PRE-LAUNCH / DEVELOPMENTIn development · No device orders or payments · Expected availability Q2–Q3 2027, an estimate subject to development and testing.

A DEDICATED SELF-CUSTODY HARDWARE WALLET

Control begins with a decision.

TUMBDA is a self-custody hardware wallet in development. The planned air-gapped device keeps signing on dedicated hardware while a companion app prepares and broadcasts transactions without receiving your private keys. Review each request before approving it on the device.

Dedicated hardware wallet. No exchange or trading services.

In development. No device is available to order yet. A free founder reservation can record your place in the founder queue before orders open. Expected availability: Q2–Q3 2027 — an estimate subject to development and testing.

TUMBDA hardware wallet product image.

01 / A FRAMEWORK FOR THE WORK AHEAD

Eleven dimensions. One clear purpose.

The Eleven Security Design Goals guide what we intend to evaluate as this hardware wallet develops. These are goals, not completed device features or independent security findings.

01 / FOUNDATION

Key generation

Plan how private keys could be created and protected from the start.

02 / SEPARATION

Key isolation

Explore keeping sensitive signing material apart from everyday computers and phones.

03 / ACCESS

Device access

Design intentional access controls that reflect the device’s actual threat model.

04 / CLARITY

Transaction review

Make destination, amount and fee information understandable before approval.

05 / INTENT

Physical confirmation

Study an explicit approval step at the device itself.

06 / CONTINUITY

Recovery

Develop clear backup and restoration guidance without implying that lost secrets can always be recovered.

07 / INTEGRITY

Firmware integrity

Evaluate ways to authenticate software running on the device.

08 / INTERFACE

Connection security

Define a careful boundary between the wallet and companion software.

09 / RESILIENCE

Tamper resistance

Assess physical risks and disclose realistic limits when the design is finalized.

10 / RESPECT

Privacy

Minimize unnecessary data exposure throughout the intended experience.

11 / EVIDENCE

Independent testing

Plan for external scrutiny and publish substantiated findings when available.

The eleven dimensions add an evaluation framework to the planned hardware-wallet project. Published plans are not evidence of completed production capabilities, certification or independent audit. Read the product disclosure ↗

THE PRODUCT DIRECTION / SUBJECT TO DEVELOPMENT

The intended wallet. In clearer detail.

TUMBDA is being planned around the same self-custody design direction: offline signing, user-controlled recovery and a companion app that prepares transactions without receiving private keys. The items below are intended features and design decisions to verify, not functioning or certified product specifications.

01 / OFFLINE SIGNING

Air-gapped by design

No USB data path, Bluetooth or Wi-Fi is planned for signing. The companion app prepares and broadcasts transactions; the device reviews and signs a payload without exporting private keys.

02 / KEY PROTECTION

Secure element and open firmware

The product plan calls for keys generated and sealed in a certified secure element, with published, reproducible firmware. Component certification and build verification must be documented for the finished device.

03 / NETWORKS

Multi-chain support

Bitcoin, Ethereum and major EVM networks are planned at launch, with additional networks through signed firmware updates. Final compatibility will be confirmed after implementation and testing.

04 / RECOVERY

Shamir backup

The intended recovery model uses Shamir-style shares kept in separate places, with a user-chosen threshold. Its final format and independent compatibility will be published before ordering.

05 / ACCESS

Decoy passphrase

A second passphrase is planned to open a separate wallet. The actual user experience and threat-model limits will be documented when the design is validated.

06 / PHYSICAL DESIGN

Tamper-evident construction

The design direction calls for a milled shell and sealed packaging so interference before first use is easier to notice. No physical design eliminates every tampering risk.

07 / PRIVACY

No unnecessary telemetry

The planned device has no telemetry channel; the intended companion app needs no login or cloud recovery. Final software behavior and data handling will be documented before release.

08 / USER CONTROL

Review on the device

Users are meant to inspect transaction details and approve signing on the device. The companion app should never receive a private key, while approval of a harmful request can still cause loss.

NO DEVICE TELEMETRY

The intended hardware has no analytics channel to report wallet activity.

NO TRACKING

The planned app does not require an account, identity check or linked address profile for its core operation.

NO CLOUD

Backup material stays with the user rather than in a project-operated cloud account.

These are planned device and app behaviors. The live website and any email request involve separate data handling described in Privacy.

