Fully open-source, air-gapped hardware wallet. Keys never leave the device — what you see is what you sign.
← Back to HomeDesigned for signing security, built for trust
Private keys live only inside certified EAL6+ secure elements. The MCU stores no key material whatsoever.
No radio. Transactions and signatures move via QR code — the device is physically isolated from the network.
What you see is what you sign. Human-readable recipient, amount and contract intent on screen — no blind signing.
Works as a security key on GitHub, Google and any WebAuthn site — in Chrome and Firefox, over USB.
Firmware, schematics and host tools are fully open source. Compile and compare hashes yourself — zero trust required.
25 rounds of security audit against the secure-core. No key self-destruction, ever — a stolen device is useless, a lost seed can always recover.
Signing security as the sole core
Product images