UBIQS

A cold wallet with no seed phrase, for people and their AI agents

Self-custody almost never fails at the device. It fails at twenty-four words on a piece of paper. AI agents that move money cannot keep paper at all, so their keys end up hot. A cold wallet that removes the seed phrase has to remove the stored secret behind it too, and that is what makes it work for people and agents alike.

Share LinkedIn X Email

Hardware security for crypto has improved a great deal. Secure elements resist probing, firmware is signed, screens show what you are about to approve. And yet the most common way people lose self-custodied funds has nothing to do with any of that. The weak point sits outside the device, written down. Now a new kind of holder is arriving that cannot write anything down at all: software that spends money on its own.

The seed phrase is the whole key

Every conventional cold wallet ends in a seed phrase: twenty-four words that fully reconstruct the private key. The device can be flawless and the model still fails at the seed, because anyone who sees those words owns the funds.

  • Phished. A convincing support page or fake wallet update asks for the words, and the attacker never needs to touch the device.
  • Photographed or copied. A phone photo, a cloud note or an email draft turns an offline secret into an online one.
  • Coerced. A secret that a person knows or keeps nearby is a secret someone can be forced to hand over.
  • Lost. Paper burns, gets thrown away or outlives the only person who knew where it was. For long-term holdings and inheritance, loss is as final as theft.
  • Leaked at generation. If the words are ever exposed when they are created, every later safeguard protects a key that is already compromised.

What "seedless" usually means

The industry knows this, and several designs remove the phrase. Split-key wallets spread key shares across a phone, a provider's server and a backup. Passkey wallets tie the key to a cloud account. Social recovery hands pieces of trust to nominated guardians.

Each removes the twenty-four words. None removes the stored secret. Key material still exists somewhere, and recovery means trusting a provider, a cloud account or other people to behave. That is a reasonable trade for convenience. It is not the same thing as having nothing to steal.

Removing the phrase is easy. Removing the stored secret behind it is the real problem.

Agents can't keep a seed phrase

AI agents are starting to move money on their own: paying for APIs and compute by the call, settling stablecoin invoices, rebalancing positions, paying other agents. Every one of them needs a key, and none of them fits the model self-custody was built around. There is no person to write the words down and lock them away. So today an agent's key lives in one of two places, and both break in predictable ways.

  • A hot key next to the agent. The spending policy is software running beside the key, in the same place an attacker reaches first. A poisoned web page or a malicious tool output can talk the agent into a transfer, and nothing underneath the agent says no. One prompt injection away from an empty wallet.
  • A key held by a provider. The provider signs on the agent's behalf. The agent's funds are now only as safe as that provider's servers and policies, and every agent it serves sits in one place to attack.
  • Fleets make it worse. One agent is one key to protect. A thousand agents is a thousand keys, and seed phrases do not scale to that at all.

For a person, a seedless wallet is a convenience. For an agent, it is the only way to get a cold wallet at all.

A different starting point: the silicon

Our cold wallet is built on a silicon intrinsic root of trust, the same foundation behind identity you can't copy. The identity comes from physical variation in each chip, created when it was made. It is not written into memory and cannot be read out.

  • No seed phrase. There are no words to write down, photograph or hand over.
  • No key at rest. The key is derived only at the moment of signing and is gone afterwards. A stolen device holds nothing to extract, and physical attacks fail closed.
  • A clone cannot reproduce it. Copying the firmware or the enclosure does not copy the silicon that the key comes from.
  • Recovery without a new trusted party. Losing the device does not mean losing the funds, and getting them back does not depend on a provider, a cloud account or guardians holding a piece of your key. The details are shared under NDA.

Why it fits agents

The same properties that remove the seed phrase for a person are the ones an agent has been missing.

  • Cold custody for something that cannot hold paper. There is no phrase to store, so an agent gets a cold signer instead of a hot key by default.
  • A breached agent leaks nothing. There is no key on the agent's host and none at rest in the signer. An attacker who takes over the agent can only ask the signer, and the signer applies its own rules.
  • The rules sit below the agent. Spending limits and approved payees are enforced at the signer itself, below anything the agent can be talked into. A prompt can change what the agent asks for. It cannot change what the signer will sign.
  • Every payment traces to one device. Each signature traces back to one specific piece of silicon, so the agent's owner, an auditor or a counterparty can tell which signer authorized a payment, not just that some valid key did. That is the idea behind a signed receipt for every execution, applied to money.
  • Fleets without a key problem. Each signer's identity comes from its own silicon, so adding agents adds no seed phrases to generate, back up or lose.
The agent asks. The silicon decides.

What it does not do

Being precise about limits is what makes the rest credible. A cold wallet without a seed phrase does not stop you from approving a transaction you should not approve, and it does not fix a flawed smart contract on the other side. For an agent, it enforces the rules you set; it does not judge whether a payment inside those rules is a good idea. It is self-custody, not a custodian: the decisions stay yours. What it removes is the single stored secret that every other safeguard depends on.

Not a concept

The technology underneath is silicon hardened, patented, and backed and validated by the U.S. Army. The question for anyone holding assets that have to last, or handing an agent a budget, is simple: where does the secret live today, and who else could reach it?

Keep reading

Related

Holding assets, or handing an agent a budget?

We're talking with custody teams, agent-payment builders, wallet partners and investors who want self-custody with no seed phrase, no key at rest, and rules an agent can't talk its way past.