Verify your
self-custody setup.

On your airgapped hardware.
No single wallet should grade its own homework.

Bitcoin Witness is a set of plaintext scripts that turns a Raspberry Pi into a hardened, air-gapped verification device with encrypted storage. Based on scripts instead of compiled binaries. No firmware, no black boxes.

Validate your hardware wallet outputs and multisig setups. Derive your addresses and descriptors independently. Inspect and sign PSBTs, generate reports for third parties, keys, passwords, encrypt documents, all offline, auditable, on your hardware.

The deliverables ↓  ·  Or see the Case for the Verification Layer →

✓ Bitcoin Witness v1.0raspberrypi · Pi 4   air-gap ✓
╭─ Bitcoin Witness ────────────────────────────────────────────╮
│ │
│ GUIDED WORKFLOWS │
│ 1 Verify Addresses, seed, backups, tx ││ 2 Generate New seed, BIP85, split shares ││ 3 Sign Transactions and messages ││ 4 Encrypt GPG documents for your heirs │
│ │
│ TOOLS │
│ 5 BIP39 Tool Offline HTML ││ 6 Electrum Wallet Launch offline ││ 7 Sparrow Wallet Launch offline ││ 8 KeePassXC Password manager │
│ │
│ PACKAGES │
│ 9 Package Builder Inheritance, multisig, proofs │
│ │
│ SYSTEM │
│ H System Health Check Air-gap, entropy, integrity ││ E Export to USB Reports + logs to a USB stick ││ L Shred Logs Securely wipe operational logs ││ S Settings Preferences and diagnostics ││ Q Quit / Lock Screen End session │
│ │
╰──────────────────────────────────────────────────────────────╯
1-4 workflow  ·  5-8 apps  ·  9 packages  ·  H E L S system

Five ideas that we built on.

Bitcoin Witness primary purpose is to be a verification layer for your self-custody stack. For such a system to be completely trustless, we believe all five principles below have to hold at once.

  1. No binaries. No firmware.
    All our code ships as plain-text scripts.

  2. General-purpose hardware.
    A Raspberry Pi you buy anywhere. Nothing that links you to Bitcoin.

  3. All our code is plain text.
    Bash and Python scripts you can read in place, or hand to an AI to validate.

  4. Only code you chose runs.
    Every line of ours that runs on the Pi is a plain-text script you can read in place.

  5. We invent no cryptography.
    Public Bitcoin and cryptographic standards only, verified against their standard test vectors.

Standalone Confidence Reports and signed packages for third parties

The Confidence Report is one of the main verification documents Bitcoin Witness produces. Everything is generated entirely on your air-gapped device, configured by plain-text scripts you can read in place, and running on hardware you bought. No accounts or internet connection required. The verification is between you and the math.

Read a Confidence Report field by field, and how to verify one →Why you may need one →

Backup Correctness

Checks your saved backup and derives every standard path’s addresses from it for verification. Supported formats are BIP39, Electrum, SeedXOR, Bitcoin Core, SLIP-39 and others. This one is a Shamir backup opened with a passphrase, so the sheet states that the passphrase is required and is in no backup we made. See full preview for details.

INHERITANCE PACKAGE, PRINTED

Lets you prepare a package for your heirs, attorneys and other third parties. The cover sheet below mentions what is enclosed, what to do first, and what it does not cover. Secret-free. See other report formats in full preview.

MULTISIG SETUP, CHECKED

Reads a 2-of-3 policy from the descriptor your wallet exported, here with the cosigner keys given as Zpub, then re-derives the addresses so you can confirm the quorum before you fund it. Native SegWit, sortedmulti (BIP67). See the multisig shapes in full preview.

SEED GENERATION, FROM DICE

Turns your own dice throws into a 24-word seed on the air-gapped box: 99 throws of a d6, estimated at 256 of 256 bits. The sheet states what it checked: the numbers you entered, not the fairness of your dice. See the generation workflow in full preview.