Close-up product image showing TUMBDA engraved into the hardware wallet body.

02 / THE HARDWARE WALLET IDEA

Prepare elsewhere. Decide deliberately.

This is a general explanation of hardware-wallet signing, not a verified TUMBDA device specification or a setup guide.

01 — PREPARE

See the transaction.

A companion app can prepare a request showing the destination, amount, network and fees. It may be compromised, so these details still deserve careful checking.

02 — REVIEW

Check before approval.

A dedicated device may display details for you to compare with your intent. Inspect addresses, network, amount and any permissions requested.

03 — AUTHORIZE

Sign with intent.

In this planned model, signing occurs on the device and private keys are not shared with this website. An approval can still be harmful if the transaction itself is unsafe.

THE SIGNING BOUNDARY

Why dedicated hardware?

A software-only wallet may keep signing material on a connected phone or computer. The TUMBDA plan separates signing onto a dedicated device while the companion app prepares and broadcasts the request. Software wallets vary; neither arrangement makes a harmful approval safe.

Keys: planned to remain on the TUMBDA device instead of being handed to the companion app.

Review: the user should compare transaction details and explicitly approve on the device.

Recovery: intended split-share backup under user control, with final format and compatibility still to be verified.

A USEFUL CHECK

Pause before any approval.

When evaluating any self-custody transaction, compare the destination, network, amount and fees with what you intended. For a contract request, read the permissions and limits. A device cannot make a harmful request safe simply because you approve it there.

Read the risk disclosure ↗

THE PRODUCT BOUNDARY

What TUMBDA is — and what it is not.

Intended: a dedicated hardware wallet for self-custody signing, with the user in control of their own keys and decisions.

Not offered: an exchange or any service to buy, sell, exchange, swap or trade crypto assets. We do not hold customer funds or manage investments.

03 / THINKING THROUGH SELF-CUSTODY

Different people. The same careful questions.

These examples describe situations people consider when evaluating a hardware wallet. They do not claim that TUMBDA already supports a particular workflow or network.

01 / PERSONAL

Protecting a personal backup

Consider where recovery information would be kept, who could access it, and what would happen if the device or backup were lost.

02 / LONG TERM

Checking before an infrequent transfer

When you transact rarely, revisit addresses, network choices and permissions instead of relying on a familiar-looking app screen.

03 / TEAMS

Defining who can authorize

A DAO or business treasury needs defined approvals and recovery across contributors. The product plan includes threshold-based control; the finished workflow has not been tested or released.

04 / BUSINESS

Documenting reserve controls

A business can plan custody roles, review records and recovery responsibilities. TUMBDA intends to support deliberate authorization; final organizational features remain unverified.

Detail product image showing TUMBDA engraved into the hardware wallet body.

04 / REAL-WORLD LIMITS

Your backup matters. So does every approval.

A hardware wallet cannot guarantee that a destination is trustworthy, a contract approval is safe, or a transaction can be reversed. Losing or exposing recovery material can mean permanent loss or theft. Assets remain on their networks; they are not stored inside a device.

Understand the risks ↗

05 / DEVELOPMENT RECORD

Progress needs evidence.

TUMBDA is presently a hardware-wallet project in development. The stages below describe what should be disclosed as work progresses; they are not completed milestones, guaranteed specifications or a production schedule.

NOW / DEVELOPMENT

Define the questions.

The Eleven Security Design Goals frame decisions about key handling, transaction review, recovery and verification. No device is available for ordering or testing by users.

NEXT / DESIGN DECISIONS

Publish confirmed choices.

When design work supports it, publish actual architecture, compatibility and recovery details. Until then, no chip, connection method, open firmware or supported network is promised.

BEFORE ORDERS / EVIDENCE

Show what has been tested.

Share substantiated test results, independent findings if obtained, final specifications, pricing, delivery regions and terms before accepting orders. Plans can change as development continues.

Expected availability: Q2–Q3 2027. This is an estimate, not a commitment to ship, open orders or complete any specific feature by that time. Read the full pre-launch disclosure ↗ · Use the security evaluation worksheet ↗

06 / A PRACTICAL EVALUATION TOOL

Ask for evidence. Keep your own list.

Use these eleven questions when evaluating any hardware wallet, including a future TUMBDA product. Select the topics you want to investigate. This worksheet is educational; it does not grade security or confirm an TUMBDA feature.

