A vault you create offline.
Generate your wallet in the USB’s Linux environment. Encrypt it with a passphrase that stays out of the website.
> vault.create → encrypted fileA deliberate break between the internet and your private key. One computer. A bootable USB. Your approval.
Open transfer terminal░░░░░░░░░░░░░░░░░░░░░ ░█████▓▓▓▓▓▒▒▒▒▒▒▒▒▒▒▓▓▓▒░░ ░░░░░░░░░░░░░░░░░ ░░░░░░░ ░░░░░░░ ░░░░░░░ ░░░░░░░░░░░░░░░░░░░░░░░ ░░░░░░ ░░░░░░░░ ░░░░░░░░░░░░░░░░░░░░░░░ ░░░░░░ ░░░░░░ ▒███▓▓▓▒▒▒▒▒▒░░░░░░░░░░▓█▓▒░ ███████████████████▄▄ ░██████▒ ▓██████ ▒██████▀ ░██████████████████████▓ ▒██████ ░▓███████▀ ░██████████████████████▓ ▓██████ ▄██████▀ ▓█▓▓▓▓▒▒▒▒▒░░░░░░░░░░░░░░▓█▒ ▒█████████████████████▓ ▓██████░ ▒██████░ ▒██████░ ▓██████████████████████▒ ▓█████▓ ▄███████▀ ▓██████████████████████░ ▒██████▒ ▄██████░ ░▓▓▓▓▒▒▒▒▒▒░░░░░░░░░░░ ░ ▓▒ ▓██████████████████████▒ ██████▓ ░██████▒ ▒██████░ ██████████████████████▓ ▒██████░ ▄███████▀ ██████████████████████▓ ▓█████▓ ░▓█████▓ ▄▒ ░▒▓░░░ ░▓ ░██████░ ▒██████▓ ▒██████░ ▓█████▒ ▒█████▓░ ▒█████▓ ▓█████▓ ░▓██████▀░ ▒█████▓ ░██████░ ░▓█████▀ ██▄ ▓▓░░ ▒▒ ▓█▓▓▓█▓ ▓▓▓▓▓█▒ ▓█▓▓▓█▓ ▒█▓▓▓█▓ ▒█▓▓▓█▓ ▓█▓▓▓█▒ ░▓▓▓▓▓█░ ░▒█▓▓▓▓█▀░ ▓█▓▓▓█▒ ▒█▓▓▓█▓ ▒█▓▓▓█▓░ ▒█▓▓▓ ░▄▓██▓░ ▒▒ ░ ▓░ ░▓▓▓▓▓▓░ ▒▓▓▓▓▓▓░ ░▓▓▓▓▓▓▒ ▒▓▓▓▓▓▓ ▒▓▓▓▓▓▓ ░▓▓▓▓▓▓░ ▒▓▓▓▓▓▓ ▄▓▓▓▓▓▓▓░ ░▓▓▓▓▓▓░ ░▓▓▓▓▓▓░ ▓▓▓▓▓▓▒ ▓▓▓▓▒ ░▓█████▒ ▓▒ ░▓ ▒▓▓▓▓▓▓ ░▒▓▓▓▓▓▓▒ ▒▓▓▓▓▓▓ ░▓▓▓▓▓▓░ ▒▓▓▓▓▓▒ ▒▓▓▓▓▓▓ ░░░░░░░░░░░░ ▓▓▓▓▓▓▒ ░▓▓▓▓▓▓▓░ ▒▓▓▓▓▓▒ ░░░░░░░░░░░░ ▒▓▓▓▓▓▒░▓▓▓▓▓▓░ ░▓▓▒▓▒ ░▓███▓▀ ░▓░ ▒▒ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓░ ░▓▓▓▓▓▓▒ ▓▓▓▓▓▓▒ ▒▓▓▓▓▓▒ ░▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓░ ▒▓▓▓▓▓▓░▒▓▓▓▓▓▓▓▒ ░▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓░ ▓▓▓▓▓▓▓▓▓▓▓▒ ▓▓▒▒▒░ ▒███░ ▒▒ ░▓ ░▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▀ ▒▓▓▓▓▓▓░ ▒▓▓▓▓▓▒ ▓▓▓▓▓▓▒ ▒▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▒ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▒ ▒▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▒ ▒▓▓▓▓▓▓▓▓▓░ ░▓▒▒▒▒ ▒██▓▓▒ ▓░ ▒▒ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▒▀░ ▓▓▓▓▓▓▒ ▒▓▓▓▓▓▓ ░▓▓▓▓▓▓░ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓░ ░▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓░ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓░ ▓▓▓▓▓▓▓▓░ ▒▒░░░░ ▒▓▓▓▒▒▒ ▒▒ ▓░ ░▓▓▓▓▓▓░ ░▓▓▓▓▓▓▓░ ▒▓▓▓▓▓▓░ ░▓▓▓▓▓▓░▓▓▓▓▓▓░ ▒▓▓▓▓▓▓ ▒▓▓▓▓▓▓▓▓▓▀ ▒▓▓▓▓▓▓▓ ▒▓▓▓▓▓▓ ▒▓▓▓▓▓▓ ░▒▒░░░ ░▒▒ ░▒ ▒▓▓▓▓▓▓ ▒▓▓▓▓▓▓▓ ▓▓▓▓▓▓▓ ▓▓▓▓▓▓▓▓▓▓▓▓░ ▓▓▓▓▓▓▒ ░▓▓▓▓▓▓▓▓▀ ▓▓▓▓▓▓▓▓ ▓▓▓▓▓▓▒ ░▓▓▓▓▓▓░ ▒▒░░░░ ░░░░░░░░░▄▓▀░ ▒░ ░▓▓▓▓▓█░ ▓▓▓▓▓▓█▒ ░█▓▓▓▓█▒ ▓█▓▓▓▓▓▓▓▓▓░ ░▓▓▓▓▓▓░ ▒█▓▓▓▓▓▒░ ░▓▓▓▓▓▓█▒ ░█▓▓▓▓▓░ ▒█▓▓▓▓▓ ▒░░░░░░░░░░░░░░░░░░░ ░ ▒▒ ▒█▓█▓█▓ ░█▓▓██▓█▒ ▓█▓█▓█▓ ▒█▓████▓█▓░ ▓█▓█▓█▓░░░░░░░░░░░░░░░░ ▓█▓█▓█▒ ▒█▓██▓██░ ▓█▓█▓█▓░░░░░░░░░░░░░░░░ ▓█▓█▓█▒ ░▒░░░░░░░░░░░░░░░░░░░░░░░▄▓▒ ▓█████▒ ▒███████░ ░██████▒ ░███████▓ ░██████████████████████▓ ▒█████▓ ▓██████▓ ░██████████████████████▓ ▒█████▓░ ▒░░░░░░░░░░░░░░░░░░░▒▒▒▓▓▀░ ▒██████ ▓██████▓ ▒██████░ ▓█████▓ ▒██████████████████████░ ▓█████▒ ▓██████▓ ▒██████████████████████░ ▓█████▓ ░▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▓▓▀░░ ▓▓▓▓▓▓▒ ░▓▓▓▓▓▓▓▒ ▓▓▓▓▓▓▒ ▓▓▓▓▓▓ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓ ░▓▓▓▓▓▓░ ░▓▓▓▓▓▓▓▒ ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓ ░▓▓▓▓▓▓░
