IN STOCK · SHIPS IN 3–5 BUSINESS DAYS · $60 / $70 — FREE US SHIPPING · MADE IN THE USA
Keystick
The Solana Key Generator
Powered by KOINIkeystickNot affiliated with  Solana

Your Solana keys are born on a machine that has never touched the internet.

Plug in the stick. Restart. The host operating system never runs. Your keypair is generated, shown to you once, written down by hand — then you pull the plug and the machine that made it stops existing.

Holds nothing · Stores nothing · Remembers nothing

01The idea in one sentence

A key that has never existed on an online computer cannot be stolen from one.

Every other way of making a Solana wallet — a browser extension, a phone app, a desktop client — creates your private key on a machine that is connected to the internet and that keeps running afterward. Keystick does not. It boots its own operating system, generates the key in RAM, and that operating system has no network stack and no storage drivers compiled into it at all.

The capability to transmit or to save is absent, not merely unused. That is a different claim from “we promise we don’t.”

02Unlimited, unrelated keypairs from one stick

One stick is not one wallet. Run the ceremony again and you get an entirely new seed with no mathematical relationship to the last one. Generate a treasury key, a trading key, a cold key and a burner — nothing on the stick links them, because the stick remembers nothing.

03How it works

Plug in and restart

Your machine boots from the stick instead of from its own disk. Whatever is installed on that computer — including anything malicious — never gets to run.

Add your own randomness

Roll dice or hammer the keyboard. Your entropy is blended with the hardware source. In the 2026 Coldcard failure, the users who added their own randomness were the ones who kept their money.

Write down what you see

Twelve or twenty-four words, plus your Solana address. On paper, by hand. The stick makes you prove you copied it correctly before you ever send funds.

Pull the plug

Power off. The key lived only in volatile memory. There is no disk to wipe because nothing was ever written to one.

04Your seed phrase

Standard BIP-39. Standard derivation. Your seed restores in Phantom, in Solflare, in the Solana CLI, or in any other conformant wallet, with or without us.

This matters

A key you can only recover with our software is not a product, it is a trap. We do not hold your key, we cannot recover your key, and we have deliberately built nothing that could.

05The products

Keystick
PCs & Intel Macs · Bootable
Keystick
Your computer becomes the vault, then ceases to exist.
$60Free US shipping
STEALTH edition
PCs & Intel Macs · Bootable · Unbranded
STEALTH edition
Black on black, no markings, no logo. Nothing on the outside says what it is.
$70Free US shipping
read-only edition
PCs & Intel Macs · Write-protect
read-only edition
Write-protected standard casing. Same ceremony, sealed at the hardware level.
$75Free US shipping
METALLIC read-only
PCs & Intel Macs · Write-protect · Special edition
METALLIC read-only
Hardware write-protected metal. The stick cannot be altered after it ships.
$100Free US shipping


Mac editions and international shipping are on the order page.

06Why now

On 31 July 2026 Coldcard disclosed that a firmware build guard had checked whether a macro existed rather than whether it was enabled. The crypto library bound to what it believed was the hardware random number generator while the runtime had silently compiled in a software fallback. Effective entropy dropped from 128 bits to roughly 40. Around 594 BTC was swept in twenty-five minutes.

The bug shipped in March 2021 and went undetected for five years. Patching the firmware does not repair a seed already generated.

That failure was not unique. It is a bug class, and it is stack-agnostic — the same shape of failure took Trust Wallet, Profanity, and blockchain.info, across four unrelated technology stacks.

07Trust architecture

We never hold your key

Not on a server, not in a log, not for a millisecond. KOINI is affiliated with a licensed exchange, which makes possessing customer key material a regulatory problem, not just a security one.

It refuses rather than guesses

If the entropy source is missing, unverifiable, or behaving oddly, the stick stops and says so. It will never quietly substitute something weaker.

You own the entropy

We draw from the platform source ourselves and assert it, rather than trusting a library to have chosen well. Your dice go in on top.

08Go as deep as you like