808bits
808bits. 101 bytes. The quiet infrastructure of trustless systems.
0b0000001100101000₂: four bits on, twelve off

signal

Mathematics doesn’t promise. A proof verifies or it doesn’t, and no amount of reputation, paperwork, or assurance changes which. Everything here starts from that indifference.

territory

Somewhere between the keys an institution holds and the proofs it can show, there is a quiet gap. Most of what actually matters in cryptographic systems (custody, recovery, continuity) lives in that gap. This is a place for taking it apart.

posture

No team page. No roadmap. No newsletter. Discretion isn’t secrecy; it’s sequencing. Things appear here when they can stand on their own.

log

Field notes on digital-asset custody, key management, MPC protocols, and recovery you can prove.

  1. 008 2026-09-01 FIPS 140-3 levels 1 to 4: what each level actually requires Level 1 is software, Level 3 is the HSM tier, Level 4 is empty: none of 773 FIPS 140-3 certificates as of September 2026. What each level actually requires.
  2. 007 2026-08-19 The ECDSA tax: a field guide to threshold signing Every MPC wallet pays a price set by one line of algebra. GG18/GG20, CGGMP, DKLs and FROST: who ships them, who audited what, which broke. Benchmarked.
  3. 006 2026-08-15 The key that never exists: a threshold signing ceremony in your browser interactive Three keyholders run a real 2-of-3 key generation and FROST signing session on this page, every message shown byte for byte. Zig to WebAssembly, no server.
  4. 005 2026-08-05 FIPS 140-3 is not a security guarantee, and auditors know it Validated modules shipped ROCA, EUCLEAK and a YubiKey flaw caused by FIPS self-tests. What the certificate attests, what FIPS mode costs, where auditors look.
  5. 004 2026-08-02 Coldcard's seed bug: the right RNG was in every binary, never called A five-year Coldcard firmware bug cut seed entropy from 128 bits to about 40. Why no audit could catch it afterwards, and what it means for anyone making keys.
  6. 003 2026-06-12 Fireblocks Recovery Utility: what verify mode actually checks I read the verify path in both Fireblocks recovery tools. What a Verified! line proves about your backup, and the three things it takes on trust.
  7. 002 2026-06-05 What a DORA reviewer wants in a custody exit plan DORA Article 28(8) wants a documented, tested exit plan for every critical ICT provider. For MPC custody the exit is signing capability, not data.
  8. 001 2026-05-29 A custody recovery drill that never exposes a key A recovery drill for MPC custody produces four numbers and a deviation log, and touches no private key. Most of what it finds is not cryptography.

tools

  1. t02 2026-09-01 TPM 2.0 playground interactive A real TPM 2.0 command interface in your browser: the Microsoft reference implementation compiled to WebAssembly. Send commands, read every annotated byte, seal a secret to a boot state and watch tampering destroy it. No server.
  2. t01 2026-08-20 Raw transaction decoder interactive Paste a raw transaction from Bitcoin, Ethereum, Solana, Cosmos, NEAR, Tron, TON, Cardano, Sui or Tezos and see every byte named: scripts disassembled, addresses derived, senders recovered from signatures. Zig compiled to WebAssembly, no server.

fips

5503 FIPS 140 certificates tracked from nightly NIST CMVP snapshots: status, sunset dates, and the list moves NIST never dates. 487 active FIPS 140-2 certificates sunset in 18 days.

  1. f00Certificate tracker interactivesearch all 5503 certificates
  2. f012026-09-21The FIPS 140-2 sunsetwhat moves to historical, and when