DRIVEKEY_Security / FAQ
DRIVEKEY / SYSTEM 01ROBINHOOD CHAIN / NATIVE ETH

Online to prepare.
Offline to sign.

A deliberate break between the internet and your private key. One computer. A bootable USB. Your approval.

Open transfer terminal
drivekey / live sessionBOOT DEMO
Your key stays on the offline side.
Illustration · this website is not running Linux
ETH TRANSFERSLOCAL KEY CREATIONEXACT SIGNATURE VERIFICATIONExplore the system
01 / THE MECHANISM

A small file crosses.
Your private key doesn’t.

There is a real reboot between preparation and approval. Each side has a specific job.

WINDOWS / ONLINE

Prepare

Set the recipient and amount. Save the unsigned request to USB.

unsigned-request.json
USB LINUX / OFFLINE

Review & sign

Boot from USB. Verify every detail, unlock locally, then shut down.

signed-response.json
WINDOWS / ONLINE

Verify & submit

Import the response. Check it against the original request and explicitly send.

transaction receipt
02 / CAPABILITIES

Fewer moving parts.
More deliberate control.

[01]

A vault you create offline.

Generate your wallet in the USB’s Linux environment. Encrypt it with a passphrase that stays out of the website.

> vault.create → encrypted file
[02]

One request. Exact details.

Recipient, amount, network and fee ceiling travel together. Review the same transaction again on the offline screen.

> request.freeze → review locally
[03]

Check the signature. Then send.

Back online, the dashboard verifies the response against your saved request. Sending needs its own confirmation.

> signature.verify → explicit submit
[04]

Files, not a closed ecosystem.

Use a compatible USB and keep a separate encrypted backup. Export public metadata without exposing the private key.

> public.export → backup.verify
03 / SECURITY MODEL

Know what
you’re trusting.

Separation is a workflow, not a guarantee. Here are the protections—and their boundaries.

security / checks

Private key excluded from web requests

Full transaction review before approval

Signed response matched to frozen request

Current nonce, balance and fee preflight

No automatic retry after an uncertain send

What does offline boot protect?

It separates signing from the running Windows session. Use a trusted PC and disconnect networking before boot. The website’s boot animation is only an illustration.

What does a USB not protect?

A normal USB has no secure element and its files can be copied or modified. DriveKey does not guarantee clean firmware or boot media. A VM is for functional tests, not isolation from a compromised host.

What happens if I lose the USB?

Recovery needs a separate encrypted backup and its passphrase. Test that backup offline. Reconnecting cannot recover a lost passphrase. Never reflash the only copy of a vault.

What does a signed file authorize?

Anyone holding it can broadcast that exact transaction. The application’s deadline does not revoke a signature on-chain. Check uncertain results before preparing another payment.

04 / GET SET UP

Bring a USB.
Keep your keys.

Already created your vault? Go straight to Offline transfer and load its public file.

01 / Offline system

The bootable image bundles Linux, the terminal signer, and its dependencies. No signing-time downloads.

Download bootable USB image

Public download · no login required. Experimental v5 r5 uses UTC only on the USB and website. Menu 9 accepts UTC time or ISO timestamps ending Z. Character logo and Solana shortcuts included. VM-tested; physical USB acceptance is still required. Use an empty USB—flashing erases its contents.

drivekey-offline-amd64-v5-experimental-r5.iso · 543.4 MiB (569,769,984 bytes)

SHA256 checksum93343439d432c55372cff7234637e8f009073aa084493ba7761b46d923aec9e9

Writing the image erases the selected drive. Never overwrite your only vault.

READY WHEN YOU ARE.Open transfer terminal drivekey@web:~$ prepare_