Hardware Signer for Tezos Baking on Raspberry Pi Zero 2W
Russignol is a dedicated hardware signing device. Your validator keys stay on isolated hardware.
Website: russignol.com | Demo: YouTube
tz4 addresses (BLS signatures) enable aggregated attestations—combining hundreds of signatures into one per block. This reduces consensus data by 63x (from ~900 MB/day to ~14 MB/day), allowing all bakers to attest every block instead of ~200 out of ~300. The result: stronger security through full participation, predictable rewards proportional to stake, and reduced overhead that supports further block time improvements.
Ledger Nano can't perform BLS signatures fast enough for 6-second blocks, and software signers store keys on internet-connected machines—exposing them to remote exploits and memory-scraping attacks.
- BLS12-381 signing — ~6ms via BLST
- USB gadget ethernet only — WiFi, Bluetooth, Ethernet compiled out of kernel
- PIN-protected key storage — AES-256-GCM encryption, PIN-derived key via Scrypt (256MB memory-hard)
- Hardened kernel — Kernel lockdown (integrity mode, enforced early), module signature enforcement, no core dumps, heap zeroed on free, locked accounts, no getty or SSH
- High watermark protection — Per-key watermarks for consensus and companion key signing, pre-set one level into the future so steady-state signing doesn't block on disk I/O, Blake3-hashed for corruption detection, persists across reboots
- Touch-enabled e-ink display — On-device PIN entry (never crosses USB), menu-based navigation with System, Activity, Blockchain, Watermarks, About, and Shutdown pages
- Activity LED — Visual indication of baker connection
- CPU frequency scaling — Idles at 600 MHz, boosts to 1000 MHz during signing and PIN entry
- Flash-optimized storage — F2FS with hardware-adaptive alignment, over-provisioning for wear leveling
- Key restore across reflashes —
russignol image flash --restore-keyscarries keys and watermarks over from an existing card - Key migration —
russignol image flash --migrate-keysimports keys from a Nomadic Labs tezos-rpi-bls-signer card - Network mismatch detection — Warns during key restore if the key's network doesn't match the connected node
| Component | Part |
|---|---|
| Board | Raspberry Pi Zero 2 W, with headers |
| Display | Waveshare 2.13inch Touch e-Paper HAT (part 19493, or 20716 with case) |
| Storage | microSD, 8 GB or larger, high-endurance |
| Cable | USB data cable, micro-B at the device end |
Part numbers, what not to buy by mistake, and where to order: Hardware.
- Automated Installation (recommended)
- Manual Installation
- LXC Container Setup
- Hardware
- Device Operation
- Security Audit
- Watermark Crash Analysis
- TPM Key Storage Compared to a Dedicated Signer
- Host Utility
- Configuration
- Key Rotation
- Inspired by tezos-rpi-bls-signer
- Powered by blst
- Logic ported from Tezos octez-signer
- Icons by Mobirise Icons
