Project Update
September 2026
Where the build stands, why we moved the date, and what ships in Batch 1 at the end of October.
Public edition v1.0 · 11 September 2026
Citadel Vault units running Vault OS
Distributed Security. 1000-Year Durability.
Citadel Vault is the inheritance computer. It keeps everything your family needs to recover your Bitcoin, and releases it only on your terms.
A heavy summer on the engineering side
Completed
- Independent penetration test and security audit across hardware, Vault OS and the Guardian application
- Audit fixes landed for the timelock, key memory, backup media, factory reset and the USB air gap
- Vault inheritance computers in stock at our Canada, Europe and United States hubs
- Expansion boards for every tier: final production run complete, in stock
- Archival disc drive supply secured, with spare inventory held
- Air-gapped timelock verification hardened
In progress
- Multi-source entropy, with your own dice rolls or keypress timing
- A simpler login across Vault OS and Guardian
- Change your Vault Master Passphrase without re-encrypting the vault
- The Emergency Vault Restoration Kit
- Final foam layout for the vault case
- Secure firmware updates on removable media
- Production and provisioning procedures
From today to Batch 1, week by week
A product with this job does not get to be early.
It gets to be right.
Every layer tested. The critical finding closed first.
Timelock Closed
Stricter proof checks on the Bitcoin block headers that enforce your waiting period.
ⓘ DetailsThe timelock trusted the difficulty written inside a block header, so a forged header could claim the waiting period was over.
Headers must now meet a real network difficulty floor and link back to built-in checkpoints with cumulative proof of work.
Key memory Closed
Keys locked in memory, never written to swap, wiped after use.
ⓘ DetailsIf the system refused to lock a key in memory, the vault carried on anyway, and the recovery laptop path had no swap protection.
A refused memory lock now stops the session, and the recovery path pins keys in memory and turns swap off.
Backup media Closed
Everything written to backup media is encrypted. Nothing is left in the clear.
ⓘ DetailsLegal documents and printed QR cards were copied onto backup media without encryption.
Both are now sealed inside the encrypted bundle before anything is written to the disc or drive.
Factory reset Closed
A reset now erases everything it should, not just part of it.
ⓘ DetailsReset deleted only some files, and simply deleted files can be recovered from flash storage.
Reset now overwrites and then removes the full list of sensitive files, including keys and documents.
USB air gap Closed
No USB device can open a network path into the vault.
ⓘ DetailsA USB device that pretended to be a network adapter was allowed to stay connected.
Every network interface except the internal loopback is shut down, USB ones included, and checked after.
Metadata Closed
Less information visible on the drive to anyone who finds it.
ⓘ DetailsThe document index kept titles and heir names in the clear, and compressed secrets hinted at their size.
The index now lives inside the encrypted vault index, and secret size no longer shows through compression.
Card wipe Closed
Wiping a Vault Card clears all of it, and proves it.
ⓘ DetailsWiping a card cleared only the first block of its share, yet reported the card as erased.
The wipe now clears the whole share area, then reads it back to confirm it is empty.
Boot chain Scheduled
Operating system hardening and verified boot, in the Vault OS pass.
ⓘ DetailsThe operating system image has no boot time integrity check, so an offline change to it would go unnoticed.
Signed, verified boot and the full hardening profile, delivered in the Vault OS hardening pass.
"The cryptographic core is genuinely strong."
Audit summary. Remaining items, including card share verification, import size limits and verified boot, are scheduled into upcoming releases.
Rebuilding the foundation
The audit found a strong core. We chose to go further: rebuild how keys live inside the vault, so that safe handling is enforced by the structure of the code rather than by care and convention.
Seven layers of protection
Six milestones
Five sources in. Two 256-bit keys out.
You can import your own Vault Master Passphrase instead, if you know how to guarantee proper entropy.
- Hashed, never XORed. One weak source cannot cancel out a strong one.
- Conservatively credited. With dice, around 898 bits of assessed randomness go in, far above the 320 bits a full-strength 256-bit key requires.
- Your input adds, never replaces. The device and Vault Card randomness is always in the mix.
- Committed before you add yours. The vault records a verification code first, so neither side can steer the result.
- Checked. Statistical tests on dice rolls catch a stuck or loaded die.
- A missing source stops setup. It is never quietly replaced by a fixed value. That exact shortcut is what went wrong in July.
About twenty minutes, in one sitting
The vault walks you through every step. It checks your work as you go and never lets you leave in a half-finished state.
What you will see on the vault
This Vault is your family's Inheritance computer. This one-time setup creates your Vault Master Passphrase and your Vault Cards.
