FORTRESS KEY

Dice-Roll BIP39 Seed Generator & Verifier. Open Source. Offline. Auditable.
100% OFFLINE
CURE53 AUDITED CRYPTO
COLDCARD COMPATIBLE
For maximum security, download and use offline:
HTML version: Works everywhere (Mac, PC, Linux, phone). Download, disconnect, open in browser.
DESKTOP APP — Rust Crypto + Secure Memory Zeroing
macOS (Apple Silicon) macOS (Intel) Windows (.exe) Windows (.msi) Linux (.AppImage) Linux (.deb)
Desktop app uses Rust cryptography with secure memory zeroing. Private keys are wiped from RAM after use.

Generate BIP39 Seed from Dice Rolls

Roll a physical die and enter each result. Your entropy comes from physics, not software.
99 rolls → 24 words (256 bits)  |  50 rolls → 12 words (128 bits)
Cross-verifiable with Coldcard. Same rolls = same seed, always.

Rolls: 0 / 99 Entropy: 0 bits
No rolls yet. Roll your die and click the matching face above.

Verify BIP39 Seed Phrase

Enter your 12 or 24 word seed phrase to verify it's valid before trusting your backup.
Detects invalid words, checksum errors, and suggests corrections.

BIP39 Passphrase Manager (Word 25)

A passphrase creates a completely different wallet from the same seed phrase.
Seed in steel at home + passphrase in your head = neither alone opens anything.

How It Works
🔑
Seed (24 words)
Stamped on metal, stored at home. Physical security.
+
Passphrase
Lives in your head. Crosses borders. No evidence.
🔒
= Unique Wallet
Different passphrase = different wallet entirely.
Plausible Deniability
No passphrase → Decoy wallet with small balance
Simple passphrase → Another decoy, slightly more
Real passphrase → Main wallet with real funds

Under duress, you reveal the seed + a decoy passphrase. There is no way to prove other passphrases exist. Every passphrase produces a valid wallet.
Case-sensitive. Spaces count. An incorrect passphrase opens a different (empty) wallet — there is no "wrong passphrase" error.

Select your hardware wallet:

1
Memory
2
Invented
3
Numbers
4
Dice
5
Secret
R
Review

Step 1: A Memory Only You Lived

Think of a specific moment from your life involving your senses: what you saw, smelled, tasted, heard, or felt. Nobody else on Earth can guess this.

Why: Episodic memories are stored differently in your brain than facts. They're vivid, emotional, and nearly impossible to forget.
Good: "Abuela Rosa's kitchen smelled like burnt garlic every Sunday at 11am"
Good: "The hospital room was freezing when my daughter was born at 3:42am"
Bad: "I love my family" (too vague) • "My birthday is June 15" (public info)
0 chars
Enter your memory

Step 2: Words You Invented

Create 2+ words that do NOT exist in any language or dictionary. Sounds that mean something only to you.

Why: BIP39 uses 2,048 known words. Attackers can brute-force known wordlists. Your invented words exist in NO wordlist — the search space is infinite.
Techniques: Mash syllables ("churplex"), childhood nicknames ("tukimoshi"), funny sounds ("blorpnax fantomila"), imaginary names ("zikkel morvayne")
Don't use: Real words from any language, celebrity names, "leet speak"
0 chars
Enter your invented words

Step 3: Numbers + Symbols

Numbers and special characters meaningful to you but impossible to guess. Prices, dates, coordinates, patterns.

Good: "47300!!@@" • "40.7128##-74.0060" • "$$$342.17***"
Avoid: "123456" (sequential) • Your phone number or SSN (could be leaked)
0 chars
Enter numbers and symbols

Step 4: Dice Rolls (Physical Randomness)

Roll a REAL physical die and click the result. Minimum 10 rolls. This adds true randomness no computer can predict.

Roll your die and click...
Roll at least 10 times

Step 5: Your Secret Sauce

Anything else uniquely YOU: song lyrics, coordinates, emojis, another language, inside jokes, formulas...

