Keycard Shell

Keycard Shell

Sale price  €135,50 Regular price  €156,51
Skip to product information
Keycard Shell

Keycard Shell

Sale price  €135,50 Regular price  €156,51

The air-gapped signer that shows you what you sign. Keys live on cards that will outlive any device. Keys never leave the card.

In stock · Delivered in 7 days
Verify your device is genuine at first boot. Cryptographically.
VisaMastercardAmexGoogle PayApple PayBitcoinEthereumUSDC

A hardware wallet was supposed to make you independent

Terms · legacy hardware wallets
  1. §1Trust code you cannot fully audit
  2. §2Install our companion app
  3. §3Keep your keys inside our device
  4. §4Accept the firmware changes we decide

Shell removes the conditions. Verify everything. Depend on no one.

Point. Check. Sign.

Shell works with the wallet you already use. Your wallet builds the transaction; Shell shows you what it really does, then signs it, off the internet. The whole loop takes seconds.

  1. 01

    Your wallet builds the transaction

    MetaMask, Sparrow or any of 15+ wallets shows a QR code. Your wallet, not ours. There is no Keycard app.

  2. 02

    Insert your card, enter your PIN

    Shell turns on at insertion and boots in 20 milliseconds. Your PIN goes into a physical keypad.

  3. 03

    Point Shell at the screen

    One button. The global-shutter camera reads even animated QR codes instantly.

  4. 04

    Read what you are signing

    Recipient, amount, network, fee. Decoded on Shell's own screen, out of reach of malware.

  5. 05

    Press OK to sign

    The card signs on its secure element. Keys never leave it.

  6. 06

    Show the QR back

    Your wallet's camera reads Shell's reply and broadcasts. Your keys never touched a connected machine.

You decide how your keys are organized

The card is the key, not the device. Each card is one BIP-32 wallet with its own PIN, and it derives as many keys as you will ever need. How many cards you keep, what each one holds and where they live is your design, not ours.

m/44'/60'/0' m/84'/0'/0' unlimited

One card

One wallet, an unlimited number of keys

One card is one BIP-32 wallet. From a single seed it derives unlimited keys and addresses, hardened or not, ten levels deep. That is why one card signs for Bitcoin, Ethereum and every EVM chain and L2. Name it, and the name becomes the menu title on insertion.

= = PIN 1 PIN 2 PIN 3 same seed

A card and its spares

Your backup is a card, not a piece of paper

The same seed, on as many cards as you like. Each has its own PIN and works alone, so a spare in another building is a wallet you can use, not a note you hope is still legible. Words follow BIP-39, restorable in any compatible wallet. Or use SLIP-39 Shamir shares, with your own threshold.

savings daily testing next one

Independent cards

Separate wallets, separate risk

A second wallet is a second card. Long-term holdings on one, contract keys on another: different seeds, different PINs, nothing shared, so a mistake in one cannot reach the other. Unlimited Keycards per Shell, swapped in seconds. Shell wakes on insertion, boots in twenty milliseconds, and never asks you to pair again.

2 of 3 spend

Multisig across cards

No single card can move the funds

Spread a Bitcoin multisig across several cards, one key each, kept in different places. Native SegWit, P2WSH, with a dedicated export flow and full PSBT support, so Sparrow and other coordinators see a normal cosigner. Losing one card costs you a card.

Bring your existing keys or generate brand new ones

  • Generate on the card. True hardware randomness, 12 or 24 BIP-39 words.
  • Bring your own. Type your existing BIP-39 words and the card takes them.
  • Scan a SeedQR To import your seed
  • SLIP-39 Shamir shares Import or generate, with your own threshold.
  • BIP-39 passphrases are supported. Chosen when the card is initialized, and set once.

Use your cards on all your devices

Shell is the best place to use your keys, not the only one. The same card taps a phone over NFC, or sits in a USB reader on a desktop. Nothing to re-pair and nothing to migrate, because the keys never left the card in the first place. Your keys can never ever leave the card.

  1. In Shell

    Camera, screen and keypad, never connected to anything. The setup this page is about, and the one to use for anything that matters.

  2. On your phone

    Tap the card against the back of the phone. Status mobile talks to it over NFC, and the card signs on its own secure element. No Shell in the room.

  3. On your desktop

    A plain contactless reader over USB, no drivers to install. Status desktop and Sparrow both work this way.

See what you sign

Shell decodes the transaction on its own screen — recipient, amount, network, fee — before anything is signed. What you approve is exactly what the card signs. Nothing in between.

Shell decodes ERC-20 transfers, token approvals with spender and amount, EIP-712 typed data, Safe transactions and Bitcoin PSBT with change detection. What cannot be decoded is shown raw, never hidden.

