Foundation's avatar
Foundation
_@foundation.xyz
npub1s0vt...pq6j
We build Bitcoin-centric tools that empower you to reclaim your sovereignty, including Passport hardware wallet and Envoy app. Open source, USA assembled. Learn more at https://foundation.xyz
Foundation's avatar
Foundation 15 hours ago
Passport Prime is assembled in the USA! That matters because hardware security begins long before you switch a device on. Who assembled it? Who tested it? Who handled it before it reached you? The reason is practical, not patriotic. When you’re building a device people will trust with their keys, you should know exactly where it has been and who handled it before it reached them. With Passport Prime, we do. image
Foundation's avatar
Foundation 2 days ago
KeyOS v1.3.1 is now available for Passport Prime. This release adds last-word generation to creating your seed phrase. If you create your own seed using dice, coin flips, or words drawn from a container, you can now enter the first 11 or 23 words directly on Passport Prime. Passport Prime will generate a valid final word that satisfies the BIP39 checksum, no external tool required. The video in the blog post shows the feature in action. You can check your Passport Prime firmware version in the settings on your Passport Prime and initiate the download with Envoy. Read the full release notes in our blog post. As always, let us know if you have any questions. We’re happy to help. image
Foundation's avatar
Foundation 6 days ago
Many are reassessing their Bitcoin security. We understand why. Passport Prime is compatible with multisig coordinators including Sparrow, Nunchuk and unchained. Use it alongside hardware from other manufacturers. Choose your coordinator. Build the setup that works for you. Let us know if we can help along the way 🧡
Foundation's avatar
Foundation 6 days ago
Security claims are easy. Receipts are harder. We hand our hardware and code to independent experts whose job is to find where we were wrong, then publish the results. Both Passport Core and Passport Prime have undergone independent security audits by Keylabs. We publish the reports in full, including the findings and our responses. Passport Prime Keylabs audited the hardware and firmware, including secure boot, tamper response, wireless isolation, physical attacks, fault injection and key extraction. No critical or high-severity vulnerabilities were identified. The five low-impact findings were addressed and documented publicly. Audit: https://foundation.xyz/security/passport-prime-keylabs-audit-2025.pdf Our response: https://foundation.xyz/security/passport-prime-audit-response-2025.pdf Passport Core The pre-production review found issues in the boot process, firmware handling and downgrade protections. We fixed them, Keylabs sanity-checked the fixes, and we published the unmodified report. Audit: https://foundation.xyz/security/passport-core-keylabs-audit-2021.pdf Our response: https://foundation.xyz/security/passport-core-audit-response-2021.pdf Our ongoing bug bounty keeps the door open for researchers to report new vulnerabilities across Foundation products and services. All security resources: image
Foundation's avatar
Foundation 1 week ago
Thank you so much to those who have been submitting AI security reports to us over the last few days, especially Rob Hamilton. Since Thursday evening we have been engaged in internal code review and hardening. We have confirmed that seed generation in all Passport models is secure. By design, Passport models use at least 2 sources of entropy (randomness). Typically we don't post deeply technical updates, but given the events of the last few days, we will continue to post technical updates about our FOSS codebases. All Passport models include three sources of randomness: (1) Avalanche noise source (ANS), an open architecture true random number generator (no black box silicon) (2) MCU or MPU true random number generator (TRNG) depending on the model (3) Secure Element TRNG Passport Core uses all three sources when generating seeds. Multiple parties reported a scenario, which we also identified during our internal review on Thursday evening, where a theoretical ANS hardware failure would cause Passport Core to continue seed generation using the MCU and Secure Element TRNGs. (We are not aware of any ANS hardware failure in any Passport Core unit) Some AI models, specifically Kimi, are confused about this scenario and are falsely reporting that in the case of ANS hardware failure there is no additional entropy added. This is false. In this scenario, the Foundation team has confirmed that Passport Core still incorporates 2 sources of entropy during seed generation. Two sources provide more than sufficient entropy. But the better behavior is to instead refuse to generate the seed at all if the ANS fails. So we are hardening the code accordingly. Additionally, Passport Prime currently uses two sources of entropy for seed generation: ANS and MPU TRNG. We have confirmed that this seed generation path is secure. This is more than sufficient entropy but we are also adding in the Secure Element TRNG to the seed generation process. The Secure Element TRNG introduces some latency (it is slower) but we have always intended to use it as a third source of entropy for seed generation on Passport Prime. We have already made this code change internally. We will be releasing firmware updates in the coming days. All seeds generated on Passport hardware are safe. Please let us know what questions you have.
