- Recovery
- One BIP-39 phrase (12 or 24 words), optional BIP-39 passphraseNostr identity derives via NIP-06 · Bitcoin via BIP-84 (single-sig) and BIP-48 (multisig) · passphrase at setup or restore, up to 100 characters, typed or scanned — baked in, or asked at each Bitcoin session (any number of wallets from one set of words) · existing nsec import supported
- Entropy
- Your choice at setup: SE051 TRNG XOR camera sensor, or your own dice rollsTwo chips: both 16 × 16 grids shown on screen, seed = SHA-256 of their XOR — recheck it at Seed check · dice: SHA-256 of your rolls, reproducible off-device · nothing else is mixed in
- At rest
- AES-256 ciphertext, wrapped twice — outer key inside the SE051, inner key inside the signing processorNostr key stored inside the SE051 · seed stored in flash · a flash dump yields ciphertext and public data, nothing more
- PINs
- Two: Nostr PIN (identity, messages, client) and BTC PIN (Bitcoin signing, device buttons only)Hardware retry counter with escalating delays · nine attempts on the device, three over the network · separate budgets for each PIN · a locked device recovers by wiping and restoring from your phrase
- Signatures
- BIP-340 Schnorr (Nostr) · ECDSA (Bitcoin)Both computed on the isolated signing processor — the Wi-Fi chip never holds a key
- Firmware integrity
- Secure Boot V2, RSA-3072 — fused on production unitsProduction units also carry per-unit XTS-AES flash encryption and an irreversible debug lock on the signing processor · prototypes do not yet — full security page