The Device Layer

Device Architecture Edition 8 4 min read by illithics

Is There Such a Thing as “The Perfect Wallet?”

No. But try, fail, and try again.

The argument in one sentence No one can remove trust from the equation — the perfect wallet is the one that shows you where its trust is derived: open silicon, open secure element, open software, open company.
A red laser beam striking a mound of sand, melting its peak into glowing molten glass against a black background.

If I were asked to build the perfect wallet today I would look at three specific things. What is it built out of: chips, elements, materials. How is it programmed: the firmware and the software. Finally, who built it, how do they behave, and what is their mission. Basically asking the wallet the classic Arnold Schwarzenegger line, “who is your daddy and what does he do?”

Those three questions would lead me down a tree that is fraught with ideology, technical limitations, economic trade-offs, and so many layers of trust. I think most could agree that the “Perfect Wallet” is not only a difficult thing to achieve, but perhaps a deeply personal one.

But let's give it a try. I'll build a hypothetical wallet out of known components and explain why I think it represents the best of what I want out of a wallet.

Start with the grains of sand. This year's DEF CON will showcase in their badge a long-awaited project by developer bunnie and baochip. The idea is to inspect your wafer, then build visibly on top of that.

The first test will come through this year's DEF CON badge. The trust layers I'm interested in are execution of firmware, screen control and transaction parsing — all attack surfaces that rely on the semiconductor manufacturer's specs. So let's start our hypothetical wallet here, with an MCU whose physical implementation can be examined instead of merely documented.

Now we are interested in cryptography and physical attacks. Traditional secure elements come from manufacturers like ST, Infineon, Microchip with proven track records. Say some dastardly or fortunate actor grabs my new wallet and I no longer have it in hand. The secure elements from these manufacturers provide varying levels of security from zips and zaps that try to break in and steal my private keys. These secure elements resist sophisticated attacks, but their internal design remains basically closed even to the owner of the device.

The philosophy of obscurity from the chip design is believed to add security. The manufacturer and its certification process become auditors of a component on my device that I cannot fully inspect. The evidence says that trusting these chips is often justified, but only as long as the game stays the same.

For this wallet, we'll try something different with a secure element from TROPIC. Recent external tests have shown it handles some punishment in the zip-zap department. The testing exposed weakness, but that is partly the point. In an open system, weaknesses become inspectable engineering problems rather than forever buried. The trust layer has not disappeared, but now it can be checked.

The next layer, auditable open source firmware and software, is almost universally accepted. The open source claims from current wallet makers live mostly at this level and they are legit. I will be 100 percent clear that I am not qualified to even speculate as to what would be the most secure choice here, but will simply say I will only pick one with fully open-source code and it's on me to learn.

The final layer I have focused on a lot in my previous articles but it is worth mentioning here again: the open source mission. A wallet company's mission should be auditable just like the code. I don't mean in a greenwashed CEO, or a finance bro's bravado — I mean have you had your company's history tracked and audited? What have you done about past problems? What's your security record as it stands today, and an honest assessment about how you are addressing it?

Open silicon, open secure element, open software, open company. Are we picking up a theme?

This is the radically open model. Auditable trust from chip to company. If anyone claims they can remove trust entirely from the equation I believe they are mistaken. If you put effort into demonstrating where your trust is derived, I'm back on board and listening.

Trust Ledger claims · sources · uncertainty

Claims checked

  • This year's DEF CON badge features the bunnie/baochip inspectable-silicon project.
  • TROPIC's secure element has undergone published external security testing, and weaknesses found were disclosed openly.

Primary sources

Commercial interests

  • The author's employer builds open-source wallets and could plausibly use the components praised here; no commercial relationship with baochip or TROPIC is asserted in the essay.

What is confirmed / what remains uncertain

  • Confirmed: the direction of the inspectable-silicon and open-secure-element projects described.
  • Uncertain: long-run security performance of the newer open components versus incumbent certified silicon — the essay argues the openness is the point, not a guarantee. The "hypothetical wallet" is a thought experiment, not a product.
Published: 2026-08-02 (provisional) Last reviewed: 2026-08-05 Corrections: none