Specifications

What's inside.

The full sheet — silicon, standards, and the physical object. Part numbers included, because you should be able to look everything up.

THE BOARDMODEL N°01 · ANNOTATED
Favilla KEY main board, annotated: ESP32-S3 WROOM-1U MCU, NXP SE051 secure element, OV2640 camera, BMA400 accelerometer, piezo buzzer, DRV2605L haptic driver, USB-C connector
The main board of an earlier prototype (model N°01). The current board adds the isolated signing processor, the battery monitor and a different accelerometer — a new photo follows with the production run.

Core silicon

Processor
Espressif ESP32-S3 (WROOM-1U module, external antenna)Dual-core Xtensa LX7 @ 240 MHz
Secure element
NXP SE051 · Common Criteria EAL 6+ with AVA_VAN.5Tamper-resistant key storage · on-chip PIN verification with hardware retry counter · certified TRNG · holds the mode latch
Signing processor
ST STM32G0 — isolated signer, no radiosHolds the Nostr key and unseals the Bitcoin seed · fixed-length commands only, no parser · read-out lock fused on production units — how it works
Camera
OmniVision OV2640, fixed-focus lens tuned for QR captureOn-device QR decode — used for airgap signing and pairing
Display
240 × 240 colour TFT (ST7789) behind cover glass
Motion
ST LIS2DW12 accelerometerDrives the motion auto-lock
Feedback
DRV2605L haptic driver + piezo buzzerYou feel and hear every confirmation
Controls
Four tactile buttons, machined brassThe two left buttons together cut power to both processors in hardware — a true power cycle, not a software reboot

Power & connectivity

Battery
500 mAh LiPo · TI BQ24075 power-path charging · TI INA232 battery monitorAuto-sleep by default · hours of active use, about a week on standby · gauge readable at Settings › Device › Battery
USB
USB-C (data + power)
WiFi
2.4 GHz b/g/n · own access-point modeAway from home, the device broadcasts its own network with a per-device password — your phone joins it directly · never in Bitcoin mode
Bluetooth
BLE 5.0 hardware-capable, not used

Keys & cryptography

Recovery
One BIP-39 phrase (12 or 24 words), optional BIP-39 passphraseNostr identity derives via NIP-06 · Bitcoin via BIP-84 (single-sig) and BIP-48 (multisig) · passphrase at setup or restore, up to 100 characters, typed or scanned — baked in, or asked at each Bitcoin session (any number of wallets from one set of words) · existing nsec import supported
Entropy
Your choice at setup: SE051 TRNG XOR camera sensor, or your own dice rollsTwo chips: both 16 × 16 grids shown on screen, seed = SHA-256 of their XOR — recheck it at Seed check · dice: SHA-256 of your rolls, reproducible off-device · nothing else is mixed in
At rest
AES-256 ciphertext, wrapped twice — outer key inside the SE051, inner key inside the signing processorNostr key stored inside the SE051 · seed stored in flash · a flash dump yields ciphertext and public data, nothing more
PINs
Two: Nostr PIN (identity, messages, client) and BTC PIN (Bitcoin signing, device buttons only)Hardware retry counter with escalating delays · nine attempts on the device, three over the network · separate budgets for each PIN · a locked device recovers by wiping and restoring from your phrase
Signatures
BIP-340 Schnorr (Nostr) · ECDSA (Bitcoin)Both computed on the isolated signing processor — the Wi-Fi chip never holds a key
Firmware integrity
Secure Boot V2, RSA-3072 — fused on production unitsProduction units also carry per-unit XTS-AES flash encryption and an irreversible debug lock on the signing processor · prototypes do not yet — full security page

Nostr

Signing
NIP-01 events · policy per event kind: auto, manual, or selectiveEnforced by device firmware — a client cannot override it · policy mode (your own rules) coming
Messages
NIP-44 v2 encryption on every DM that leaves the device · NIP-17 gift-wrap end to endNIP-04 legacy: decrypt always, send opt-in only
Remote signing
NIP-46 for any client supporting Nostr ConnectOne-time bunker tokens · mint and revoke app links remotely · the controlling pairing changes only on the device
Zaps
NWC (Nostr Wallet Connect) — your node or a custodial serviceThe device signs the zap request; the client sends the NWC payment · gift-wrapped zaps inside DMs
Client
Full Nostr client served from the device itselfLocal network or the device's own AP · remote client for NIP-46 · publishes once to our relay (relay.favillakey.io), which fans out to public relays — replace it with your own

Bitcoin

Wallet
BIP-84 single-sig · BIP-48 P2WSH multisig cosignerUp to 4 registered multisig wallets, up to 7 cosigners each · Bitcoin exists only in Bitcoin mode, opened with the BTC PIN after a power cycle — no balance, addresses or Bitcoin API under the Nostr PIN
Signing
PSBT · every input re-derived and verified, every change output checked against the registered descriptorInputs it cannot prove are yours come back unsigned · BTC PIN on device buttons only · our recommendation: multisig, so the KEY never spends alone
Airgap
ur:crypto-psbt animated QR — camera in, screen out, no networkValidated round-trip against Sparrow and BlueWallet on mainnet, single-sig and multisig

Physical

Enclosure
CNC-machined 6061 aluminium, bead-blasted and anodised · 2 mm glass back panelPlanned finishes for later runs: stainless steel, copper, solid brass
Dimensions
55 × 55 × 17.5 mm
Weight
65 g
Assembled
Perth, Western Australia

And

CIPHER
Skill-based hash-mining game, built into the firmwareSigned scores, weekly sats draw — the full guide
Price
To be announced before launch
Availability
First production run 2026 · early-access list

Want one on
your desk?

Join the list — first allocation, no deposit.

Get early access →