About 20 minutes, in one sitting. Three steps:
1 Add randomness: cards and dice
2 Write 24 words on paper
3 Prove the words, then the cards
HAVE THESE ON THE TABLE
Your Vault Drive and 3 main Vault Cards
1 die, a pen, 2 sheets of paper
Screen 0. Everything the sitting needs, listed before it starts. Backup cards stay in the box.
RIGHT SIDE
Power USB-C, from the wall charger
Vault Drive USB-A
Card reader USB-C
Screen 1. Every connection is detected live, so the screen answers itself.
> 2 OF 3 MAIN CARDS
Any 2 cards open the vault. You can lose 1 and still get in. Fewer cards to manage.
3 OF 5 MAIN CARDS
Any 3 cards open the vault. You can lose 2 and still get in.
Screen 2. Vault Core uses 2 of 3 and skips this screen. Vault Pro and Pro+ may choose 3 of 5.
Your cards, then the vault, then your dice
Place each main Vault Card in the reader when asked. Nothing is written to the cards yet.
Each card's certified chip adds its own randomness. No source ever sees another source's output.
Screen 3. The secure element in every main card contributes randomness before anything else happens.
The vault has locked in its own randomness, and your cards', before you add yours.
VERIFICATION CODE
7F3A 91C2 0B4E D86A
Saved to the setup log automatically. Copy it only if you want to audit later.
Now the vault cannot change its mind after seeing your dice.
Screen 4. The commitment is what stops a tampered device steering the result.
Roll the die and type the number you see.
Enter each roll exactly once, in order. If you mistype, use Backspace. Do not roll again.
Last roll: 4
Screen 5. 100 rolls minimum. Keypress timing is the alternative. Roll checks run next, automatically.
Write it down, then prove you did
These are NOT a Bitcoin seedphrase.
Never type them into a website, wallet, phone, or other computer. Do not photograph them. Enter them only on this Citadel Vault, and only when it asks.
They will not be shown again after setup.
Screen 7. The warning comes first, every time.
Write all 24 words on the paper in front of you, in this order. Metal comes later.
You can continue in 0:23
Screen 7, continued. Your 24 words appear here. Continue unlocks after 30 seconds.
Type each word from your paper, not from memory.
BIP39 word list · page 1 of 4, words 1 to 6
Word 4: abst▌
Screen 8. The BIP39 word list scrolls to your letters and highlights the match. Accepted words hide again; all 24 are checked.
Every card written, every card proved
Number your cards 1 to 3 with the supplied pen before the first card.
Keep the Vault on mains power until all 3 are written. There is no Back button on this screen.
2 of 3 written
Screen 9. Each main card receives its share of the vault key.
Test 1 passed: cards 1 and 2
Now place card 1, then card 3.
Two tests, so that every card is proved to open the vault, not just two of them.
Screen 10. Every card is proved before setup is allowed to finish.
Vault Card verification PASSED
Creating your vault…
Any 2 of your 3 main Vault Cards open this vault. Never keep 2 or more in one place.
Check your metal copy against the paper before you destroy the paper.
Screen 11. The vault is created only after every card has passed.
Built for the vault, in stock for every tier
Vault Pro expansion
Rev A- USB-C power in, plus USB-A and USB-C ports
- A powered port that drives the archival disc drive at full current
- For Vault Pro, Pro+, Advisor and the Founders Edition
Vault Core expansion
Rev A- One USB-A and one USB-C port, nothing more
- Unused connectors are left as bare pads, not fitted
- Every board carries a laser-etched serial, e.g. CVX-PA-2628-747689
A rugged case, cut to fit everything
Three layers of custom foam, 142 mm of stack inside a 163 mm deep hard case. Every part has its own pocket, and finger pulls lift each layer out.
What is hard right now, and how we are handling it
Release integrity
Every shipping build is made on a hardened, controlled host and signed. Standing that pipeline up is the first link on our critical path this month.
The signing key ceremony
The key that signs Vault OS is created offline, split and backed up in a formal ceremony, scheduled for the week of 14 September.
Proof on the device
Passing tests on development machines is not enough. Every release is proved again on Vault OS itself before it ships.
Vault Card format
We are finalizing the data format written to each Vault Card, 15 to 29 September, so the ceremony writes cards once and for good.
Component supply
Some parts come from a single source. We hold stock at three hubs and keep spares of the parts that are hardest to replace.
What we will not do
Ship before it is right. If a date has to move again, you will hear it from us with the reason, as you did in August.
The questions we expect, then yours
citadelvault.org/updates