Ideas: A lyric from an obscure song • GPS coordinates of where you proposed • "the purple elephant ate my homework" • "f(x)=3x^2+7" • A sentence mixing 2 languages
0 chars
Add your secret sauce

Review Your Recipe

Verify each layer. Can you close your eyes and recall all 5? If not, go back and choose something more memorable.

Layer 1 — Sensory Memory
Layer 2 — Invented Words
Layer 3 — Numbers + Symbols
Layer 4 — Dice Rolls
Layer 5 — Secret Sauce
0
estimated bits of entropy
IMPORTANT: A forgotten recipe = lost crypto forever. Make sure you can recall all 5 layers from memory before proceeding.
This wizard NEVER saves or transmits anything. All data stays in your browser and is cleared when you close the page.
⚠ SECURITY WARNING: Dictionary Attack Risk
User-chosen recipes are vulnerable to dictionary attacks. Attackers run crackers continuously against the public Bitcoin UTXO set, testing billions of candidate passwords per second. Since this tool is open source, attackers know the exact KDF, iteration count, and recipe grammar.

Do not use this mode with significant funds. Use the Dice Roll mode (coming soon) for cryptographically secure entropy, or use a hardware wallet.

Reference: "The Bitcoin Brain Drain" (Vasek, Bonneau et al., FC 2016), Brainflayer (DEFCON 23)
MODE 1 - PURE FORTRESS: Your recipe generates a raw 256-bit private key. No public wordlists involved. Import into MetaMask, Trust Wallet, Electrum, Sparrow, or any wallet that accepts raw/WIF keys. Your recipe IS your key.

LAYER 1 - Personal Phrase

A sentence only you would know. Example: "My grandmother cooked arroz con pollo every Sunday"

LAYER 2 - Your Invented Words

Words YOU made up that exist in NO dictionary on Earth. This is what makes your key unbreakable. Example: "flurbnax zoptikrel"

LAYER 3 - Numbers + Symbols

Any combination of numbers and special characters. Example: "!!73**@942&&%%"

LAYER 4 - Dice Rolls (Physical Randomness)

Roll a REAL physical die and click the result. Each roll adds ~2.6 bits of true randomness that no computer can predict.

LAYER 5 - Extra Secret Sauce

Anything: coordinates, dates, song lyrics, another language, emojis, code... the more unique to YOU, the stronger.
KEY STRETCHING
Adds 3 layers of hash-based key stretching protection (Keccak-256 + SHA-256 cascading). Resistant to Shor's and Grover's algorithms.
Entropy Strength 0 bits
Add more layers

YOUR FORTRESS KEY

Private Key (Hex) - NEVER SHARE THIS
Private Key (WIF - Bitcoin)
Private Key (WIF - Dogecoin)
Bitcoin Address (P2PKH)
Dogecoin Address
Ethereum Address
Verification Hash (SHA-256 of private key)
HOW TO IMPORT YOUR KEY:

BITCOIN:
Electrum: File > New > Import Private Keys > paste BTC WIF
Sparrow: New Wallet > Import > paste BTC WIF
Exodus: Settings > Import Private Key > paste BTC WIF
BlueWallet: Add Wallet > Import Wallet > paste BTC WIF

DOGECOIN:
Coinomi: Add Wallet > Dogecoin > Restore > paste DOGE WIF
Exodus: Settings > Import Private Key > select Dogecoin > paste DOGE WIF

ETHEREUM / ERC-20 / POLYGON / BASE / ARBITRUM:
MetaMask: Import Account > Private Key > paste Hex key (without 0x)
Trust Wallet: Settings > Wallets > + > Import > Private Key > paste Hex
Coinbase Wallet: Settings > Import Wallet > Private Key > paste Hex
Rainbow: Settings > Import > Private Key > paste Hex

MULTI-CHAIN: Your ETH private key works on ALL EVM chains (Polygon, Arbitrum, Base, Optimism, BSC, Avalanche). Same key, same address everywhere.

