Skip to content

Latest commit

 

History

1,709 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

KISS Signer 💋

An airgapped single-sig Bitcoin signer hidden behind a fruit slashing arcade game.

Drawing the word KISS on the game menu, which opens the signer

Draw KISS on the menu to enter. You can customize the swipe after setup.

FRUIT ISLAND game menu KISS Signer home screen
What everyone sees: a playable game What you see after drawing KISS

Keep it simple. Make it clear. Make it safe.

Simulator  ·  Docs  ·  Walkthrough  ·  Changelog  ·  Roadmap  ·  Security  ·  Telegram  ·  X

Caution

Experimental beta firmware. Do not trust it with meaningful funds.

What it is

  • BIP39 seed plus passphrase. 12 or 24 words. The passphrase is typed or scanned every session and never stored.
  • Single-sig: native SegWit (BIP84, the default), nested SegWit (BIP49) and legacy (BIP44), plus Silent Payments: receive, send and spend (BIP352).
  • Airgapped. PSBTs move by QR (BC-UR) or SD card. The radio chip is held in reset from the first instruction of every boot.
  • Works with Sparrow and BlueWallet. Other coordinators work if they import a watch-only output descriptor (or a zpub) and exchange PSBTs by QR (BC-UR) or SD card for signing. BBQr is not supported.
  • Verifies before it signs. Every output, the fee and the change are derived again on the device; change is verified, not trusted.

Runs on three ESP32-P4 boards with a touch screen, camera and microSD slot. No soldering.

  • Guition JC4880P443C, 4.3in, 800×480
  • Waveshare ESP32-P4-WIFI6-Touch-LCD-3.5, 3.5in, 480×320
  • Guition JC1060P470C, 7in, 1024×600

Boards with the newer v3.x ESP32-P4 chip are not supported yet (roadmap).

Inspired by Bowser, a Bitcoin signer hidden under a Tetris game.

Install

Pick one. All three end the same way: unplug, wait 3 seconds, plug back in.

How You need
🟢 Easy Install page in your browser Chrome, Brave or Edge, a USB cable
🟡 Medium Verify the files yourself, then flash A terminal, gpg, esptool
🔴 Hard Build it from source Docker

Warning

Flashing erases the whole chip, keys included. Have your seed words and passphrase first.

🟢 Easy: from your browser

  1. Open the install page.
  2. Pick your board, plug it in, click Connect and install.
  3. Unplug, wait 3 seconds, plug back in.

🟡 Medium: verify, then flash

  1. From the latest release, download your board's firmware plus SHA256SUMS, SHA256SUMS.asc and kiss_signer_pgp.asc.

    Board Firmware
    Guition 4.3in kiss-signer-VERSION.bin
    Waveshare 3.5in kiss-signer-VERSION-ws35.bin
    Guition 7in kiss-signer-VERSION-jc1060.bin
  2. Verify. Cross-check the fingerprint somewhere other than this page.

    gpg --import kiss_signer_pgp.asc
    gpg --verify SHA256SUMS.asc SHA256SUMS      # expect this fingerprint:
    # 166A CBF3 7786 FCEA A694  96DE 886F 1BFE B84E F1C0
    shasum -a 256 --ignore-missing -c SHA256SUMS   # macOS (Linux: sha256sum)
  3. Flash.

    pip install esptool
    # port: /dev/cu.usbmodem* or /dev/cu.wchusbserial* (macOS) | /dev/ttyACM* (Linux) | COMx (Windows)
    esptool --chip esp32p4 -p <port> -b 460800 \
      --before default-reset --after no-reset write-flash \
      --flash-mode dio --flash-size 16MB --flash-freq 80m \
      0 kiss-signer-VERSION.bin
  4. Unplug, wait 3 seconds, plug back in.

Tip

No internet on that computer? Download kiss-signer-VERSION-offline.zip and its .asc instead. Verify the zip with gpg --verify, unzip it, run the serve script inside, and use the install page offline.