Everything Shell decodes

Ethereum

  • To address, amount, network name and gas fee before signing
  • Full call data display
  • ERC-20 transfers, ticker and amount from the on-device token database
  • ERC-20 approve: spender address and approved amount
  • ABI decoding: function name and arguments for known contracts
  • EIP-712 typed data with type labels, digest always shown
  • ERC-8213 hash, so the digest can be checked independently on a second machine. erc8213.eth.limo
  • Gnosis Safe dedicated view, SafeTx human-readable
  • Permit and Permit2
  • personal_sign raw message, scrollable

Bitcoin

  • PSBT: each output with recipient and amount, fee calculated
  • Change output auto-detected and labeled separately
  • Multisig PSBT with appropriate labeling

Always

  • ETH and BTC receiving addresses on screen, exportable as QR
  • Every field scrollable before confirmation
  • Signing requires a physical button press

Ethereum and Bitcoin

Ethereum

  • Ethereum mainnet and every EVM chain and L2, chain names resolved from the on-device database

Solana is not supported.

Bitcoin

  • Legacy, Nested SegWit, Native SegWit
  • Multisig (P2WSH)
  • Full PSBT support, all sighash flags, testnet included

Taproot is not supported yet.

Security, layer by layer

Your keys never leave the secure element

Keys are generated inside the Keycard secure element by its own hardware random number generator, and they never come out. It is certified EAL6+, the same class that protects bank cards. The card is the signer: a 32-byte hash goes in, a signature comes out. The microcontroller that drives Shell's screen, keypad and camera never sees key material, so a compromised Shell has nothing to leak.

Sealed at production

The card leaves the factory locked: its GlobalPlatform keys are randomized and the chip is in SECURED state, so no applet can be installed, replaced or removed through its interface.

Air-gapped, and why it matters

No WiFi, Bluetooth or cellular hardware exists on the board. The only channel is light: QR codes in, QR codes out. USB data has a kill switch, and Shell is stateless: remove the card and it forgets everything.

A PIN, not a fingerprint

Your PIN goes into a physical keypad, and there are no biometrics on the device by design. A PIN is something you know. A fingerprint can be physically compelled.

Proves it's genuine

Every card carries a factory-signed certificate, and every Shell holds a unique device key. At first boot, device and server prove genuineness to each other, cryptographically. A verification counter flags anything unexpected.

Under duress, a second PIN

An optional duress PIN opens a decoy wallet, cryptographically distinct from your real one. Nothing on screen reveals which PIN you used.

The most open and verifiable hardware wallet

Every claim below has a verification path. You never have to believe us.

Firmware you can rebuild

MIT licensed and reproducible: build from source, compare the hash. Same source, same binary.

Shell firmware on GitHub →

Hardware you can fabricate

Schematics, Gerbers, BOM and 3D files under CERN-OHL-S v2. Enough to manufacture the device, not just to audit the design.

Hardware files on GitHub →

A database you can trace

Token lists, chain registry and ABIs built from public sources. Every version is signed and hash-verifiable.

How the database is built → Database version history →

Updates on your terms

Signed firmware, physical approval on the device, and a fully offline update path via USB drive. And the card's rules never change: the applet is sealed.

Update over the web → Update in air-gapped mode →

Build it yourself

Compile the firmware with your own keys. Program your own blank JavaCard. The DIY path removes the last trust assumption.

Build your own Keycard → DIY Keycard Shell →

Tech specs

Shell

Display2.0" TFT IPS, 240×320, adjustable brightness
Keypad12 hard-rubber clicky keys, durable coating
CameraGlobal shutter. Reads animated QR in one frame
BatteryRemovable BL-4C, about $3, sold worldwide. No tools
Boot20 ms. Turns on and off at card insertion
USB-CAny charger. Data kill switch in settings
EnclosureABS, dust resistant, pocket-sized
BrandingNone. No crypto identifiers on the device
SigningAir-gapped via QR (ERC-4527), or USB

Keycard

Secure elementNXP JCOP4 P71, EAL6+ Common Criteria
Form factorStandard bank-card, ISO 7816 + NFC
PowerNone needed. No battery, no moving parts
Lifespan20+ years. Water, dust and X-ray resistant
ReadersWorks with Shell and any standard card reader
BrandingNone. Looks like any card in your wallet

In the box

  • Keycard Shell
  • Keycard (black, no brand visible)
  • BL-4C replaceable battery
  • USB-C to USB-C cable

Before you buy

What if I lose my card or device?
Your keys live on the Keycard, protected by a PIN with limited attempts. Keep a spare Keycard or your recovery phrase as a backup, and a lost card or device never means lost funds.
Does it work with my wallet?
Shell signs with 15+ independent wallets over QR and USB, including MetaMask, Rabby and Sparrow. There is no Keycard companion app, no account, and nothing to install.
Shipping and returns
Shipping is free and takes 7 days. Returns: yes — 30 days after delivery. As with any security product, the packaging must be unopened for a return to be accepted.
What if Keycard the company disappears?
Nothing about your wallet depends on us. Your keys follow the BIP-39 standard, so any compatible wallet can restore them. Shell signs with 15+ independent wallets — there is no Keycard app or server in the loop. And the code, schematics and card applets are open-source public goods anyone can maintain. If we vanished tomorrow, your setup would keep working.
What does “air-gapped” actually mean?
Your keys live on hardware that never touches the internet. To sign, your wallet app shows a QR code; Shell scans it, decodes the transaction on its own screen so you can check it, and answers with a QR of the signed result. No cable, no Bluetooth — no radio hardware at all.

Your keys, your rules

Get Shell

Free shipping · 30-day returns · Verify your device is genuine at first boot

All our products