For hardware wallets: Switch to Mode 2 (Hardware Bridge) to get BIP39 format.
CRITICAL SECURITY:
1. NEVER share your private key or WIF with anyone.
2. NEVER take a screenshot or save digitally.
3. Your RECIPE is your permanent backup - memorize it.
4. Same recipe = same key. Always. On any device.
5. Click DESTROY when you're done importing.
MODE 3: FORTRESS KEY IS YOUR hardware wallet
No hardware wallet needed. Use two computers: one online (to prepare transactions) and one offline (to sign with your recipe). The private key NEVER touches an internet-connected device.
ONLINE
Prepare TX
→
Copy hex
via USB/paper
→
OFFLINE
Sign TX
→
Copy signed
via USB/paper
→
ONLINE
Broadcast

STEP 1 ONLINE COMPUTER Prepare Transaction

Get your UTXO info from a block explorer (blockchair.com, mempool.space, or blockchain.info). Search your Bitcoin address and find unspent outputs.

STEP 2 OFFLINE COMPUTER Sign Transaction

On your air-gapped computer (NO internet), open Fortress Key and paste the unsigned transaction hex below. Then enter your recipe to sign it.
ENTER YOUR RECIPE TO SIGN
This derives your private key and signs the transaction. The key exists only during signing and is destroyed after.
Layer 4: Dice rolls

STEP 3 ONLINE COMPUTER Broadcast Transaction

Paste the signed transaction hex and broadcast it to the Bitcoin network.
Broadcast your signed transaction at any of these services:

BlockCypher: blockcypher.com/pushtx/btc
Mempool.space: mempool.space/tx/push
Blockchair: blockchair.com/broadcast
Blockchain.com: blockchain.com/btc/pushtx

Paste the signed hex, click submit, and your transaction is on the Bitcoin network.
No wallet software needed. No account needed.

Why Air-Gap Signing Is The Gold Standard

Hardware Wallet Fortress Key Air-Gap
Private Key Stored on device chip Never stored — derived from recipe each time, destroyed after
If device is stolen PIN protects, but physical attacks possible Nothing to steal — key is in your head
Firmware bugs Can compromise keys No firmware — just math in a browser
Supply chain Must trust manufacturer shipping Open source HTML file, verify yourself
Cost $60-250 Free (use any old laptop offline)
Recovery Need 24-word backup Your recipe = your backup. Nothing to lose.

Cryptographic Self-Test

These tests verify that every cryptographic primitive produces correct, known outputs. All test vectors are from official Bitcoin/Ethereum specifications and can be independently verified. Run these tests every time you download a new copy of Fortress Key.

What These Tests Prove

SHA-256: Verified against NIST test vectors. Ensures hashing is correct for address generation and transaction signing.

RIPEMD-160: Verified against known outputs. Used in Bitcoin address derivation (Hash160 = RIPEMD160(SHA256(pubkey))).

Keccak-256: Verified against Ethereum test vectors. Used for Ethereum address derivation and PBKDF2 Key Stretching.

secp256k1: Verified that a known private key produces the correct public key. This is the elliptic curve used by Bitcoin and Ethereum.

Bitcoin Address: Verified that a known private key produces the correct P2PKH address (starts with '1').

Ethereum Address: Verified that a known private key produces the correct 0x address.

WIF Encoding: Verified that private key to Wallet Import Format conversion is correct.

ECDSA Signing: Verified that signing produces valid, deterministic signatures (RFC 6979).

PBKDF2-SHA512: Verified against known test vectors. Ensures recipe-to-key derivation is correct and deterministic.

Audit Information

All cryptographic primitives use the noble-curves and noble-hashes libraries by Paul Miller.

These libraries have been independently audited by Cure53, a leading security research firm.

Audit report: cure53.de/pentest-report_noble-libs.pdf

Source: github.com/paulmillr/noble-curves | github.com/paulmillr/noble-hashes

Memory Limitation Notice:
JavaScript running in a browser cannot securely zero memory. Private keys and intermediate buffers may persist in RAM until garbage collection or page close. This is a fundamental browser limitation, not specific to Fortress Key.

Mitigation: Always run on an air-gapped computer. Close the browser tab immediately after use. For maximum security, reboot the computer after generating keys.