Date
2026-08-05 12:49:50 UTC
Version
v1.0 · Bitcoin mainnet
Air-gap
VERIFIED ✓
Master fingerprint
D08E74C0
Backup format
SLIP-39 Shamir backup
Seed length
256-bit (32 bytes)
Passphrase used
Yes — a SLIP-39 passphrase. The addresses need both the recovered master seed and that passphrase, and it is in no backup we made.
BIP84 receive #0
bc1qlkkw7k6emm65xv2qx5yfswrcs5skp4g8fkjwq4
BIP84 receive #1
bc1qp9a82w34ej5z2hu5laqx2mv9fqhn48hjhl4rj4
BIP44 receive #0
1JuddqexrWgLQ42Pyor9fiZwsBXCZS3h7U
Report SHA-256
b6403f6ddbb4…
Sample report · zero shares or secret material · safe to print or share · the SLIP-39 passphrase is in neither this report nor any backup we made, so these addresses cannot be re-derived without it

What the station does

Verify and Attest

Independently check the information any other software or hardware wallet had generated for you, on an airgapped and generic hardware of your choosing: address derivations, xpubs, descriptors, cosigners and more. Turn a technical check into a dated Confidence Report an auditor or attorney can rely on.

Guided, step-by-step verification of correct derivations of address, xpubs, descriptors, cosigners and other wallet information across modern and legacy standards.

Optional passphrase, the 25th word, and all 10 BIP39 languages are supported.

Proof of address control

Verify wallet descriptors and their privacy

PSBT privacy and security audit reports

Support for SLIP-39 shares, Seed XOR and Codex32 backup formats.

Key generation ceremony certificates

Support for Bitcoin Core generated wallets

Why verify across layers? →

Generate and Sign

Sign with included trusted and open-source software: Electrum or Sparrow. Every signature gets its deterministic nonce recomputed and audited independently from the software that signs. Generate new seeds of 12, 15, 18, 21 and 24 words, from dice or coin flips, in all 10 BIP39 supported languages.

New seeds from dice or coin flips. RNG is supported via Sparrow, Electrum or BIP39 tool

BIP85 child seeds derived on-device, in all 10 BIP39 languages

Traditional open-source Electrum, Sparrow and Ian Coleman tool is also included

Sign offline, single-key or multisig

Create and manage your own GPG keys, passwords and passphrases. On your machine, offline and airgapped.

Audit any PSBT for privacy and structural issues.

Audit produced signatures for Dark Skippy

See the full specification →

Prove and Inherit

Assemble secret-free packages for third parties, CPAs, Attorneys or auditors: a watch-only recovery set with plain-language instructions. Encrypt with GPG or LUKS if necessary.
Prove you control an address without moving coins.

The Inheritance package: the whole estate folder.

The Multisig Onboarding package: one handout per cosigner

The Verification package: the certificate and the reports it covers

The Proof-of-Control package: batch-sign a challenge with every address into one printable document a counterparty can check, proving control without proof of reserves.

Heir rehearsal mode: verify your instructions for any issues while you can still fix them

Nothing leaves the device with secret material in it: the builder refuses to package anything that looks like one

See the packages →

Keep it Safe

All three run on a machine with no route to a network. Any sensitive information is encrypted at rest with LUKS.

Air-gapped throughout: no interface up, no route out, re-checked before every workflow

Documents encrypted with GPG AES-256

LUKS at rest

Password databases managed offline in open-source KeePassXC

All sensitive operations are performed in RAM memory only and erased immediately after.

See our threat model →

Every script is plain text. No compiled binaries of ours. Read it before you run it. Built on Bitcoin tools that earned their reputation: Electrum, Sparrow Wallet, KeePassXC, Ian Coleman's BIP39 Tool and GPG, each independently auditable, each verified at install.

Independence is the point.

