Home-stashed fortunes have been a thief's delight throughout history. Don't store your life savings in your home.
Having your keys in a single location makes you an inviting target to criminals.
Sophisticated physical and violent thefts against bitcoin owners are becoming more prevalent.
Is your bitcoin security system sufficient to safeguard you and your sats from both theft and coercion?
With a 2-of-3 setup, any two devices must sign—one at a time—to access your bitcoin.
One device at your residence
One device at your workplace
One device with trusted party or vault
2-of-3
Multisig
2-of-3
Multisig
One device at your residence
One device at your workplace
One device with trusted party or vault
Perfect for disaster redundancy and coercion resistance. You choose your number of devices and the T-of-N threshold required to spend.
Frostsnap is the world's first hardware wallet that you do not need to trust. By using advanced cryptography (Distributed Key Generation + FROST), devices are never trusted to generate or hold the wallet secret on their own.
Trustless Multi-Device Security
No single device or component can compromise your bitcoin. Devices are never trusted to generate keys on their own.
Protection against: Device compromise, Weak or malicious entropy, Supply chain attacks.
Connect your devices and create a new wallet. Keys are generated collaboratively across all devices—no single device is trusted.
Place devices in separate secure locations (home, office, safe deposit box). Create backups for disaster recovery or device failure.
To spend, visit the required number of devices (e.g., 2-of-3) one at a time.
At Frostsnap we are building the self-custody tools we want as bitcoiners: sovereign controls for bitcoin through custom spending policies
Spending from a multisig wallet is inconvenient by design -- but for routine transactions, this can become annoying. We want convenient spends facilitated through spending-limited devices, while maintaining ultimate security for our savings.
We want easy and well-defined inheritance for our loved ones -- a straightforward and secure pathway for them to unlock generational wealth in your absence.
2-of-3 Unlock
Any two devices must sign
Cold Storage & Ultimate Control
For your life savings and major transactions
Limited Device
<Max 1M sats/day>
Convenient Daily Spending
Spending limits enforced by devices and app
Separate 3-of-5 Unlock
Family, Lawyer, Friend, Vault...
Access in Your Absence
Well-defined pathway for loved ones
Our vision for the building blocks of the parallel financial system, coming soon.
Protect and empower yourself with the ultimate Bitcoin security system
Early adopter edition with ongoing feature development
Quick answers to common questions
Frostsnap is a security system that keeps your life savings outside of your home. In a sleek convenient form factor that presents the power of multisignature security.
Frostsnap leverages advanced cryptography to push the frontier of trustless hardware and security capabilities. Devices are not trusted to generate keys on their own, with your phone or laptop participating in key generation to add entropy and verify correctness.
Each Frostsnap device is backed up independently with its own seed phrase. This seedphrase can be restored onto another device.
The beauty of threshold multisig is that you can lose some devices/backups and still recover your funds as long as you have enough to meet the threshold.
For a 2-of-3 setup, you could lose one device and its backup completely and still access your bitcoin with the remaining two devices.
See /recovery for more.
To restore knowledge of your wallet onto a new phone or laptop visit a threshold number of devices.
Backups can be loaded into blank devices during this process.
See /recovery for more.
Frostsnap does not have a device PIN that unlocks a secure element. This was a specific design choice: PINs act as an additional piece of information you have to remember and they complicate inheritance.
With Frostsnap the devices themselves are the pieces of information you need to have access to (or their backups), in a forgiving threshold of your choosing.
Device secrets are encrypted with a decryption key being secured by your phone's secure element.
In order to know about the wallet or begin signing requests a phone must have visited a threshold number of devices, learning the decryption key.
Frostsnap's security model is strongest in a greographically distributed threshold multisignature protected behind multiple devices. With a simple 2-of-3:
This provides both security (against theft) and redundancy (against loss). You can choose different thresholds like 3-of-5 for even more flexibility.
We're here to answer your questions. Pre-purchase inquiries welcome.
Frostsnap has finally arrived, and we're so excited to get these devices into your hands.
Long ago Lloyd and Nick were exploring exciting advancements in cryptography made possible by Bitcoin's Taproot upgrade. At the first Bitcoiner Malaysia meetup we met Adam showcasing his self-made Bitcoin electronics. The realization struck — putting this powerful cryptography onto hardware would revolutionize self-custody.
The dream for Frostsnap was born.
With several years of careful engineering, design exploration, and rethinking the challenges we face as Bitcoin users, we're thrilled to share this physical embodiment of our vision with you. As early adopters and longtime supporters, we're committed to ensuring you're well looked after with what should prove to be a historic piece of Bitcoin technology.
- The Frostsnap Team 💙