Key Stretching — Technical Details

Needed to Break BTC Current State (2026)
Logical Qubits 2,500 - 4,000 ~10-20 usable
Physical Qubits 10-20 MILLION ~1,500-2,000
Error Rate Near zero Still very high
Realistic Timeline 10-20 years (NOT 2 years)
Bottom line: Quantum computers will NOT break Bitcoin in 2 years. Anyone saying otherwise is uninformed or has an agenda. But 10-15 years? Bitcoin needs to be ready. And so should your keys.

How Key Stretching Works

1

Shor's Algorithm — Breaks Elliptic Curves

Can derive private keys from public keys by solving the discrete logarithm problem on secp256k1. This is the main threat. Requires ~2,500-4,000 logical qubits. Current quantum computers have ~10-20. The gap is 100-400x.

2

Grover's Algorithm — Weakens Hash Functions

Reduces the effective security of hash functions by half. SHA-256 goes from 256 bits to 128 bits of security. Still strong enough (128 bits = trillions of years), but we add extra protection anyway.

How Fortress Key's PBKDF2 Key Stretching Works

1

Layer 1: PBKDF2-SHA512 (500,000 rounds)

Standard key derivation. Even with Grover's quadratic speedup, this requires 707+ rounds of quantum computation per guess — each round is astronomically expensive on a quantum computer.

2

Layer 2: Keccak-256 Cascade (10,000 rounds)

The PBKDF2 output is run through 10,000 rounds of Keccak-256 (SHA-3 family). Keccak is a different construction than SHA-256 (sponge vs Merkle-Damgard). An attacker would need to break BOTH hash families — quantum algorithms that target one don't automatically target the other.

3

Layer 3: SHA-256 + Keccak-256 XOR Fusion

Final output combines SHA-256 and Keccak-256 via XOR. The result is only breakable if BOTH hash functions are simultaneously compromised — a scenario no quantum algorithm currently addresses.

4

Layer 4: Your Invented Words (Human PBKDF2 Key Stretching)

This is the most underrated quantum defense: Grover's algorithm provides quadratic speedup on KNOWN search spaces. But your invented words create an UNKNOWN search space. Grover can speed up searching through all English words — but it can't speed up searching through words that don't exist in any database. The search space is effectively infinite even for quantum.

Fortress Key Key Stretching — Details

Attack Standard BIP39 Fortress Key + PBKDF2 Key Stretching
Shor's (curve attack) Breaks secp256k1 if public key is exposed Same risk (secp256k1 used for addresses) — mitigated by not reusing addresses
Grover's (hash attack) 256→128 bit security. Searchable wordlist. Dual-hash (Keccak+SHA256). Unknown search space. 128 bits still = trillions of years.
Brute force key 2048^24 from known list — reduces search time Unknown character set + invented words = large search space against brute force
Future-proof Needs Bitcoin protocol upgrade (BIP-360) Hash-based protection already quantum-resistant. Recipe system is algorithm-agnostic.

The Bitcoin Community Response

BIP-360: Proposes quantum-resistant signature schemes for Bitcoin. Under active development.

NIST Key Stretching Standards (2024):
• CRYSTALS-Dilithium — lattice-based digital signatures
• SPHINCS+ — hash-based signatures (quantum-resistant by design)
• CRYSTALS-Kyber — lattice-based key encapsulation

What this means: Bitcoin CAN upgrade via soft fork before quantum becomes a real threat. The math, the proposals, and the code are already being built. Fortress Key's hash-based PBKDF2 Key Stretching is aligned with SPHINCS+ philosophy — using hash security as the foundation rather than mathematical problems quantum computers can solve.

Best Practices for Key Security

1

Never Reuse Addresses

Shor's algorithm needs your PUBLIC key. Bitcoin only exposes the public key AFTER you spend from an address. If you never reuse addresses, your public key is only briefly exposed during a transaction.

2

Use Fortress Key with PBKDF2 Key Stretching ON

The dual-hash cascade (Keccak + SHA-256) ensures your key derivation is resistant to Grover's algorithm. Your invented words make brute force impossible even with quantum speedup.

