Not affiliated with SolanaPlug in the stick. Restart. The host operating system never runs. Your keypair is generated, shown to you once, written down by hand — then you pull the plug and the machine that made it stops existing.
A key that has never existed on an online computer cannot be stolen from one.
Every other way of making a Solana wallet — a browser extension, a phone app, a desktop client — creates your private key on a machine that is connected to the internet and that keeps running afterward. Keystick does not. It boots its own operating system, generates the key in RAM, and that operating system has no network stack and no storage drivers compiled into it at all.
The capability to transmit or to save is absent, not merely unused. That is a different claim from “we promise we don’t.”
One stick is not one wallet. Run the ceremony again and you get an entirely new seed with no mathematical relationship to the last one. Generate a treasury key, a trading key, a cold key and a burner — nothing on the stick links them, because the stick remembers nothing.
Your machine boots from the stick instead of from its own disk. Whatever is installed on that computer — including anything malicious — never gets to run.
Roll dice or hammer the keyboard. Your entropy is blended with the hardware source. In the 2026 Coldcard failure, the users who added their own randomness were the ones who kept their money.
Twelve or twenty-four words, plus your Solana address. On paper, by hand. The stick makes you prove you copied it correctly before you ever send funds.
Power off. The key lived only in volatile memory. There is no disk to wipe because nothing was ever written to one.
Standard BIP-39. Standard derivation. Your seed restores in Phantom, in Solflare, in the Solana CLI, or in any other conformant wallet, with or without us.
A key you can only recover with our software is not a product, it is a trap. We do not hold your key, we cannot recover your key, and we have deliberately built nothing that could.




Mac editions and international shipping are on the order page.
On 31 July 2026 Coldcard disclosed that a firmware build guard had checked whether a macro existed rather than whether it was enabled. The crypto library bound to what it believed was the hardware random number generator while the runtime had silently compiled in a software fallback. Effective entropy dropped from 128 bits to roughly 40. Around 594 BTC was swept in twenty-five minutes.
The bug shipped in March 2021 and went undetected for five years. Patching the firmware does not repair a seed already generated.
That failure was not unique. It is a bug class, and it is stack-agnostic — the same shape of failure took Trust Wallet, Profanity, and blockchain.info, across four unrelated technology stacks.
Not on a server, not in a log, not for a millisecond. KOINI is affiliated with a licensed exchange, which makes possessing customer key material a regulatory problem, not just a security one.
If the entropy source is missing, unverifiable, or behaving oddly, the stick stops and says so. It will never quietly substitute something weaker.
We draw from the platform source ourselves and assert it, rather than trusting a library to have chosen well. Your dice go in on top.