There is a real reboot between preparation and approval. Each side has a specific job.
Set the recipient and amount. Save the unsigned request to USB.
unsigned-request.jsonBoot from USB. Verify every detail, unlock locally, then shut down.
signed-response.jsonImport the response. Check it against the original request and explicitly send.
transaction receiptGenerate your wallet in the USB’s Linux environment. Encrypt it with a passphrase that stays out of the website.
> vault.create → encrypted fileRecipient, amount, network and fee ceiling travel together. Review the same transaction again on the offline screen.
> request.freeze → review locallyBack online, the dashboard verifies the response against your saved request. Sending needs its own confirmation.
> signature.verify → explicit submitUse a compatible USB and keep a separate encrypted backup. Export public metadata without exposing the private key.
> public.export → backup.verifySeparation is a workflow, not a guarantee. Here are the protections—and their boundaries.
Private key excluded from web requests
Full transaction review before approval
Signed response matched to frozen request
Current nonce, balance and fee preflight
No automatic retry after an uncertain send
It separates signing from the running Windows session. Use a trusted PC and disconnect networking before boot. The website’s boot animation is only an illustration.
A normal USB has no secure element and its files can be copied or modified. DriveKey does not guarantee clean firmware or boot media. A VM is for functional tests, not isolation from a compromised host.
Recovery needs a separate encrypted backup and its passphrase. Test that backup offline. Reconnecting cannot recover a lost passphrase. Never reflash the only copy of a vault.
Anyone holding it can broadcast that exact transaction. The application’s deadline does not revoke a signature on-chain. Check uncertain results before preparing another payment.
Already created your vault? Go straight to Offline transfer and load its public file.
The bootable image bundles Linux, the terminal signer, and its dependencies. No signing-time downloads.
Public download · no login required. Experimental v5 r5 uses UTC only on the USB and website. Menu 9 accepts UTC time or ISO timestamps ending Z. Character logo and Solana shortcuts included. VM-tested; physical USB acceptance is still required. Use an empty USB—flashing erases its contents.
drivekey-offline-amd64-v5-experimental-r5.iso · 543.4 MiB (569,769,984 bytes)
93343439d432c55372cff7234637e8f009073aa084493ba7761b46d923aec9e9Writing the image erases the selected drive. Never overwrite your only vault.
Create and verify your vault offline. Keep a separate encrypted backup before using real funds.
Step-by-step SetupCreate a vault, verify your backup and learn your first transfer →
drivekey@web:~$ prepare_