Model #29 • Desk 7: Digital Assets & Crypto Derivatives

Crypto Key Custody & Cold Storage Security Architecture Workbench

An institutional threat modeling engine, hardware security module comparator, and cryptographic key derivation simulator. Evaluate single-sig, air-gapped hardware, multi-signature, and MPC architectures against real-world physical and digital attack vectors.

Custody Architecture Threat Vector Evaluation

Select a custody architecture to assess systemic resilience across 8 common attack vectors.
Resilience Score
28 / 100
Critical Vulnerability
Physical Attack Defense
Low
Device & coercion tolerance
Remote Network Defense
Failing
Malware & keylogger risk
Single Point of Failure
Present
Loss of 1 seed drains vault
Threat Vector Vulnerability Status Microstructure Analysis & Mitigation

Institutional & Sovereign Hardware Signer Matrix

Compare security microcontrollers, firmware auditability, and communication physical air-gaps.
Filter Devices:
Ledger

Ledger Flex / Nano X

  • Secure ElementSTMicroelectronics ST33 (EAL6+)
  • Firmware ModelProprietary BOLOS (Closed)
  • Air-Gap MechanismNone (USB-C & Bluetooth)
  • Display & SigningE-Ink Touch / OLED (Clear Sign)
  • Ecosystem SupportMulti-Chain (5,500+ Assets)
EAL6+ Secure Chip Multi-Chain Utility
SatoshiLabs

Trezor Safe 3 / Safe 5

  • Secure ElementOPTIGA™ Trust M (EAL6+)
  • Firmware Model100% Open Source (GPLv3)
  • Air-Gap MechanismNone (USB-C Cable)
  • Display & SigningColor Touchscreen with Haptic
  • Standard ProtocolsBIP-39, Shamir (SLIP-39)
Open Source Firmware Shamir Secret Sharing
Coinkite

Coldcard Mk4 / Coldcard Q

  • Secure ElementDual: ATECC608A + DS28C36
  • Firmware ModelViewable Source (Verifiable)
  • Air-Gap MechanismMicroSD, Optical QR, NFC
  • Display & SigningFull QWERTY + High-Res LCD
  • Security FeaturesBrick PIN, Duress Wallet, Ephemeral
Bitcoin Only Dual Secure Element True Air-Gap
Shift Crypto

BitBox02 (Bitcoin-Only Edition)

  • Secure ElementMicrochip ATECC608A
  • Firmware Model100% Fully Open Source
  • Air-Gap MechanismMicroSD Seed Backup / USB-C
  • Display & SigningInvisible Touch Sensors + OLED
  • Key FeaturesInstant MicroSD Backup, Anti-Klepto
Open Source Anti-Klepto Protocol
Blockstream

Blockstream Jade

  • Secure ElementVirtual SE (Blind Oracle Model)
  • Firmware Model100% Open Source Hardware & SW
  • Air-Gap MechanismCamera QR Code Scanning
  • Display & SigningColor IPS LCD with Click Wheel
  • Liquid & LightningNative Liquid Network L-BTC Support
Camera Air-Gap Blind Oracle PIN
Foundation Devices

Passport (Batch 2)

  • Secure ElementMicrochip ATECC608A
  • Firmware Model100% Open Source (GPLv3)
  • Air-Gap MechanismHigh-Res Camera QR + MicroSD
  • Power SystemRemovable Standard Nokia Battery
  • Physical EnclosureMachined Zinc & Physical Keypad
Zero Wireless Transceivers Removable Battery

BIP-39 Mnemonic Entropy & Combinatorial Security Engine

Examine the cryptographic math separating 128-bit vs 256-bit mnemonic seed derivation.
BIP-39 encodes entropy in chunks of 11 bits mapped to a standardized 2,048-word dictionary.
Testing HMAC-SHA512 key derivations with 2,048 rounds of PBKDF2.
Entropy Bit Strength
256 bits
+ 8 bits checksum
Combinatorial Space
1.15 × 1077
Possible Mnemonic Permutations
Estimated Exhaustive Brute-Force Duration
> 1050 Years
Vastly exceeds the projected thermodynamic lifespan of the universe (10100 years)
$$\text{BIP-39 Key Stretching: } \text{Seed} = \text{PBKDF2}(\text{mnemonic}, \text{"mnemonic"} \parallel \text{passphrase}, 2048, 512, \text{HMAC-SHA512})$$ $$\text{Elliptic Curve Public Key Derivation: } K = k \cdot G \quad \text{over } \mathbb{F}_p: y^2 \equiv x^3 + 7 \pmod p$$

BIP-39 Passphrase ("25th Word") Plausible Deniability Simulator

Demonstrates how any passphrase acts as an irreversible cryptographic salt, generating completely distinct wallet addresses.
Important Cryptographic Principle: There is no such thing as an "incorrect" passphrase. Every distinct string derives an entirely new, cryptographically valid set of addresses without revealing whether a vault holds funds.
Decoy / Coercion Vault (No Passphrase)
Default Derivation (Passphrase = "")

This wallet is accessed by entering the standard 24 words with an empty passphrase. Store a nominal amount here to satisfy a physical attacker or duress scenario.

Derived Native SegWit Bitcoin Address (BIP-84):
bc1q7x4p89kz2v93ma0y4flj6u8e7w90rt27p9q00a
Derived Ethereum / EVM Address (BIP-44):
0x4a82173F9004fBb5bE41662Ec5cDcb9a896C7891
Hidden Sovereign Vault (With Passphrase)
Derived Salted Vault

This vault only materializes when your exact passphrase is provided. If you type even a single character differently, a completely separate empty vault is derived.

Derived Native SegWit Bitcoin Address (BIP-84):
bc1q9v83w7k4m0p2a5x9e8y1z0d3c6h8u7j5n2q99z
Derived Ethereum / EVM Address (BIP-44):
0x91d3A90e1B7829aC857e8412F5e7b7891B2C0542

Sovereign Self-Custody Disaster Recovery & Inheritance Protocol

Physical resilience checklist and multi-generational key transition architecture.

Phase 1: Physical Seed Plate Engineering

Phase 2: Geographic Redundancy

Phase 3: Institutional Inheritance Protocol