Thanks review and spending the time with the proposal
, I want to address the points raised since I think some of them come from a misunderstanding
I think it’s a cool technical project and honestly I’d like to play with it myself, but it feels too niche for ZCG funding, especially at this budget.
The wishlist lists hardware wallet support and lightweight physical storage, so the question is really about the DIY approach, and I think that is the strongest part of the proposal not the weakest (and one of the main reasons SeedSigner exists in Bitcoin). A commercial hardware wallet means trusting a vendor’s supply chain and a vendor’s customer database.
Leaks of customer database keeps hapening left and right, and then these users get target by fishing campaings (I.E Trezor on X: "Two days ago, we received an update from our shipping provider, ShipMonk. We're deeply saddened to share the news that the recent data breach affects more customers than originally thought. Another 67,000 customers from the US who ordered between November 2019 and August 2021 were af… / X ), some users are being targeted in real life by criminals to steal their crypto ( A man with a bitcoin fortune was allegedly tortured for weeks in a New York City home. Here's what we know. - CBS News ).
Because this device can be built from off the shelf parts, no one can know that these are meant to build a hardware wallet, so it preserves your privacy as a holder in real life too.
cc @artkor
I agree that this is a fun project, but unfortunately I don’t think the value matches the ask. I’m going to reject.
I will resubmit at 30,000 USD
cc @GGuy
I agree to reject. There are also the concerns about hot wallet integration mentioned in the proposal. The proposal mentions upstream integration with ZODL, and until that were agreed upon I think it would be premature to make that assumption.
@paulbrigner on the ZODL integration point, I think the proposal was unclear here and that is on me. The signer does not need anything from ZODL to work, it will speak the same PCZT over UR transport that Zashi already uses with Keystone, so a released Zashi build can hand a transaction to the device and broadcast the signed result today with no changes on the wallet side.
What I meant by upstream integration was the nice to have of Zashi listing the device by name in its hardware wallet screen (whch is an easy change I can submit on my own for improved UX)
It’s reject from me as well, even though it’s probably a cool nerdy project. It’s not worth the funding from us right now with a very limited user group
@zerodartz on the limited user group: I think is smaller than it should be precisely because the option does not exist yet. Today if you hold shielded ZEC and want your keys off your phone you have exactly one class of device to choose from, all commercial (with a vendor supply chain).
Anyone who wants an open, verifiable signer has no options, so of course that group looks like zero from the outside. On Bitcoin the same group turned out to be large once the option was available, specially users that value privacy. the Bitcoin SeedSigner latest release image was downloaded over 20k times in the two months since July.
The ZODL integration is a bit of an issue, but he did mention that only a small change is needed, so maybe he can do it without. I agree it’s a bit too expensive. It’s really a hobbyist project, because in terms of cost it isn’t really cheaper than buying a hardware wallet once you account for the parts you have to buy and assemble, and the result will be less secure because it doesn’t have a secure element. For a hobbyist project, this request is way too high for me.
@hanh on cost: the parts are around 50 USD, so is cheaper, but I agree price is not the argument. The argument is that nothing about the device passes through a vendor, no order, no shipment, no firmware download signed by a company, no customer record. You buy generic parts anywhere, build the image yourself or verify the published one against a reproducible build, and nobody knows you own it.
On the secure element I would argue the SeedSigner operational model is more secure. A secure element protects a secret that is stored on the device against someone who has the device in hand but this design stores nothing. The seed is loaded per session from a password protected SeedQR, lives in RAM while you sign, and is gone when you power off.
There is no secret at rest for an attacker to extract. This is a short explanation:
On the request being too high, I will resubmit is at 30,000 USD
Thanks again for taking the time to review the proposal and for the feedback ![]()