AIR-GAPPED BITCOIN SIGNING DEVICE
Fully assembled and ready to use. Load a seed, sign a transaction through the camera and the screen, then pull the power and the seed is gone.
Includes a setup session with me.
I do not sell a signing device to someone I have not spoken to.
Plus the €150.00 setup session · what that is →

STATELESS
Your seed sits in memory only while the device has power. Remove the power and it is wiped. There is no key material stored on the device for anyone to find later.

AIR-GAPPED
No WiFi. No Bluetooth. The unsigned transaction goes in through the camera. The signed one comes back out as a QR code on the screen. Your keys never touch a networked machine.

BUILT FOR HANDS
A 2.8 inch IPS display at 240x320, so addresses and seed words are readable without squinting. DPAD style controls. A spring-loaded microSD slot. Outgoing QR data moves faster than on the original hardware.

POWER ONLY
The USB-C port takes power and nothing else. There is no cable path in or out for your keys, by design. The camera and the screen are the only two doors.

OPEN SOURCE
SeedSigner is MIT licensed, built by volunteers, with reproducible builds and commodity parts. No sealed black box, no company claims to take on faith. Ten dollars from every assembled unit goes to the project maintainer.

“A vault that only exists while it is powered, and holds nothing at all once it is not.
No. It is held in memory while the device is powered and wiped when power is removed. If the device is lost or taken, there is nothing on it to extract.
Any coordinator that speaks QR. Sparrow, Specter Desktop, Nunchuk, BlueWallet and Keeper are the common ones. You keep watching your balance there, and only the signing happens here.
Yes. Load your seeds one at a time, export the xpubs to your coordinator, and sign each key on the same device. It is the cheapest honest way to try multisig.
No. It arrives assembled with a microSD card, ready to power on. The hardware and the software are public, so you can still verify or rebuild it yourself later.
Yes, and you should. Download the image from the SeedSigner project, then drop the file onto verify.bitsaga.be: it compares the SHA-256 against the hash the project published, in your browser. Nothing is uploaded and we host no firmware of our own.
Yes, and it costs nothing. The real firmware runs in a browser tab at bitsaga.be/seedsigner-simulator, so you can walk the menus, load a seed, export an xpub and sign a transaction first. Pick the stock firmware for this model, and use a public test seed, never one of your own.
One device, any number of seeds, singlesig or multisig. Nothing stored, nothing plugged into your computer, nothing you have to take on trust.