Power-off is the destruction event.
No network stack. No storage drivers. The seed is shown once and never stored. BITCOINkeystick boots your computer into an environment that cannot reach the internet and cannot write to a disk, generates your Bitcoin keys there, and stops existing when you pull the plug.
The idea in one sentence
Your computer off. Your keys on. Everything else gone.
Holds nothing
There is no storage driver in the kernel. Writing to a disk is not disabled — it is absent.
Stores nothing
Your seed exists in RAM, is displayed once, and is gone at power-off.
Remembers nothing
Every ceremony starts from the same clean image. The stick learns nothing between uses.
Bitcoin only
This edition derives secp256k1 only. It has its own boot image, its own ceremony and its own published SHA-256. It is not the three-chain KŌINIkeystick with a different sticker on it.
That is a deliberate choice and it costs us something: a second artifact to build, hash, and put in front of an auditor. What it buys you is the smallest attack surface in the family. One curve. One derivation family. An entropy path short enough that a reviewer can read all of it in one sitting.
KŌINIkeystick generates Bitcoin, EVM and Solana addresses from one seed. Same company, same architecture, larger surface. If Bitcoin is not all you hold, that is the one to buy.
How it works
Boot
Restart from the stick. Your operating system never loads.
Add entropy
Roll dice if you want to. Your randomness is mixed with the machine's — see why on the history page.
Write it down
Twelve or twenty-four words, on paper, by hand. Then verify them before you fund anything.
Power off
That is the destruction step. Nothing was stored, so nothing survives — except the paper in your hand.
The products
Same image on every edition. The difference is the shell, and whether the machine can boot from it. Free tracked US shipping on all of them; international is $25 once per order, not per stick.
BITCOINkeystick
PCs & Intel Macs · Bootable
The stick boots your computer into a RAM-only environment. Your operating system never runs.
BITCOINkeystick STEALTH
PCs & Intel Macs · Bootable · Unbranded
Identical inside. No label, nothing on the shell that says what it is. For people who would rather it looked like nothing.
BITCOINkeystick read-only
PCs & Intel Macs · Bootable · Write-protect switch
A hardware write-protect slider. The standard stick can in principle be tampered with if it is plugged into an infected running computer between ceremonies; this one cannot.
BITCOINkeystick METALLIC read-only
PCs & Intel Macs · Bootable · Write-protect switch · Special edition
Our most durable stick. Machined metal shell, USB-A and USB-C on one body, hardware write-protect switch.
BITCOINkeystick for Mac
Apple Silicon · Sealed sandbox
Apple Silicon Macs cannot boot from a USB stick at all, so this edition runs the ceremony in a sealed, network-less sandbox inside macOS. macOS keeps running underneath — destruction here is a property of our software, not of the hardware. If you have any PC or Intel Mac, boot the standard edition on that instead.
BITCOINkeystick STEALTH for Mac
Apple Silicon · Sealed sandbox · Unbranded
The Mac edition, unlabelled. Apple Silicon Macs cannot boot from a USB stick at all, so this edition runs the ceremony in a sealed, network-less sandbox inside macOS. macOS keeps running underneath — destruction here is a property of our software, not of the hardware. If you have any PC or Intel Mac, boot the standard edition on that instead.
BITCOINkeystick read-only for Mac
Apple Silicon · Sealed sandbox · Write-protect switch
The write-protect switch still matters here: it protects the stick's contents from tampering between uses, even though the ceremony runs inside macOS.
BITCOINkeystick METALLIC read-only for Mac
Apple Silicon · Sealed sandbox · Write-protect switch · Special edition
The metal-shell stick, run as a sealed sandbox app on Apple Silicon.
Why now
On 31 July 2026 Coldcard disclosed that a firmware build guard had been checking whether a macro existed rather than whether it was enabled. Wallets built on that firmware had roughly 40 bits of entropy instead of 128. Around $38–40M in Bitcoin was drained, including 594 BTC in a single 25-minute sweep.
The bug shipped in March 2021 and nobody found it for five years. Patching the firmware does not repair a seed already generated.
The users who were unaffected were the ones who had supplied their own dice entropy. Their randomness never travelled through the broken path.
That is the whole argument for how this product works, and it is why the dice step is offered in the main flow rather than buried in an expert menu.
Trust architecture
Published hash
Every release has a SHA-256 you can check against your own stick before you boot it. How to verify →
Independent review
The entropy path goes to an independent reviewer before this product goes on sale. We will not ship it before that happens.
Tamper-evident seal
Every stick ships in a sealed bag that cannot be opened without showing it. If the seal is broken, do not use the stick.
Flashed, verified and sealed in the USA
Every stick is written, hash-checked against the published SHA-256, labelled and sealed by us, by hand, in the United States. Nobody else touches the image, and no factory ever holds it.
The USB hardware itself is manufactured overseas, like all flash hardware. We say flashed and sealed rather than made because that is the part we actually control — and it is the part that protects you.
What we cannot do for you
We cannot recover your seed. Not for a fee, not with ID, not ever. A recovery service would mean we held a copy of your key, and a company affiliated with a licensed exchange holding customer key material is not a grey area. If you lose the paper, the coins are gone. Buy this understanding that.
Go as deep as you like
How it works
The ceremony, step by step.
The technology
Where the randomness comes from, and what the runtime check does not prove.
Addresses
One seed, four formats, standard paths.
The environment
What destroyed means, including RAM remanence.
History
Four stacks, one bug class.
Why this exists
The claim, and what it is not better than.
Verify your stick
Check the seal and the hash before you boot.
FAQ
Including the ones we would rather not be asked.
Legal
What we collect, which is nothing.