A SeedSigner ships without software on purpose. This guide walks through the whole first hour: download and verify the image, flash the card, create a seed with dice, connect a wallet by QR code and sign a test transaction. No command line needed, about 45 minutes.
Why there is no card in the box. A signing device with a pre-installed image means trusting the seller. If you flash it yourself from the official repository, the chain of trust ends with you, not with us. The Dark Skippy attack from 2024 showed that malicious firmware can leak a seed through ordinary-looking signatures, which is exactly why this step is yours.
Go to github.com/SeedSigner/seedsigner/releases and open the newest release. Download three files: the image for the Pi Zero (the name contains pi0 and ends in .img.zip), the file with the SHA256 checksums, and its signature file (.asc).
Check the checksum. On Windows open PowerShell and run Get-FileHash .\seedsigner_os…img.zip; on macOS or Linux sha256sum seedsigner_os…img.zip. Compare the result with the line for your file in the checksum list. One wrong character means a corrupted or manipulated download.
Check the signature. The checksum list is signed with the SeedSigner project key. Import the key from the release notes or the project README into GPG once, then run gpg --verify seedsigner_os…sha256.asc. A good signature from the SeedSigner key means the checksum list itself is genuine. This is the step that protects you against a tampered GitHub download page.
If GPG is new to you: do the checksum today and the signature on a quiet evening. Both together are the full verification, the checksum alone already catches a broken download.
Unzip the image. Then write it to the card with Raspberry Pi Imager (choose “Use custom” and pick the .img file) or with balenaEtcher. Both are free, both run on Windows, macOS and Linux. Select the correct drive, writing takes one to two minutes.
Your computer may complain afterwards that the card is unreadable and offer to format it. Do not. The card now contains a Linux file system that Windows and macOS cannot display. Eject it and put it into the SeedSigner.
Connect USB power. The display stays dark for a moment, then shows the SeedSigner logo and after roughly 30 to 60 seconds the main menu. The first boot takes longest; later starts are faster.
Go to Tools → Camera and point the device at anything. If you see a live image, the camera is connected correctly. If the screen stays black, power off and check the ribbon cable; this is the most common assembly mistake with the kit.
In Settings you can set the language and, if you like, switch the display orientation. Leave the network settings alone; the device has no network, there is nothing to configure.
Choose Seeds → Create a seed → Dice rolls. The SeedSigner asks for 50 rolls for a 12-word seed or 99 rolls for 24 words. Roll a real die, enter each number, do not type a pattern you made up. The randomness comes from the dice, the device only turns it into words.
Then the device shows the words. Write them down by hand, in order, numbered. Read them back once. Paper is fine for today; a steel backup is the job for the coming week.
Optional: the SeedSigner can display the seed as a SeedQR. Draw or print that small QR code and you can reload the seed in two seconds by scanning it with the camera, instead of typing 24 words. Treat the SeedQR exactly like the words: whoever has it, has your coins.
The device forgets. A SeedSigner has no storage for your seed. Power off and it is gone. Every time you want to sign you load it again, from the words or from the SeedQR. That is the whole security model: nothing to steal from the hardware.
The wallet app watches your coins and builds transactions. The SeedSigner only signs. To connect the two, the wallet needs your extended public key (xpub), which lets it derive addresses but never spend.
With the seed loaded choose Export Xpub, pick single-signature and Native SegWit unless you have a reason not to, and select your wallet software from the list. The SeedSigner shows the xpub as a QR code.
In the wallet: Sparrow → File → New Wallet → Airgapped Hardware Wallet → SeedSigner → Scan QR. BlueWallet → Add Wallet → Import → Scan. Nunchuk → Add key → SeedSigner. Scan the code with the computer webcam or the phone camera, give the wallet a name, done.
Check one receive address on both sides: the wallet shows it, the SeedSigner can verify it under Address Explorer. If they match, the connection is right. Now send a small test amount to that address.
Build a transaction in the wallet, for example sending the test amount back to an exchange or to a second address of your own. The wallet shows the unsigned transaction (a PSBT) as an animated QR code.
On the SeedSigner, with the seed loaded: Scan. Hold the device so the camera sees the whole code; it collects the frames and shows the transaction: amount, destination address, fee. Read the address on the display, not on the computer. This is the moment the whole device exists for.
Confirm. The SeedSigner shows the signed transaction as a QR code; scan it back into the wallet, which broadcasts it. Then power off the SeedSigner. Seed gone, job done.
From here the routine is always the same: load seed, scan, check, sign, scan back, power off. After the third time it takes two minutes.
The checksum proves the file arrived intact. The signature proves the checksum list came from the SeedSigner developers. If someone could replace the download, they could replace the checksum list too; only the signature catches that. Do both, the signature once you are comfortable with GPG.
Yes. Choose Seeds → Load a seed → Type in words and enter the 12 or 24 words. Any BIP39 seed works, including one with a passphrase. Just be aware that typing a seed into a new device is the moment to be alone and unobserved.
After loading the seed you can add a BIP39 passphrase. It creates a completely different wallet from the same words, so the xpub export and every signature then use that combination. Forget the passphrase and the coins are gone, so write it down separately from the words.
Make the code larger on the screen, reduce screen brightness a little and hold the device 15 to 25 cm away without shaking. In Sparrow you can also lower the QR density under Preferences if the code has too many frames.
SeedSigner+, Rugged Pill and the DIY kit, printed and assembled in Germany, shipped across the EU. Without SD card, on purpose.