🔴 Hard: build it from source

You only need Docker. Builds are reproducible, so your hashes should match CI's.

tools/build_release.sh                   # Guition 4.3in
KISS_BOARD=ws35 tools/build_release.sh   # Waveshare 3.5in
KISS_BOARD=jc1060 tools/build_release.sh # Guition 7in

Each writes its image to its own build-release* folder; hash it with shasum -a 256 and compare.

🔄 Updating

Copy your board's -update.bin from the latest release to an SD card, then SETTINGS > FIRMWARE. Your keys stay.

First boot

Draw KISS on the menu. Setup takes two minutes: generate or restore a BIP39 seed, write down the seed words, verify the backup, set a passphrase.

Write down the 12 recovery words Backup verified: every word matched
Write down the seed words Type them back to confirm

Tip

Check your backup before you fund it: KEYS > BACKUP > SEED WORDS. Also write down the fingerprint on the home screen. A mistyped passphrase gives no error, it just opens different, empty keys.

Day to day

Under KEYS > PAIR COORDINATOR, export the watch-only output descriptor to Sparrow (or the zpub to BlueWallet). The coordinator tracks your UTXOs, builds the PSBT and broadcasts it; KISS verifies and signs.

Receive screen with address QR Sign screen showing amounts, fee, and hold to sign
Verify the receive address on the device Every output, the fee and change, before you sign

Rehearse on testnet or signet first: SETTINGS > SIGNER > NETWORK.

Before signing, the device flags a high fee, dust attack inputs, inputs that link your addresses, tiny change, and change your coordinator cannot see.

Features

🎲 Entropy you can check

  • New seeds mix four sources: the camera, the chip's hardware RNG, your taps and timing. No single source decides your keys.
  • Or roll a die 50 times or flip a coin 128 times, and check the SHA256 on any computer.
  • Or draw 11 words blind from a cut up BIP39 list; the device works out the checksum word.
  • A randomness audit tests the chip's RNG on the device.

🕵️ Duress

  • Drawing KISS alone opens decoy keys, with no passphrase. Keep a little in them to hand over.
  • Your real keys sit behind your own extra swipe and your passphrase. You can also replace KISS with your own drawing.

💾 Where your seed words live, your choice

  • Flash: on the device, unencrypted in this beta.
  • SD card: sealed to this device, so the card alone opens nothing. Not a backup.
  • Amnesic: RAM only, gone at power off. Load your seed words every session.

🔑 Backups

  • Seed words on paper, verified on the device without showing them.
  • An encrypted backup as a QR or a file on the SD card, in Krux's KEF format, opened only with your password.

🛡️ Firmware you can trust

  • Reproducible builds and GPG signed releases.
  • SD card updates are checked on the device against two signatures, ECDSA and post quantum SLH-DSA, and roll back by themselves if the new firmware fails to start.

🌍 22 languages, and a ? on any Bitcoin term opens a plain words card.

Docs

The guide has the details. The walkthrough is the short version.

🔐 Security

Found a vulnerability? Email diybitcoin@protonmail.com. Please do not open a public issue for anything that could put funds at risk. Details in SECURITY.md.

💬 Community

  • Telegram: t.me/KISS_signer for questions, ideas and help
  • X: @KISS_signer for news and releases
  • GitHub issues for bugs that do not put funds at risk

🤝 Contributing

Pull requests are welcome. To keep reviews quick:

  1. One open pull request at a time. GitHub enforces this; drafts do not count. When yours is merged or closed, open the next.
  2. One fix or feature per pull request, based on the develop branch.
  3. Read CONTRIBUTING.md first: building, tests, and testing on a real board.

New to pull requests? GitHub's guide walks you through it. Found a vulnerability? Email it instead, see Security above.

License

MIT. Third party components keep their own licenses, listed in THIRD_PARTY_NOTICES.md.

Releases

Packages

Contributors

Languages