Satochip sells an NFC card whose vault is an open-source JavaCard applet (AGPLv3) in an NXP JCOP EAL6+. ISO 7816, GlobalPlatform, PIN, keys that never leave the silicon. Electrum, Sparrow, a PC reader or the phone’s NFC. This is not Coldcard, not Ledger, not Tangem. It is a smartcard.
The visual kinship with Tangem is the trap. Same rectangle, same NFC, no screen. The Satochip applet compiles and, on a dev card with known ISD keys, flashes. On locked production, the vendor installs. The seed is an imported BIP39 — plate or Seedkeeper — not a key born imprisoned. Satodime is another job (bearer, unseal).
The JavaCard OS and the NXP die stay closed. You audit the applet, not the chip. The phone is the screen. Satochip documents that a software HMAC in the applet has a cost against a bench. A few tens of euros, a multisig leg, travel, a refusal of Tangem’s closed ecosystem.
Fits if
Open-source NFC card, budget, a leg of a multisig, alternative to Tangem.
Keep in mind
No screen: the host is the display. JavaCard OS and silicon closed. Software HMAC = lab surface. BIP39 seed to back up elsewhere (steel or Seedkeeper).
Related incidents
- 2018– — Clones and marketplaces
The first security ritual is commercial: who sold you the object, and what does attestation say on first plug-in?