Seedmate is designed with a strict air-gapped and stateless architecture to provide a highly secure environment for managing cryptographic seeds. But the users must be aware of the following risks:
1. Breaking the Air-Gap (Cameras & Smartphones)
Seedmate is a 100% offline device. However, taking a photograph of the device screen (words or QR codes) with a smartphone instantly compromises the seed. Smartphones routinely sync photos to cloud backups (iCloud, Google Photos) and grant gallery access to third-party apps. Users are strictly instructed never to photograph, scan with an online device, or type their seed into a computer or mobile keyboard.
2. SD Physical access
If you choose to export and keep your seed to the SD card, it will NOT be cryptographically encrypted. A basic obfuscation is used solely to prevent accidental plain-text reads by common operating systems (Windows/macOS).
However, a tech-savvy attacker with physical access to the SD card could use a hex editor, de-obfuscate and extract the base seed. The physical SD card must be treated with the exact same security as a paper/metal backup.
Never store the MicroSD card and the Seedmate device together. An unformatted SD card stored on its own looks like a corrupted or broken drive. However, an SD card stored next to a Seedmate device immediately gives an attacker the context they need to realize it holds raw cryptographic data. Do not label the SD card with clues about its contents.
3. "Erased" Does Not Mean Destroyed (SD Card Memory)
Due to how modern SD cards physically manage memory, it is impossible for Seedmate to guarantee the physical destruction of your data when you "erase" or overwrite the card.
But don't panic, an erased seed cannot be recovered by simply plugging the card into a computer, not even with the most advanced software available. It would require the use of advanced laboratory techniques, a process called off-chip recovery. An attacker would have to make a significant upfront investment to hire services from a professional data recovery company, which would only make sense if they know what is inside. Therefore, avoid labeling the card and always keep it separate from the device.
Of course, if you want to make sure no one will ever access the residual SD seed, just physically destroy it with a drill or scissors.
If you ever lose your seed copies but still have the wiped SD card, you could potentially use these professional off-chip recovery procedures yourself to try to retrieve it, but with no guarantees.
4. Custom Cryptography & HTML Recovery Tool Risks
Seedmate offers custom obfuscation and Shamir's Secret Sharing (SSS) implementations that are not compatible with other industry standard hardware wallets (such as SLIP-39). If the physical Seedmate device is lost or destroyed, these specific shares or obfuscated data cannot be imported directly into third-party devices.
To mitigate this, an open-source HTML recovery tool is provided as a last resort. This file is published on github and should always be online. But if you choose to use Shamir/Obfuscation you should consider the following steps:
- Download the open-source HTML recovery tool today. Keep a digital copy on a standard USB drive, PC and/or cloud service provider, just in case GitHub is ever offline in the future.
- Practice the recovery steps in advance with a dummy seed: download the HTML file, transfer it via USB, and execute it on a secure, permanently offline computer or a live amnesic operating system (such as Tails OS).
5. Physical Tampering & ICSP (Evil Maid/Supply Chain Attacks)
Seedmate is completely stateless and stores no secrets in its internal non-volatile memory (Flash). However, the ICSP programming pins remain accessible under the case to allow users to verify and update the open-source firmware. Because of this, an attacker with physical access to the device could flash a malicious firmware. Given the small size of the project this risk is close to zero at this moment. I plan to implement SD firmware updates and firmware verification processes in the future.