Affiliate disclosure: buying through links on this page may earn us a commission at no extra cost to you (details). Nothing here is investment advice.
Verdict up front: SeedSigner isn’t a product — it’s a philosophy you assemble with a screwdriver. Roughly $50 of Raspberry Pi parts becomes a fully air-gapped, stateless bitcoin signing device: it stores nothing, remembers nothing, and forgets your seed the moment it powers off. It’s completely open source, bitcoin-only, beloved by the community that takes self-custody most seriously — and it is emphatically not for everyone. 7/10 on our board, and the most interesting device on it.
Quick specs
| What it is | DIY build: Raspberry Pi Zero + camera + small LCD + open-source software (~$50 in parts, or community kits) |
| The stateless trick | No storage of secrets, ever. Your seed enters per-session — scanned from a SeedQR you keep on paper/steel, or generated on-device with dice/camera entropy — signs via QR, and vanishes at power-off |
| Air gap | Total: no radios on the build, QR codes in and out, works with Sparrow, Nunchuk, Specter (PSBT) |
| Secure element | None — by design. There’s no secret to guard when the device holds no secrets |
| Firmware | Fully open source; community-verifiable builds; bitcoin-only |
| Best at | Multisig cosigning, verifying-everything workflows, air-gapped signing for the ideologically committed |
| Our verifiability score | 7 / 10 |
Why stateless matters
Every other device on our board is a vault: it holds your key and defends it with chips, meshes, and self-destructs. SeedSigner deletes the problem instead of defending it — a stolen SeedSigner contains exactly nothing. Your seed lives where you put it (ideally stamped in steel, optionally as a scannable SeedQR), and the device is just disposable, auditable glue between that backup and a transaction. It also means one $50 build can serve as cosigner for any number of multisig quorums — which is why the serious multisig crowd adopted it as standard equipment.
The honest drawbacks
- You are the supply chain. No SE, no factory attestation — the security model assumes you sourced parts honestly and verified the software. That’s a feature to the target audience and a hazard to everyone else.
- Every session is a ceremony. Re-entering or scanning your seed each use is the cost of statelessness; beginners will fumble it.
- No formal audits — massive community review, yes; commissioned audit reports, no (it’s where our score docks it).
- Handling raw seeds regularly (SeedQR sheets, dice rolls) creates its own operational risks if your physical space isn’t controlled.
Who should build one
Multisig users wanting a stateless cosigner; verify-don’t-trust bitcoiners who enjoyed this paragraph; anyone who wants to understand their signer down to the solder. Skip it if you want a product with a warranty and a support line — that’s what the Coldcard Q and Keystone are for. Start at seedsigner.com for the build guide and verified releases.

