Prepare your
SeedSigner

Download it, check it, put it on the card.

Download the firmware, check it against SeedSigner's published hash, write it to a microSD.

Software comes only from SeedSigner's own GitHub checked locally in your browser this page loads nothing from any other server

Which one did you buy?

It is on your order. The smartcard one has a card slot.

Premium and Plus run stock SeedSigner. Plus Smartcard runs ShieldSigner, the Satochip fork.

1 Download the software

Your browser will show that it is downloading from github.com. That is how you can tell where it really came from.

One file gets saved to your computer, usually in your Downloads folder.

Download the software

Exact URL

Open the release page and compare the filename yourself.

Fetch and hash it without this page


    

Different board? Every official image is at github.com/SeedSigner/seedsigner/releases. This page only covers the Raspberry Pi Zero v1.3, which is what Bitsaga ships.

2 Check it is genuine

Drop the file you just downloaded here

Drop the image file here

It stays on your computer. Nothing is uploaded anywhere.

Read locally, hashed in this tab. Nothing is sent anywhere.

What this is compared against

Expected hash
Computed hash
not yet
Signed by
Fingerprint

Check the signer against sources Bitsaga does not control

    A match is not a safety certificate

    Matching means this is the file SeedSigner published, unaltered. It does not mean the software is free of bugs. An authentic, correctly signed release can still carry a serious one. Read what changed and what is currently broken before you rely on it.

    Release notes for this version · Open issues

    Do not trust Bitsaga's checkmark

    Check the signature yourself

    
    
        
    Has anyone rebuilt this from source?

    Rebuild it from source and get the same bytes

    
        

    SeedSigner's build is reproducible, so the hash above is not something you have to take anyone's word for. Anyone can derive it from the source. That is the strongest link in this whole chain, and it is the reason this page is a guide rather than an authority.

    Audit this page against its own signed manifest

    
      

    3 Put it on the card

    Use Raspberry Pi Imager. It is free, and it checks the card afterwards.

    Raspberry Pi Imager, custom image, verify-after-write on.

    Get Raspberry Pi Imager Grab it while the file downloads.

    1. Open the app.
    2. Device: scroll down, choose Raspberry Pi Zero. Not Zero 2 W.
    3. OS: scroll to the bottom, choose Use custom.
    4. Pick the exact file you just checked.
    5. Storage: choose your card.
    6. Write.
    Raspberry Pi Imager with Raspberry Pi Zero highlighted in the device list
    Pick Raspberry Pi Zero, not Zero 2 W
    Raspberry Pi Imager with Use custom highlighted at the bottom of the operating system list
    Choose Use custom, then pick the file you checked

    Write it without a GUI tool

    Raspberry Pi Imager is open source, Apache licensed, and worth recommending. It also reports usage to rpi-imager-stats.raspberrypi.com: the version, your operating system, CPU architecture and locale, plus which image you picked when it comes from their own repository. Choosing your own file is not that, but if you would rather run nothing extra at all, dd is already on your machine.

    
        

    Get the device wrong and you overwrite a disk with no confirmation and no undo. Check it twice.

    Or keep Imager and switch the telemetry off

    
    
        

    Verify the card, not just the file

    Writing can go wrong after a correct file. Imager verifies by default; confirm it did. On the smartcard firmware the device itself can verify a freshly written card under MicroSD Card Tools.

    
      

    4 Start it up

    Put the card in and plug in the power.

    Insert the card, power it. First boot takes roughly twenty seconds.

    The device does not check the software again when it starts, so it runs whatever is on the card and the check you did in step 2 is the only one there will ever be. Keep the card with the device.

    The device performs no signature check at boot, so it executes whatever the card holds and step 2 is the only verification in the chain. Keep the card with the device, and treat a card you did not write yourself as untrusted.

    Practise first

    Use a throwaway seed until this feels easy.

    Rehearse the full flow with a throwaway seed first.

    Practise in the simulator, in your browser, no hardware needed.

    Before you put real value behind it

    • Generate the seed with your own entropy, dice rather than the camera, and check the entropy indicator.
    • Confirm the xpub on a second, independent path before you accept any receive address.
    • Send a small test amount and spend it back before funding properly.
    • Inspect the hardware. Verified firmware says nothing about a tampered board.

    The honest ceiling

    Software cannot verify hardware. Reproducible builds push the boundary a long way but they do not remove it, and no page can prove itself. Everything here is designed so you can check it with tools you did not get from us. That is the most this can honestly offer.

    Want a hand?

    I do guided setup calls. We go through this together on a screenshare, then set up your seed properly.

    Book a setup call