IN STOCK · SHIPS IN 3–5 BUSINESS DAYS · $60 / $70 — FREE US SHIPPING · MADE IN THE USA
Why it's safest

Measured against everything else.

Including the parts where we come off worse.

ApproachWhere the key is bornThe problem
Browser extension walletOn an online machine, inside a browserAny malicious extension, any compromised page, any clipboard monitor. The key exists on a networked device that keeps running.
Mobile wallet appOn an online, always-on phoneBetter isolation than a browser, but the device is permanently networked and permanently persistent. “Deleted” is a policy claim.
Desktop walletOn an online machineSame exposure as the browser, with more filesystem to leak into.
Hardware walletOn a dedicated offline chipGenuinely good — and exactly what failed at Coldcard. You are trusting firmware you cannot read and an RNG you cannot audit.
Exchange custodyNot yours at allSomeone else holds the key. That is a different product with a different risk, and it is not self-custody.
KeystickIn RAM, on a machine with no network stackYour host machine could still be physically compromised. You still have to protect the paper.

01What we are actually better at

02What we are not better at

Straight answer

If your computer’s firmware is already compromised at a level below the operating system, booting our stick on it does not save you. If someone is filming your desk, nothing here helps. And if you lose the paper, the money is gone — a hardware wallet with a PIN gives you a second chance that we deliberately do not.