generally irreversible; an incorrect address, lost backup, incorrect passphrase, malicious host, or incomplete multisig configuration can cause permanent loss. Before acting, check the latest official OneKey and Coinkite documentation. Stop immediately if anyone asks you to enter a recovery phrase on a website, in a chat, through remote desktop, or in unverified software.

FAQ's

Technically, a compatible BIP-39 seed phrase may restore the same wallet. But if the legacy phrase falls within the COLDCARD advisory’s scope, importing it does not eliminate the old randomness risk. This article recommends creating a new phrase on OneKey and migrating through a Bitcoin on-chain transaction.

A small test simultaneously verifies the destination address, network, account, backup, and passphrase, and confirms that the new wallet can receive correctly. It cannot eliminate every risk, but it can expose many operational errors before the main balance is transferred.

No. Bitcoin-only mode suits users who manage only Bitcoin and want to reduce the currently enabled feature set; standard mode can also manage Bitcoin. Decide before transferring the main funds, and follow the latest official version requirements and backup instructions.

Do not treat the legacy passphrase as a repair. You may choose not to use a passphrase with the new seed, or configure a new, unique passphrase that you can recover accurately. In either case, confirm that the actual receiving address belongs to the intended new wallet.

Consider retiring the legacy backup only after every intended UTXO has been confirmed in a recoverable new wallet, hidden accounts and change have been reconciled, and any multisig configuration has been verified. If unauthorized transactions or an investigation are involved, preserve the device and records rather than destroying evidence yourself.

Secure Your Crypto Journey with OneKey

View details for Shop OneKeyShop OneKey

Shop OneKey

The world's most advanced hardware wallet.

View details for Download AppDownload App

Download App

Trade global assets. Start with your email in minutes.

View details for OneKey SifuOneKey Sifu

OneKey Sifu

Crypto Clarity—One Call Away.