Choose questions to investigate

Your review list

0 of 11 questions selected

Selections stay in this browser tab and disappear when you leave or reload. This site does not receive your worksheet or request wallet secrets.

07 / CLEAR ANSWERS

Before you go further.

What exactly is TUMBDA?

TUMBDA is a dedicated self-custody hardware wallet hardware-wallet project in development. Its intended purpose is to help users review and authorize transactions while keeping private-key signing on dedicated hardware. The eleven security dimensions describe design goals; final specifications and supported networks have not been confirmed.

Is TUMBDA an exchange or trading service?

No. TUMBDA is a hardware-wallet project in development. Neither this website nor the proposed device offers buying, selling, exchanging, swapping or trading crypto assets. We do not hold funds or manage investments.

Can I reserve a founder spot now?

Yes. You can request a free founder reservation for the planned first production run before orders open. Your reservation number records your place in the founder queue. No payment or deposit is required, and the reservation is not an order, guaranteed device allocation or guarantee of delivery. Expected availability is Q2–Q3 2027, an estimate subject to development and testing.

When will pricing and shipping be announced?

Founder pricing is planned for the first production run. Founder reservation holders will receive access to the founder offer when ordering opens. The actual price, eligibility, regions, order deadline and purchase terms will be published before payment is accepted. A reservation does not guarantee delivery. Q2–Q3 2027 is an estimated availability window, not a commitment.

Which networks and features are supported?

The product plan includes Bitcoin, Ethereum and major EVM networks at launch, air-gapped signing, an open-firmware direction and user-controlled recovery. These are planned capabilities, not verified support on a released device. Final compatibility and specifications will be published after implementation and testing.

Will TUMBDA ask for my recovery phrase?

No. This informational website has no wallet connection, account, key recovery, transaction signing or payment feature. Never email a recovery phrase, private key, PIN or password.

What if the TUMBDA project stops?

Self-custody requires a backup and a compatible recovery path that you control. We have not finalized or verified TUMBDA recovery formats or compatibility, so we cannot promise that another wallet will restore a future TUMBDA backup. We will disclose the actual recovery method before taking orders.

Will the firmware be open or independently tested?

Open, reproducible firmware and independent scrutiny are goals for the proposed wallet. No firmware release, reproducible build, audit or certification is confirmed yet. Results will be published only if and when they exist.

Where can I see development progress?

This site explains the current development direction and the disclosures expected before orders. You can request a free founder reservation and development updates through the founder-reservation section. We will add verified milestones here as they become available.

What if I lose my device?

Recovery depends on the wallet’s actual backup method. A secure compatible backup may help restore access, but no TUMBDA recovery method is finalized here. Loss or exposure of recovery material can cause irreversible harm.

08 / FOUNDER RESERVATIONS

Reserve your founder spot.

Request a free founder reservation for the planned first run of 5,000 devices. A reservation records your place in the founder queue and gives us a way to send development news and the founder offer when its terms are ready. No payment or deposit is required at this stage.

—founder reservations received

The count is loaded from founder reservations received by this site. It is a queue counter, not live stock and not a guarantee that a device will be delivered.

Your reservation number records your place in the founder queue. A reservation is not an order, payment, deposit, guaranteed device allocation or guarantee of delivery. Founder price, eligibility, regions and ordering terms will be published before payment is accepted.

If submission does not work, write to [email protected] with the subject “TUMBDA updates”. Email-app requests require manual processing before they appear in the reservation counter.

01 / FIRST RUN

Founder reservations

The working plan is an opening batch of 5,000 devices. A free founder reservation records a queue position before orders open; it is not a completed purchase or a guarantee that a unit will be delivered.

02 / FOUNDER OFFER

Founder pricing

Founder reservation holders will receive access to the founder offer when ordering opens. The actual founder price, eligibility, regions, order deadline and purchase terms will be published before payment is accepted.

03 / PREVIEWS

See the design progress

Signing and recovery previews are intended before hardware ships, once there is a real implementation to show.

04 / FINDINGS

Review the evidence

Independent test findings, if obtained, will be shared after finalization with their scope and limitations.

05 / ROADMAP

Share your priorities

Optional network interest can inform future compatibility decisions without promising support for a particular chain.