Your key is your name, your followers, your Bitcoin. It can't be reset. It can't be reissued. And you wouldn't keep your Bitcoin keys in a browser. Favilla KEY is the hardware your identity should have lived in from day one.
No jargon required. If you already know Nostr, skip ahead.
On Nostr, you don't log in with an email and a password. Your account is a cryptographic key. You carry it between apps, and no company can revoke it.
Lose the key and the account is gone forever. There's no reset button.
A browser extension. A note on your phone. And the fixes on offer just add more software — new keys delegated from a master key that still sits on an internet-connected computer. The exposure doesn't go away; it grows layers.
Bitcoin solved this years ago: take the key off the computer.
We don't rotate around the problem. The master key itself is generated in hardware, sealed in certified silicon, and never exposed — so there's nothing to delegate, rotate, or clean up after.
The same answer hardware wallets gave Bitcoin, finally given to your identity. Nothing else runs on it.
Your nsec is generated on the device and sealed inside an EAL 6+ secure element. Every signature surfaces on-screen for approval. Nothing is signed behind your back.
How it works →PSBT signing over airgapped QR, validated round-trip against Sparrow and BlueWallet on mainnet. Spending always needs a separate PIN. Unlocking Nostr never unlocks your coins.
The two-door model →Leave it on the desk and it arms itself. The moment anyone picks it up, it wipes the working key from memory and demands your PIN — verified inside the secure element, with a hardware counter that makes brute force a dead end.
The self-defence layer →A hash-mining arcade game built into the firmware. Mine blocks, crack armoured bots, hunt bosses for minted loot. Your best score is signed by the device and enters a weekly draw for real sats.
Enter CIPHER →Machined from a solid block of aluminium. Tactile buttons with haptic and audio feedback — you feel every confirmation. Cover glass over a colour display that shows you the truth before you sign it. It has weight, because the thing it protects has weight.
Your keys are generated on the device and live their whole life inside it. They're never typed into a browser, never synced, never held by us or anyone else.
Favilla KEY works two ways, and you'll use both.
Power it on and connect — over your home network, or anywhere at all: away from home, the device broadcasts its own network and your phone joins it directly. Your browser pulls a full Nostr client straight from the hardware in your hand. Read, post, zap, DM. No install, no extension, no company hosting anything. If we disappear tomorrow, it keeps working.
Connect over NIP-46 to any client that supports Nostr Connect. Signing requests travel securely to the device and approvals travel back — even while it sits at home. You post from your phone across town; your key never leaves the house.
And unlike other remote signers, Favilla KEY mints one-time bunker URLs — each consumed by the app that pairs with it, never reusable if leaked. Revoke and mint new ones remotely.
End-to-end encryption stops anyone reading your messages in transit. But once they're decrypted on your phone, they're readable by whoever holds it. The key that unlocks them lives on the same device they sit on.
Your message history is decrypted with keys stored on the phone itself. Anyone who gets into the phone — thief, border agent, spyware — gets your conversations with it.
DMs are cached encrypted on your phone or computer, and the key that opens them lives in Favilla KEY's hardware. Messages are readable only while your KEY is unlocked. Lock it, and they seal again.
Designed and assembled in Perth, Australia. Drop your email and you'll be first to know when the first units are ready.