Foundation's avatar
Foundation 1 week ago
🚨 Phishing Alert 🚨 We’ve been made aware of phishing emails impersonating Foundation following the recent Coldcard security incident. These emails attempt to trick users into downloading malicious software or visiting fake websites. Please remember:
• Never download software from links in unsolicited emails.
• Never enter your seed phrase or any information into any website.
• Never trust messages claiming you need an “urgent security update.” If you’re ever unsure whether a message is legitimate, stop before taking any action. Contact us only through our official support email, Community Forum, or by sending us a DM on our official social accounts. Foundation will never DM you first, and we’ll never ask you to reveal your recovery phrase or install unknown software to “secure” your wallet. When in doubt, verify first. Taking a few extra minutes could save your Bitcoin. Email: hello@foundation.xyz Community Forum: community.foundation.xyz image
Foundation's avatar
Foundation 1 week ago
Post from our CEO, our CTO along with Zach and our devs spent the night going through every line of code for all Foundations products, we have access to GPT Cyber program too, we pointed it to everything. More posts to follow. Any questions please let us know. image
Foundation's avatar
Foundation 3 weeks ago
Most ambassador programs are affiliate links with a better name. Ours was too, so we rebuilt it. The new Foundation Ambassador Program includes more ways to earn through tasks, a ready-to-use content bank, exclusive merch and rewards, early product insights, and a private forum with direct access to our team. Referrals remain simple: earn $10 in Foundation store credit while the person using your code gets a free bumper case. Already an ambassador? Your account is waiting. New here? Join in less than a minute: image
Foundation's avatar
Foundation 3 weeks ago
KeyOS v1.3.0 is now available 🎉 This is one of our biggest KeyOS releases yet, with lots of new features. What's new: 🌱 Import external Bitcoin seeds into Vault 🟣 Import Nostr keys into Vault 🔐 Generate BIP85 passwords 📲 Mass-import 2FA codes from Google Authenticator 🔍 Scan almost any QR with the new Universal QR Scanner 📈 Scrub the Bitcoin price graph to view historical prices A huge thank you to our developers for all the work that went into this release, and to a third-party dev, immz4, for contributing to the Google Authenticator import feature. There are many more improvements and bug fixes across the Bitcoin wallet, 2FA, security keys, onboarding, Airlock, backups, USB, Bluetooth, and the wider KeyOS experience. Read the full release notes on our blog: image
Foundation's avatar
Foundation 2 months ago
Big tech apps are built to watch you. Passport Prime apps are built to protect you 💥
Foundation's avatar
Foundation 2 months ago
Bitcoin was the starting point. The principles behind it were always much bigger. Security. Verification. Sovereignty. Approvals. Now we’re bringing them to the AI era.
Foundation's avatar
Foundation 2 months ago
Today we announced a big milestone in Foundation’s history: • $6.4M funding led by Fulgur Ventures • Passport Prime is now generally available • The KeyOS developer platform is now open to developers We’ve spent the last few years thinking about a problem we believe becomes massive in the AI era: If AI agents can move money, access systems, deploy infrastructure, and operate accounts autonomously… Who actually authorizes the action? We don’t think browser prompts, cloud approvals, or software running on the same machine are enough anymore. That’s why we built Passport Prime: The first Human Authority Hardware device. Passport Prime combines: • Bitcoin self-custody • FIDO security keys • offline 2FA • encrypted vaults • 50GB encrypted storage …inside a dedicated handheld security device designed for trusted approvals and programmable security workflows. It runs KeyOS: Our open-source Rust microkernel operating system built specifically for programmable security hardware. Today, we’re also opening the KeyOS developer platform with: • SDK • simulator • CLI tooling • AI-assisted workflows You can get started here: Cake Wallet is already building on the platform, with more integrations on the way. We also launched a completely redesigned website today: image
Foundation's avatar
Foundation 2 months ago
🚨Phishing Alert 🚨 We've received reports of emails being received with a fake website.
 This is NOT from us and hosts a malicious Envoy desktop download. Do NOT click or download anything from it. There is no Envoy desktop version. image
Foundation's avatar
Foundation 3 months ago
Offline is the only security model that scales. Updates happen offline. Signing happens offline. Keys never leave the device. Just you and your keys.
Foundation's avatar
Foundation 3 months ago
Your money is online. Your memories are online. Your conversations are online. Your identity is online. So why are the passwords and security keys protecting those things online too? Somehow, we normalized that. That was a mistake.