Skip to content

Security Architecture

How Stasher protects your keys

A plain, honest account of what Stasher protects you from and how it does it. No marketing hand-waving. If a claim isn't here, we don't make it.

Threat Model

What Stasher defends against, and what it can't

With self-custody you stop trusting a company and start trusting your own device. Here is exactly where that protection starts and where it stops.

01

Remote attackers

The keys that can spend your money never leave the device, and the chip that holds them never connects to the internet. Moving your cold savings takes your PIN and a press of the button on the device itself, and nobody can press that button over the internet.

02

A compromised computer

The keys that can spend your money never reach your computer. Even if it is infected, it can't move your cold savings unless you approve the transaction on the device itself, so read the device's screen before you press. The hot side is made for quick spending, so it is protected by limits instead: caps on sends and swaps that the device itself enforces, and a freeze you can switch on from your app.

03

Physical theft

A thief who takes your device still needs your PIN. Your savings keys are stored encrypted, the secure element checks every PIN attempt, and repeated wrong guesses force longer and longer waits.

04

Firmware tampering

The device only installs firmware that Stasher has signed. A security update also blocks the versions it replaces for good, so nobody can load one with a known weakness.

05

What we can't protect

If you lose your recovery phrase, or give it (or your PIN) to someone else, no wallet can help. Keep your recovery phrase offline and private. It is also the only way back if you forget your PIN.