Retain your seed.
An open-source touchscreen hardware wallet for Nockchain. Your seed never leaves the device — review, approve and sign every transaction offline.
From setup to signature.
Initialize
Set a PIN and load a mnemonic on the device. Your seed is encrypted into a flash slot and never leaves.
Compose
Build or import a transaction in the browser composer, JS library, or CLI — plain sends, multisig, timelocks, HTLCs — and it streams to the device over USB.
Approve & sign
The touchscreen decodes and verifies the transaction — recipients, amounts, locks — you approve it, and the signed result is exported back to your host.
Specs & details
- MCU
- ESP32-S3 · dual-core Xtensa LX7
- Display
- 1.47" IPS LCD · 172×320
- Input
- Capacitive touch
- Transport
- USB-C · WebHID / WebUSB
- Seed vault
- AES-256-GCM · PIN-derived key
- Storage
- Encrypted NVS slots in flash
- Pairs with
- Open-source JS library · core CLI
- Footprint
- ≈ 24 × 44 × 5 mm
- On-device seed generation & storage
- Touchscreen review with on-device lock checks
- Offline signing — keys never leave
- Browser control over WebHID / WebUSB
- Composer: multisig, timelocks, hashlocks, HTLCs
- m-of-n multisig signing & co-signing
- Signed over-the-wire firmware updates
- Build & flash it yourself from source
- Open-source JS library & core CLI
A dedicated place to sign.
Nockster assumes your computer is hostile. Keys are generated and sealed on-device; only signed results ever cross the wire.
Encrypted seed slots
Seeds are stored in flash with AES-256-GCM, keyed by a PIN-derived key with a per-device salt.
See what you sign
The device decodes each transaction and verifies its lock tree — multisig thresholds, timelocks, hashlocks — against the committed lock-root, so a hostile host can't disguise where your coins actually go.
ESP32-S3 chip security
Hardened mode uses eFuse/HMAC-backed NVS keys, Secure Boot v2, and flash encryption — sealing the seed to the silicon itself.
Signed updates
Firmware update bundles are signed and verified on-device against a manifest before they can run.
Build it yourself
The firmware is fully open source — compile it from source and flash your own build instead of trusting a vendor binary.