Keycard Shell
The air-gapped signer that shows you what you sign. Keys live on cards that will outlive any device. Keys never leave the card.
A hardware wallet was supposed to make you independent
- §1Trust code you cannot fully audit
- §2Install our companion app
- §3Keep your keys inside our device
- §4Accept the firmware changes we decide
Shell removes the conditions. Verify everything. Depend on no one.
Point. Check. Sign.
Shell works with the wallet you already use. Your wallet builds the transaction; Shell shows you what it really does, then signs it, off the internet. The whole loop takes seconds.
-
01
Your wallet builds the transaction
MetaMask, Sparrow or any of 15+ wallets shows a QR code. Your wallet, not ours. There is no Keycard app.
-
02
Insert your card, enter your PIN
Shell turns on at insertion and boots in 20 milliseconds. Your PIN goes into a physical keypad.
-
03
Point Shell at the screen
One button. The global-shutter camera reads even animated QR codes instantly.
-
04
Read what you are signing
Recipient, amount, network, fee. Decoded on Shell's own screen, out of reach of malware.
-
05
Press OK to sign
The card signs on its secure element. Keys never leave it.
-
06
Show the QR back
Your wallet's camera reads Shell's reply and broadcasts. Your keys never touched a connected machine.
You decide how your keys are organized
The card is the key, not the device. Each card is one BIP-32 wallet with its own PIN, and it derives as many keys as you will ever need. How many cards you keep, what each one holds and where they live is your design, not ours.
One card
One wallet, an unlimited number of keys
One card is one BIP-32 wallet. From a single seed it derives unlimited keys and addresses, hardened or not, ten levels deep. That is why one card signs for Bitcoin, Ethereum and every EVM chain and L2. Name it, and the name becomes the menu title on insertion.
A card and its spares
Your backup is a card, not a piece of paper
The same seed, on as many cards as you like. Each has its own PIN and works alone, so a spare in another building is a wallet you can use, not a note you hope is still legible. Words follow BIP-39, restorable in any compatible wallet. Or use SLIP-39 Shamir shares, with your own threshold.
Independent cards
Separate wallets, separate risk
A second wallet is a second card. Long-term holdings on one, contract keys on another: different seeds, different PINs, nothing shared, so a mistake in one cannot reach the other. Unlimited Keycards per Shell, swapped in seconds. Shell wakes on insertion, boots in twenty milliseconds, and never asks you to pair again.
Multisig across cards
No single card can move the funds
Spread a Bitcoin multisig across several cards, one key each, kept in different places. Native SegWit, P2WSH, with a dedicated export flow and full PSBT support, so Sparrow and other coordinators see a normal cosigner. Losing one card costs you a card.
Bring your existing keys or generate brand new ones
- Generate on the card. True hardware randomness, 12 or 24 BIP-39 words.
- Bring your own. Type your existing BIP-39 words and the card takes them.
- Scan a SeedQR To import your seed
- SLIP-39 Shamir shares Import or generate, with your own threshold.
- BIP-39 passphrases are supported. Chosen when the card is initialized, and set once.
Use your cards on all your devices
Shell is the best place to use your keys, not the only one. The same card taps a phone over NFC, or sits in a USB reader on a desktop. Nothing to re-pair and nothing to migrate, because the keys never left the card in the first place. Your keys can never ever leave the card.
-
In Shell
Camera, screen and keypad, never connected to anything. The setup this page is about, and the one to use for anything that matters.
-
On your phone
Tap the card against the back of the phone. Status mobile talks to it over NFC, and the card signs on its own secure element. No Shell in the room.
-
On your desktop
A plain contactless reader over USB, no drivers to install. Status desktop and Sparrow both work this way.
See what you sign
Shell decodes the transaction on its own screen — recipient, amount, network, fee — before anything is signed. What you approve is exactly what the card signs. Nothing in between.
Shell decodes ERC-20 transfers, token approvals with spender and amount, EIP-712 typed data, Safe transactions and Bitcoin PSBT with change detection. What cannot be decoded is shown raw, never hidden.
