Self-custody almost never fails at the device. It fails at twenty-four words on a piece of paper. AI agents that move money cannot keep paper at all, so their keys end up hot. A cold wallet that removes the seed phrase has to remove the stored secret behind it too, and that is what makes it work for people and agents alike.
Hardware security for crypto has improved a great deal. Secure elements resist probing, firmware is signed, screens show what you are about to approve. And yet the most common way people lose self-custodied funds has nothing to do with any of that. The weak point sits outside the device, written down. Now a new kind of holder is arriving that cannot write anything down at all: software that spends money on its own.
Every conventional cold wallet ends in a seed phrase: twenty-four words that fully reconstruct the private key. The device can be flawless and the model still fails at the seed, because anyone who sees those words owns the funds.
The industry knows this, and several designs remove the phrase. Split-key wallets spread key shares across a phone, a provider's server and a backup. Passkey wallets tie the key to a cloud account. Social recovery hands pieces of trust to nominated guardians.
Each removes the twenty-four words. None removes the stored secret. Key material still exists somewhere, and recovery means trusting a provider, a cloud account or other people to behave. That is a reasonable trade for convenience. It is not the same thing as having nothing to steal.
Removing the phrase is easy. Removing the stored secret behind it is the real problem.
AI agents are starting to move money on their own: paying for APIs and compute by the call, settling stablecoin invoices, rebalancing positions, paying other agents. Every one of them needs a key, and none of them fits the model self-custody was built around. There is no person to write the words down and lock them away. So today an agent's key lives in one of two places, and both break in predictable ways.
For a person, a seedless wallet is a convenience. For an agent, it is the only way to get a cold wallet at all.
Our cold wallet is built on a silicon intrinsic root of trust, the same foundation behind identity you can't copy. The identity comes from physical variation in each chip, created when it was made. It is not written into memory and cannot be read out.
The same properties that remove the seed phrase for a person are the ones an agent has been missing.
The agent asks. The silicon decides.
Being precise about limits is what makes the rest credible. A cold wallet without a seed phrase does not stop you from approving a transaction you should not approve, and it does not fix a flawed smart contract on the other side. For an agent, it enforces the rules you set; it does not judge whether a payment inside those rules is a good idea. It is self-custody, not a custodian: the decisions stay yours. What it removes is the single stored secret that every other safeguard depends on.
The technology underneath is silicon hardened, patented, and backed and validated by the U.S. Army. The question for anyone holding assets that have to last, or handing an agent a budget, is simple: where does the secret live today, and who else could reach it?
Certificates, API keys and tokens are data. Why the identity that holds under pressure is derived from physics.
Read →Every security solution operates above the execution layer. The layer beneath is the one they all assume.
Read →We're talking with custody teams, agent-payment builders, wallet partners and investors who want self-custody with no seed phrase, no key at rest, and rules an agent can't talk its way past.