IN OUR SCOPE

  • Provenance: that a backup rebuilds the wallet it claims, re-derived on separate offline hardware
  • Control: that a key can sign for a named address today, with no coins moved
  • Wallet definition: the whole policy read back: quorum, every cosigner key, the descriptor checksum
  • Privacy: what a spend reveals, read out before a seed is ever asked for
  • Recoverability: that the threshold really opens it, proven rather than assumed
  • A document for each: dated, hash-anchored, secret-free, and readable by an heir or an auditor

OUTSIDE OF OUR SCOPE

  • Not a wallet: it holds no funds and never spends. Daily spending stays where it is
  • Not a sealed signer: a Raspberry Pi with no secure element, so it is auditable rather than tamper-proof
  • Not a coordinator: it does not host your multisig or keep your descriptor for you
  • Not a verdict on other devices: a cosigner signing on their own hardware is outside every check we do
  • Not a custodial nor a financial service: we provide the code. You verify offline.
  • Never networked: your hardware is never online, we ask for no account to run it.

Check it yourself, in about two minutes.

Our public companion tool is one open script, and it never asks for a seed. Give it a watch-only extended public key and it prints the addresses that key must produce. Then read them against any wallet you already trust.

Check it yourself, in about two minutes
xpubverify.py — BIP39 test vector 1 session
$ python3 xpubverify.py --receive-count 3 --change-count 1 \
    zpub6rFR7y4Q2AijBEqTUquhVz398htDFrtymD9xYYfG1m4wAcvPhXNfE3EfH1r1ADqtfSdVCToUG868RvUUkgDKf31mGDtKsAYz2oz2AGutZYs

  Receive addresses:
    #0    bc1qcr8te4kr609gcawutmrza0j4xv80jy8z306fyu
    #1    bc1qnjg0jd8228aq7egyzacy8cys3knf9xvrerkf9g
    #2    bc1qp59yckz4ae5c4efgw2s5wfyvrz0ala7rgvuz8z

The seed phrase is never entered, only the watch-only extended public key. Paste the same zpub into Sparrow, Electrum, or iancoleman.io/bip39 and the addresses will match. Full session output →

Read the derivation itself
xpubverify.py · simplified Python
import hashlib, hmac

def derive_child_pubkey(parent_pubkey: bytes, chain_code: bytes, index: int):
          """BIP32: derive a non-hardened child public key from a parent xpub."""
          data = parent_pubkey + index.to_bytes(4, "big")
          I = hmac.new(chain_code, data, hashlib.sha512).digest()
          IL, child_chain_code = I[:32], I[32:]
          # child_pubkey = (IL · G) + parent_pubkey  on secp256k1
          child_pubkey = secp256k1_point_add(parent_pubkey, point_mul_G(IL))
          return child_pubkey, child_chain_code
Read the source on GitHub → See how to verify every claim →

Walk through the workflows, start to finish.

A click-through of the main window, from the menu to a SHA-256 hash-anchored Confidence Report (GPG-signable with your own key, if you choose). No hardware or accounts are required for the demo.

✓ Bitcoin Witness v1.0raspberrypi · Pi 4   air-gap ✓
╭─ Bitcoin Witness ────────────────────────────────────────────╮
│ │
│ GUIDED WORKFLOWS │
│ 1 Verify Addresses, seed, backups, tx ││ 2 Generate New seed, BIP85, split shares ││ 3 Sign Transactions and messages ││ 4 Encrypt GPG documents for your heirs │
│ │
│ TOOLS │
│ 5 BIP39 Tool Offline HTML ││ 6 Electrum Wallet Launch offline ││ 7 Sparrow Wallet Launch offline ││ 8 KeePassXC Password manager │
│ │
│ PACKAGES │
│ 9 Package Builder Inheritance, multisig, proofs │
│ │
│ SYSTEM │
│ H System Health Check Air-gap, entropy, integrity ││ E Export to USB Reports + logs to a USB stick ││ L Shred Logs Securely wipe operational logs ││ S Settings Preferences and diagnostics ││ Q Quit / Lock Screen End session │
│ │
╰──────────────────────────────────────────────────────────────╯
1-4 workflow  ·  5-8 apps  ·  9 packages  ·  H E L S system

Open the product preview →

Compare to other self-custody layers →
SHIPPING Q1 2027

Get the Raspberry Pi
Air-Gap Security Checklist, free.

A practical guide to the checks every air-gapped device should pass. The same kind of verification Bitcoin Witness automates. Read it now without signing up →