3

Move to Key Stretching Addresses When Available

When BIP-360 or equivalent is activated, migrate your funds to quantum-resistant addresses. Your Fortress Key recipe stays the same — only the address format changes.

4

Don't Panic

Quantum computers that can break Bitcoin are 10-20 years away. The Bitcoin community is already building defenses. Your keys generated today with PBKDF2 Key Stretching are among the most secure possible.

Why Fortress Key Is Different

Traditional (BIP39) Fortress Key (Mode 1)
Key Source 24 words from a PUBLIC list of 2,048 known words YOUR recipe: invented words, symbols, dice - none from any public list
Attacker Knows The exact 2,048 words. Just needs the combination. NOTHING. Not even the character set you used.
Dictionary Attack Possible (2048^24 combinations from known list) Impossible (your made-up words exist in no dictionary)
Who Generates The wallet firmware (which can have bugs) YOU generate. Wallet is just a signing device.
Backup Metal plate with 24 words (can be found/stolen) Your memory. Nothing physical to steal.
Recovery Need the 24 words written somewhere Re-enter recipe on any device, get same key

How It Works - Step by Step

1

You Create Your Secret Recipe

Combine 5 layers: personal phrases, INVENTED words (not from any dictionary), numbers, symbols, physical dice rolls, and anything else. This combination is unique to you and exists nowhere else in the universe.

2

PBKDF2-SHA512 (500,000 Rounds)

Your recipe is processed through 500,000 rounds of cryptographic hashing. This is a one-way function - knowing the output tells you NOTHING about the input. Even with all computing power on Earth, reversing it is mathematically impossible.

3

Raw 256-bit Private Key

The output is a raw cryptographic private key - a 64-character hex number. This is NOT from any wordlist. It's a direct mathematical result of YOUR unique recipe. This key controls your Bitcoin and Ethereum addresses.

4

Import Into Any Wallet

Software wallets (MetaMask, Trust Wallet, Coinbase Wallet, Electrum, Sparrow): Import the raw key or WIF directly. No 24 words needed. One key works on ALL EVM chains.
Hardware wallets (Coldcard, Ledger): Use Mode 2 to get a temporary BIP39 translation for import only.

5

Destroy + Remember

Destroy all displayed output. Your recipe stays in your head. If you ever need to recover: open Fortress Key on ANY device, enter the SAME recipe, get the SAME key. Works offline, forever, on any computer.

Why This Defeats Hardware Wallet Bugs

The Coldcard vulnerability was in its key generation firmware. When the wallet generates your key, you're trusting that its random number generator works correctly. If it doesn't (like the Coldcard bug), your key could be predictable.

Fortress Key removes the wallet from key generation entirely. You generate the key from your recipe. The wallet becomes a signing device only - it holds the key but never created it. A firmware bug in key generation cannot affect a key that was never generated by firmware.

The Math: Why Your Recipe Is Unbreakable

A typical 5-layer recipe with invented words produces 300+ bits of entropy.

Bitcoin private keys are 256 bits. To brute-force 256 bits:
• Guesses needed: ~1077
• All computers on Earth combined: ~1020 guesses/second
• Time to crack: ~1050 YEARS
• Age of the universe: ~1010 years

But here's the real difference: with BIP39, an attacker knows the wordlist (2,048 words) and just needs to guess the order. With Fortress Key, the attacker doesn't even know what characters you used, let alone the words you invented. The search space is effectively infinite.

Security Checklist

The code is open source and audited. But YOUR environment determines your security.
Follow this checklist every time you generate keys.

BEFORE GENERATING KEYS
AFTER GENERATING KEYS
WARNING: Generating keys on a malware-infected computer, while online, or with browser extensions running can compromise your keys — regardless of how secure this tool is. The code is not the vulnerability. Your environment is.
Report bugs or security issues: @jcreyx on X | GitHub Issues

Known Limitations

No security tool is perfect. These are the real limitations — read them before trusting Fortress Key with significant funds.

