SeedSigner: what the sources say
Current 0 disclosed weaknesses 0 company incidents
The questions, with sources
"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.
Five facts
- SeedSigner is an open-source DIY signing device built from a Raspberry Pi Zero, a camera and a 240x240 LCD; there is no company behind it [source 3].
- The project's stated goal is a build cost below USD 50; the parts list gives no prices [source 2].
- Firmware is MIT-licensed and WalletScrutiny verified release images 0.8.5 and 0.7.0 as reproducible [source 5].
- It uses no secure element; it is air-gapped via QR codes and holds seeds only in memory [source 2].
- Supports BIP39 passphrase, multisig xpub export and PSBT signing for Bitcoin only [source 2].
Audits
- No independent audit found in our search.
Publicly disclosed weaknesses
- No publicly disclosed weakness found in our search. That is not proof there is none.
Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.
Incidents at the maker or its service providers
- No company incident found in our search.
These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.
Questions about SeedSigner
Is SeedSigner safe?
We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 0 publicly disclosed weaknesses and 0 company incidents in our search. Read the sources above before you buy.
Does SeedSigner need an internet connection?
Signing happens on the device. How the device talks to your phone or computer depends on its connections: QR. The companion app or software that builds the transaction is online.
Who found the weaknesses listed for SeedSigner?
The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.
Where this comes from
- [1] SeedSigner GitHub organization accessed 2026-10-11
- [2] SeedSigner/seedsigner repository (GitHub) accessed 2026-10-11
- [3] SeedSigner hardware page accessed 2026-10-11
- [4] SeedSigner home page accessed 2026-10-11
- [5] SeedSigner - WalletScrutiny accessed 2026-10-11
- [6] SeedSigner v0.7.0: Reproducible Builds - NoBS Bitcoin accessed 2026-10-11
- [7] SeedSigner releases (GitHub) accessed 2026-10-11
- [8] SeedSigner project page - OpenSats accessed 2026-10-11
- [9] SeedXOR feature request issue #43 (GitHub) accessed 2026-10-11
Not verified: No security audit, CVE, bug bounty or incident was found in the searches and fetches done; this is not proof of absence (releases page labels no change as a security fix). Retail price of parts not verified (project gives only a 'less than USD 50' target). Release year of 0.8.6/0.8.7 not shown on the releases page. Companion apps' licences, Shamir/SeedXOR status, FIDO and warranty not verified.
See how we check. To report an error, use corrections and right of reply.