An airgapped single-sig Bitcoin signer hidden behind a fruit slashing arcade game.
Draw KISS on the menu to enter. You can customize the swipe after setup.
![]() |
![]() |
| What everyone sees: a playable game | What you see after drawing KISS |
Keep it simple. Make it clear. Make it safe.
Simulator · Docs · Walkthrough · Changelog · Roadmap · Security · Telegram · X
Caution
Experimental beta firmware. Do not trust it with meaningful funds.
- BIP39 seed plus passphrase. 12 or 24 words. The passphrase is typed or scanned every session and never stored.
- Single-sig: native SegWit (BIP84, the default), nested SegWit (BIP49) and legacy (BIP44), plus Silent Payments: receive, send and spend (BIP352).
- Airgapped. PSBTs move by QR (BC-UR) or SD card. The radio chip is held in reset from the first instruction of every boot.
- Works with Sparrow and BlueWallet. Other coordinators work if they import a watch-only output descriptor (or a zpub) and exchange PSBTs by QR (BC-UR) or SD card for signing. BBQr is not supported.
- Verifies before it signs. Every output, the fee and the change are derived again on the device; change is verified, not trusted.
Runs on three ESP32-P4 boards with a touch screen, camera and microSD slot. No soldering.
- Guition JC4880P443C, 4.3in, 800×480
- Waveshare ESP32-P4-WIFI6-Touch-LCD-3.5, 3.5in, 480×320
- Guition JC1060P470C, 7in, 1024×600
Boards with the newer v3.x ESP32-P4 chip are not supported yet (roadmap).
Inspired by Bowser, a Bitcoin signer hidden under a Tetris game.
Pick one. All three end the same way: unplug, wait 3 seconds, plug back in.
| How | You need | |
|---|---|---|
| 🟢 Easy | Install page in your browser | Chrome, Brave or Edge, a USB cable |
| 🟡 Medium | Verify the files yourself, then flash | A terminal, gpg, esptool |
| 🔴 Hard | Build it from source | Docker |
Warning
Flashing erases the whole chip, keys included. Have your seed words and passphrase first.
- Open the install page.
- Pick your board, plug it in, click Connect and install.
- Unplug, wait 3 seconds, plug back in.
-
From the latest release, download your board's firmware plus
SHA256SUMS,SHA256SUMS.ascandkiss_signer_pgp.asc.Board Firmware Guition 4.3in kiss-signer-VERSION.binWaveshare 3.5in kiss-signer-VERSION-ws35.binGuition 7in kiss-signer-VERSION-jc1060.bin -
Verify. Cross-check the fingerprint somewhere other than this page.
gpg --import kiss_signer_pgp.asc gpg --verify SHA256SUMS.asc SHA256SUMS # expect this fingerprint: # 166A CBF3 7786 FCEA A694 96DE 886F 1BFE B84E F1C0 shasum -a 256 --ignore-missing -c SHA256SUMS # macOS (Linux: sha256sum)
-
Flash.
pip install esptool # port: /dev/cu.usbmodem* or /dev/cu.wchusbserial* (macOS) | /dev/ttyACM* (Linux) | COMx (Windows) esptool --chip esp32p4 -p <port> -b 460800 \ --before default-reset --after no-reset write-flash \ --flash-mode dio --flash-size 16MB --flash-freq 80m \ 0 kiss-signer-VERSION.bin
-
Unplug, wait 3 seconds, plug back in.
Tip
No internet on that computer? Download kiss-signer-VERSION-offline.zip
and its .asc instead. Verify the zip with gpg --verify, unzip it, run the
serve script inside, and use the install page offline.
You only need Docker. Builds are reproducible, so your hashes should match CI's.
tools/build_release.sh # Guition 4.3in
KISS_BOARD=ws35 tools/build_release.sh # Waveshare 3.5in
KISS_BOARD=jc1060 tools/build_release.sh # Guition 7inEach writes its image to its own build-release* folder; hash it with
shasum -a 256 and compare.
Copy your board's -update.bin from the latest release to an SD card, then
SETTINGS > FIRMWARE. Your keys stay.
Draw KISS on the menu. Setup takes two minutes: generate or restore a BIP39 seed, write down the seed words, verify the backup, set a passphrase.
![]() |
![]() |
| Write down the seed words | Type them back to confirm |
Tip
Check your backup before you fund it: KEYS > BACKUP > SEED WORDS. Also write down the fingerprint on the home screen. A mistyped passphrase gives no error, it just opens different, empty keys.
Under KEYS > PAIR COORDINATOR, export the watch-only output descriptor to Sparrow (or the zpub to BlueWallet). The coordinator tracks your UTXOs, builds the PSBT and broadcasts it; KISS verifies and signs.
![]() |
![]() |
| Verify the receive address on the device | Every output, the fee and change, before you sign |
Rehearse on testnet or signet first: SETTINGS > SIGNER > NETWORK.
Before signing, the device flags a high fee, dust attack inputs, inputs that link your addresses, tiny change, and change your coordinator cannot see.
🎲 Entropy you can check
- New seeds mix four sources: the camera, the chip's hardware RNG, your taps and timing. No single source decides your keys.
- Or roll a die 50 times or flip a coin 128 times, and check the SHA256 on any computer.
- Or draw 11 words blind from a cut up BIP39 list; the device works out the checksum word.
- A randomness audit tests the chip's RNG on the device.
🕵️ Duress
- Drawing KISS alone opens decoy keys, with no passphrase. Keep a little in them to hand over.
- Your real keys sit behind your own extra swipe and your passphrase. You can also replace KISS with your own drawing.
💾 Where your seed words live, your choice
- Flash: on the device, unencrypted in this beta.
- SD card: sealed to this device, so the card alone opens nothing. Not a backup.
- Amnesic: RAM only, gone at power off. Load your seed words every session.
🔑 Backups
- Seed words on paper, verified on the device without showing them.
- An encrypted backup as a QR or a file on the SD card, in Krux's KEF format, opened only with your password.
🛡️ Firmware you can trust
- Reproducible builds and GPG signed releases.
- SD card updates are checked on the device against two signatures, ECDSA and post quantum SLH-DSA, and roll back by themselves if the new firmware fails to start.
🌍 22 languages, and a ? on any Bitcoin term opens a plain words card.
The guide has the details. The walkthrough is the short version.
Found a vulnerability? Email diybitcoin@protonmail.com. Please do not open a public issue for anything that could put funds at risk. Details in SECURITY.md.
- Telegram: t.me/KISS_signer for questions, ideas and help
- X: @KISS_signer for news and releases
- GitHub issues for bugs that do not put funds at risk
Pull requests are welcome. To keep reviews quick:
- One open pull request at a time. GitHub enforces this; drafts do not count. When yours is merged or closed, open the next.
- One fix or feature per pull request, based on the
developbranch. - Read CONTRIBUTING.md first: building, tests, and testing on a real board.
New to pull requests? GitHub's guide walks you through it. Found a vulnerability? Email it instead, see Security above.
MIT. Third party components keep their own licenses, listed in THIRD_PARTY_NOTICES.md.