1. No independent audit of application logic
The cryptographic libraries (noble-curves, k256) are Cure53-audited. The way they are wired together — dice-to-seed conversion, BIP32 derivation, air-gap signer — has not been third-party audited. Community review is welcome: Security Review Request
2. Browser memory cannot be securely wiped
In the web version, JavaScript cannot guarantee that private keys are zeroed from RAM. They may persist until garbage collection. The desktop app (Rust) uses zeroize for real memory zeroing. Use the desktop app for maximum security.
3. secp256k1 has 128-bit classical security
This is inherent to Bitcoin and Ethereum — not specific to Fortress Key. All wallets using secp256k1 have the same security level. Fortress Key's 256-bit entropy feeds the key derivation, but the curve itself provides ~128 bits of classical security against brute-force.
4. Air-gap signer: P2PKH only (legacy addresses)
The transaction signer supports single-input P2PKH transactions only. SegWit (bc1...), Taproot (bc1p...), and multi-input transactions are not supported. For complex transactions, use Electrum or Sparrow with your imported seed.
5. Recipe mode is a brainwallet (use Dice Roll instead)
The legacy recipe-based key generator is vulnerable to dictionary attacks. Use the Dice Roll tab for cryptographically secure BIP39 seed generation. The recipe mode is kept only for users who need to recover existing funds.

Cross Any Border With Your Crypto

Hardware wallets get flagged at airports. Seed phrases on paper can be seized. Your recipe lives in your head.

THE PROBLEM
• Hardware wallets raise questions at customs
• Paper seed phrases can be photographed or confiscated
• Metal backup plates are suspicious in luggage
• Some countries restrict crypto hardware at borders
THE FORTRESS KEY SOLUTION
• Your recipe is in your head — nothing to confiscate
• Land anywhere, open this file offline, regenerate your key
• Import into MetaMask or any wallet in 30 seconds
• Same recipe = same key = same wallet, every time, forever

Travel light. Carry nothing. Own everything.

Verify Your Download

Before using any downloaded file, verify it hasn't been tampered with.
Compare the SHA-256 hash of your file with the official hashes below.

HOW TO VERIFY:
macOS / Linux: shasum -a 256 <filename>
Windows (PowerShell): Get-FileHash <filename> -Algorithm SHA256
OFFICIAL SHA-256 CHECKSUMS (v1.1.0)
macOS ARM (.dmg):
5be3c6042546a5613a8e06eb67c233f599be5cabaa97c98968497492fd3d81a0
macOS Intel (.dmg):
e61c3ed6fc15506f8555f9b3f3049733f9a2869a4ffb43910938bda5fee3350a
Windows (.exe):
b402c86a9ae0db973d4260ccb5b23ef56a97cef20a981189efba33fa0e9da7bd
Windows (.msi):
7312df45fb20b7902bf5833aab22c5a358f16508cd39fc9d8014f77a31795d58
Linux (.AppImage):
0b83dba37f10e0ca83e2778ab30a0408cb72bfbf1f4a99bd2f89f9f618c2c082
Linux (.deb):
0c1eee3aafe234f547a28ddc50ce0fff64a26ebc762423f3081014583c775699
Linux (.rpm):
d2a57511d06d638abe9fdfdcc60081d3ad1498d039018027deefaaf7c6ad6c33
Click any hash to copy. Also published at GitHub Release.
If your hash does NOT match — DO NOT USE THE FILE. Download again from this site.

Support Fortress Key

This tool is free and open source. If it helped you secure your crypto, consider donating.
100% of donations fund development, security audits, and keeping the tool free for everyone.

BITCOIN (BTC)
13wWCvGCG8QAFvRo44g4txu5Uh5nHLGZfv
Click to copy
DOGECOIN (DOGE)
D85bkBCqZYJSnvcPnefdSj4gMpp5YSzJ7m
Click to copy
ETHEREUM (ETH)
0x65831ed9318bb0ee5a2a8911ebb48871e0184205
Click to copy

These donation addresses were generated using Fortress Key. We eat our own cooking.