Everything Shell decodes
Ethereum
- To address, amount, network name and gas fee before signing
- Full call data display
- ERC-20 transfers, ticker and amount from the on-device token database
- ERC-20 approve: spender address and approved amount
- ABI decoding: function name and arguments for known contracts
- EIP-712 typed data with type labels, digest always shown
- ERC-8213 hash, so the digest can be checked independently on a second machine. erc8213.eth.limo
- Gnosis Safe dedicated view, SafeTx human-readable
- Permit and Permit2
- personal_sign raw message, scrollable
Bitcoin
- PSBT: each output with recipient and amount, fee calculated
- Change output auto-detected and labeled separately
- Multisig PSBT with appropriate labeling
Always
- ETH and BTC receiving addresses on screen, exportable as QR
- Every field scrollable before confirmation
- Signing requires a physical button press
Ethereum and Bitcoin
Ethereum
- Ethereum mainnet and every EVM chain and L2, chain names resolved from the on-device database
Solana is not supported.
Bitcoin
- Legacy, Nested SegWit, Native SegWit
- Multisig (P2WSH)
- Full PSBT support, all sighash flags, testnet included
Taproot is not supported yet.
Shell works with 15+ wallets
Use Keycard and Shell with the wallets you already trust. Explore the full list to filter by platform and assets.
Security, layer by layer
Your keys never leave the secure element
Keys are generated inside the Keycard secure element by its own hardware random number generator, and they never come out. It is certified EAL6+, the same class that protects bank cards. The card is the signer: a 32-byte hash goes in, a signature comes out. The microcontroller that drives Shell's screen, keypad and camera never sees key material, so a compromised Shell has nothing to leak.
Sealed at production
The card leaves the factory locked: its GlobalPlatform keys are randomized and the chip is in SECURED state, so no applet can be installed, replaced or removed through its interface.
Air-gapped, and why it matters
No WiFi, Bluetooth or cellular hardware exists on the board. The only channel is light: QR codes in, QR codes out. USB data has a kill switch, and Shell is stateless: remove the card and it forgets everything.
A PIN, not a fingerprint
Your PIN goes into a physical keypad, and there are no biometrics on the device by design. A PIN is something you know. A fingerprint can be physically compelled.
Proves it's genuine
Every card carries a factory-signed certificate, and every Shell holds a unique device key. At first boot, device and server prove genuineness to each other, cryptographically. A verification counter flags anything unexpected.
Under duress, a second PIN
An optional duress PIN opens a decoy wallet, cryptographically distinct from your real one. Nothing on screen reveals which PIN you used.
The most open and verifiable hardware wallet
Every claim below has a verification path. You never have to believe us.
Firmware you can rebuild
MIT licensed and reproducible: build from source, compare the hash. Same source, same binary.
Shell firmware on GitHub →Hardware you can fabricate
Schematics, Gerbers, BOM and 3D files under CERN-OHL-S v2. Enough to manufacture the device, not just to audit the design.
Hardware files on GitHub →A database you can trace
Token lists, chain registry and ABIs built from public sources. Every version is signed and hash-verifiable.
How the database is built → Database version history →Updates on your terms
Signed firmware, physical approval on the device, and a fully offline update path via USB drive. And the card's rules never change: the applet is sealed.
Update over the web → Update in air-gapped mode →Build it yourself
Compile the firmware with your own keys. Program your own blank JavaCard. The DIY path removes the last trust assumption.
Build your own Keycard → DIY Keycard Shell →Tech specs
Shell
| Display | 2.0" TFT IPS, 240×320, adjustable brightness |
| Keypad | 12 hard-rubber clicky keys, durable coating |
| Camera | Global shutter. Reads animated QR in one frame |
| Battery | Removable BL-4C, about $3, sold worldwide. No tools |
| Boot | 20 ms. Turns on and off at card insertion |
| USB-C | Any charger. Data kill switch in settings |
| Enclosure | ABS, dust resistant, pocket-sized |
| Branding | None. No crypto identifiers on the device |
| Signing | Air-gapped via QR (ERC-4527), or USB |
Keycard
| Secure element | NXP JCOP4 P71, EAL6+ Common Criteria |
| Form factor | Standard bank-card, ISO 7816 + NFC |
| Power | None needed. No battery, no moving parts |
| Lifespan | 20+ years. Water, dust and X-ray resistant |
| Readers | Works with Shell and any standard card reader |
| Branding | None. Looks like any card in your wallet |
In the box
- 1× Keycard Shell
- 2× Keycard (black, no brand visible)
- 1× BL-4C replaceable battery
- 1× USB-C to USB-C cable
Before you buy
What if I lose my card or device?
Does it work with my wallet?
Shipping and returns
What if Keycard the company disappears?
What does “air-gapped” actually mean?
Your keys, your rules
Get ShellFree shipping · 30-day returns · Verify your device is genuine at first boot