Offline hardware vault & 2FA

SEED VAULT

Your hardware vault for recovery phrases & 2FA.

SEED VAULT is a standalone device that stores your seeds and 2FA codes offline, protected by PIN, passphrase, TOTP, secure wipe and encrypted cloning between devices.

Connection
100% offline
Security
PIN + passphrase + 2FA
Seed slots
Up to 15
FIRMWARE AUTO-CHECK USB • ED25519
WAITING FOR CONNECTION...

Connect your SEED VAULT via USB and authorize the browser.

Simple interface, serious security

SEED VAULT follows exactly the same flow as on the device screen: PIN, passphrase, 2FA, then access to your seed slots. No online account, no cloud, no automatic sync.

It is designed as a standalone safe: configure it once, store it in a secure place, and power it on only when you need your sensitive information.

The firmware always shows a clean minimalist UI with clear buttons (SEEDS, OPTIONS, CLONE, etc.). The website mirrors that same feeling so you immediately recognise the environment.

Key features

  • Up to 15 seed slots, each with a custom name.
  • Support for 12 or 24 words per seed.
  • Built-in TOTP 2FA (Google Authenticator compatible QR).
  • Encrypted Bluetooth cloning between SEED VAULT devices.
  • Secure full wipe (ERASE ALL) directly from the UI.

Security architecture

SEED VAULT is built to minimize the attack surface. Everything revolves around three layers: PIN, passphrase, 2FA.

1. 8-digit PIN

Access starts with an 8-digit PIN. After several wrong attempts, the device can wipe itself to protect against brute-force attacks.

2. Passphrase

A passphrase complements the PIN. It is entered via a virtual keyboard on the device touchscreen and never leaves the hardware.

3. TOTP 2FA

A TOTP code is generated locally from a secret displayed once as a QR code during setup. No external backend is required.

Secure wipe (ERASE ALL)

A repeated gesture on the UI (the triangular “ERASE ALL” area) can wipe all data from NVS and reboot the device as factory-fresh.

Secure device-to-device cloning

The BLE cloning module lets you export or import seeds and settings between two SEED VAULT units using a pairing code. No server is involved: communication is direct and encrypted.

Hardware & firmware

Platform

SEED VAULT is built on an ESP32 board with a color touch display and NVS/flash for encrypted secret storage.

User interface

The firmware UI uses large high-contrast buttons (SEEDS, OPTIONS, CLONE, etc.), a dark background, light text and a green accent for validated actions – exactly like this site theme.

Firmware for integrators

The code is structured into clear modules: auth, seeds, clone, lights, wifi_time, etc. It is meant to be readable, maintainable and extensible.

User manual

The manual is provided as a PDF so you can easily print it or archive it with your sensitive documents.

Tip: print the manual and store it separately from the device, in a safe place.

Frequently asked questions

Does SEED VAULT connect to the Internet?
No. The device is designed to remain fully offline. Wi-Fi, if enabled, is only used for time sync or explicitly configured features.
What if I lose the device?
Without PIN, passphrase and 2FA, access to the data is extremely difficult. Depending on configuration, multiple failed attempts can trigger a full wipe.
Can I rename my seeds?
Yes. Each slot (SEED 01, SEED 02, etc.) can be given a custom name directly on the device screen. The site mirrors this notion of “named slots”.
How do I update the firmware?
Updates are done via USB/UART flashing with ESP-IDF / esptool. No forced OTA auto-updates.
SEED VAULT • INFO

NO CLOUD • NO AUTO BACKUP • NO HIDDEN SYNC
The device and this site share the same philosophy: simple, explicit, and under your control.