Bitcoin cold-storage key generation

Power-off is the destruction event.

No network stack. No storage drivers. The seed is shown once and never stored. BITCOINkeystick boots your computer into an environment that cannot reach the internet and cannot write to a disk, generates your Bitcoin keys there, and stops existing when you pull the plug.

01

The idea in one sentence

Your computer off. Your keys on. Everything else gone.

Holds nothing

There is no storage driver in the kernel. Writing to a disk is not disabled — it is absent.

Stores nothing

Your seed exists in RAM, is displayed once, and is gone at power-off.

Remembers nothing

Every ceremony starts from the same clean image. The stick learns nothing between uses.

02

Bitcoin only

This edition derives secp256k1 only. It has its own boot image, its own ceremony and its own published SHA-256. It is not the three-chain KŌINIkeystick with a different sticker on it.

That is a deliberate choice and it costs us something: a second artifact to build, hash, and put in front of an auditor. What it buys you is the smallest attack surface in the family. One curve. One derivation family. An entropy path short enough that a reviewer can read all of it in one sitting.

What the ceremony actually does →

If you also hold other assets

KŌINIkeystick generates Bitcoin, EVM and Solana addresses from one seed. Same company, same architecture, larger surface. If Bitcoin is not all you hold, that is the one to buy.

keystick.koini.io →

03

How it works

1

Boot

Restart from the stick. Your operating system never loads.

2

Add entropy

Roll dice if you want to. Your randomness is mixed with the machine's — see why on the history page.

3

Write it down

Twelve or twenty-four words, on paper, by hand. Then verify them before you fund anything.

4

Power off

That is the destruction step. Nothing was stored, so nothing survives — except the paper in your hand.

The full ceremony, step by step →

04

The products

Same image on every edition. The difference is the shell, and whether the machine can boot from it. Free tracked US shipping on all of them; international is $25 once per order, not per stick.

BITCOINkeystick

BITCOINkeystick

PCs & Intel Macs · Bootable

The stick boots your computer into a RAM-only environment. Your operating system never runs.

$50
BITCOINkeystick STEALTH

BITCOINkeystick STEALTH

PCs & Intel Macs · Bootable · Unbranded

Identical inside. No label, nothing on the shell that says what it is. For people who would rather it looked like nothing.

$60
BITCOINkeystick read-only

BITCOINkeystick read-only

PCs & Intel Macs · Bootable · Write-protect switch

A hardware write-protect slider. The standard stick can in principle be tampered with if it is plugged into an infected running computer between ceremonies; this one cannot.

$75
BITCOINkeystick METALLIC read-only

BITCOINkeystick METALLIC read-only

PCs & Intel Macs · Bootable · Write-protect switch · Special edition

Our most durable stick. Machined metal shell, USB-A and USB-C on one body, hardware write-protect switch.

$100
BITCOINkeystick for Mac

BITCOINkeystick for Mac

Apple Silicon · Sealed sandbox

Apple Silicon Macs cannot boot from a USB stick at all, so this edition runs the ceremony in a sealed, network-less sandbox inside macOS. macOS keeps running underneath — destruction here is a property of our software, not of the hardware. If you have any PC or Intel Mac, boot the standard edition on that instead.

$50
BITCOINkeystick STEALTH for Mac

BITCOINkeystick STEALTH for Mac

Apple Silicon · Sealed sandbox · Unbranded

The Mac edition, unlabelled. Apple Silicon Macs cannot boot from a USB stick at all, so this edition runs the ceremony in a sealed, network-less sandbox inside macOS. macOS keeps running underneath — destruction here is a property of our software, not of the hardware. If you have any PC or Intel Mac, boot the standard edition on that instead.

$60
BITCOINkeystick read-only for Mac

BITCOINkeystick read-only for Mac

Apple Silicon · Sealed sandbox · Write-protect switch

The write-protect switch still matters here: it protects the stick's contents from tampering between uses, even though the ceremony runs inside macOS.

$75
BITCOINkeystick METALLIC read-only for Mac

BITCOINkeystick METALLIC read-only for Mac

Apple Silicon · Sealed sandbox · Write-protect switch · Special edition

The metal-shell stick, run as a sealed sandbox app on Apple Silicon.

$100
05

Why now

On 31 July 2026 Coldcard disclosed that a firmware build guard had been checking whether a macro existed rather than whether it was enabled. Wallets built on that firmware had roughly 40 bits of entropy instead of 128. Around $38–40M in Bitcoin was drained, including 594 BTC in a single 25-minute sweep.

The bug shipped in March 2021 and nobody found it for five years. Patching the firmware does not repair a seed already generated.

The part that matters

The users who were unaffected were the ones who had supplied their own dice entropy. Their randomness never travelled through the broken path.

That is the whole argument for how this product works, and it is why the dice step is offered in the main flow rather than buried in an expert menu.

The four incidents in full →

06

Trust architecture

Published hash

Every release has a SHA-256 you can check against your own stick before you boot it. How to verify →

Independent review

The entropy path goes to an independent reviewer before this product goes on sale. We will not ship it before that happens.

Tamper-evident seal

Every stick ships in a sealed bag that cannot be opened without showing it. If the seal is broken, do not use the stick.

Flashed, verified and sealed in the USA

Every stick is written, hash-checked against the published SHA-256, labelled and sealed by us, by hand, in the United States. Nobody else touches the image, and no factory ever holds it.

The USB hardware itself is manufactured overseas, like all flash hardware. We say flashed and sealed rather than made because that is the part we actually control — and it is the part that protects you.

What we cannot do for you

We cannot recover your seed. Not for a fee, not with ID, not ever. A recovery service would mean we held a copy of your key, and a company affiliated with a licensed exchange holding customer key material is not a grey area. If you lose the paper, the coins are gone. Buy this understanding that.

07

Go as deep as you like

How it works

The ceremony, step by step.

The technology

Where the randomness comes from, and what the runtime check does not prove.

Addresses

One seed, four formats, standard paths.

The environment

What destroyed means, including RAM remanence.

History

Four stacks, one bug class.

Why this exists

The claim, and what it is not better than.

Verify your stick

Check the seal and the hash before you boot.

FAQ

Including the ones we would rather not be asked.

Legal

What we collect, which is nothing.