Security Architecture
How Stasher protects your keys
A plain, honest account of what Stasher protects you from and how it does it. No marketing hand-waving. If a claim isn't here, we don't make it.
Threat Model
What Stasher defends against, and what it can't
With self-custody you stop trusting a company and start trusting your own device. Here is exactly where that protection starts and where it stops.
Remote attackers
The keys that can spend your money never leave the device, and the chip that holds them never connects to the internet. Moving your cold savings takes your PIN and a press of the button on the device itself, and nobody can press that button over the internet.
A compromised computer
The keys that can spend your money never reach your computer. Even if it is infected, it can't move your cold savings unless you approve the transaction on the device itself, so read the device's screen before you press. The hot side is made for quick spending, so it is protected by limits instead: caps on sends and swaps that the device itself enforces, and a freeze you can switch on from your app.
Physical theft
A thief who takes your device still needs your PIN. Your savings keys are stored encrypted, the secure element checks every PIN attempt, and repeated wrong guesses force longer and longer waits.
Firmware tampering
The device only installs firmware that Stasher has signed. A security update also blocks the versions it replaces for good, so nobody can load one with a known weakness.
What we can't protect
If you lose your recovery phrase, or give it (or your PIN) to someone else, no wallet can help. Keep your recovery phrase offline and private. It is also the only way back if you forget your PIN.
Secure Element
Keys guarded by a JIL High secure element
A secure element is a small chip built for one job: keeping a secret, even from someone who has the device on a lab bench. Stasher's is rated JIL High, the top level on the scale used to grade how well smartcard chips resist attack. Your savings keys are stored encrypted, and unlocking them takes both your PIN and the secure element, so a copy of the device's storage is not enough to get at them.
Cold and Hot Architecture
Two chips, two wallets, one boundary
Stasher keeps two wallets in one device. The cold wallet is for savings: every spend takes your PIN and a press of the physical button, every time. The hot wallet is for everyday spending: your paired app can spend from it without the button, but only within limits the device itself enforces. The two use different keys, so nothing that can spend hot can spend cold. Your keys sit on a chip that never connects to the internet. A second chip does the talking, over USB, Bluetooth and Wi-Fi, and anything about your money crosses it locked, so it can't read it or fake it. That is why the hot side can be reached from anywhere while the cold side can't: a message can travel over the internet, but it can't press a button.
Post-Quantum Cryptography
Quantum-resilient where it counts
Future quantum computers are expected to break some of the encryption in use today. Stasher already uses quantum-resistant algorithms selected by NIST, alongside today's proven ones, in two places it controls: when your app pairs with the device, and when firmware is signed. An attacker would have to break both kinds. The signatures on your transactions still follow each blockchain's own rules, as they do in every wallet, because only the blockchains can change those.
Clear Signing
The device decides what it shows you
Blind signing means approving a transaction you can't actually read, and it is how most wallet users get drained. When you send a coin or a token Stasher recognises from your savings, the device works out for itself who is being paid and how much, straight from the transaction, and shows you that on its own screen. Without this step, a token transfer shows up as sending zero to the token's contract, which tells you nothing about where your money is going. The device does not rely on your computer's description of the payment, so an infected computer cannot dress up one transfer as another.
Defense in Depth
Layered protection
Security doesn't rest on any single feature.
Stored encrypted
Your recovery seed is never stored in readable form. It is encrypted, and unlocking it takes both your PIN and the secure element inside your device.
Escalating lockout
After a few wrong PINs the device forces longer and longer waits, and it allows only a limited number of wrong attempts in a row. Guessing the PIN is impractical.
True hardware randomness
A wallet created on Stasher gets its keys from real physical randomness produced by hardware, not from software-generated numbers that could be predicted.
On-device confirmation
Every cold transaction needs your PIN and a press of the physical button. For the sends, swaps and other actions it recognises, the device shows you who is being paid and how much on its own screen first.