pico-quorum

The test ladder: from a simulated Safe to Ethereum mainnet

This is the tracker for getting the console’s approvals from the laptop to real chains. Each rung runs the same firmware and the same approval: someone proposes, the console shows it, you hold A, and the Safe executes. Only the Safe and the money behind it change from rung to rung. Tick boxes as things land, and link the evidence (a buildlog entry, an explorer link).

How a chip key owns a Safe, on every rung:

# Rung Where Who signs Status
0 Simulated tools/quorum serve, no chain Alice and Bob (simulated), the real Pico ✅ 2026-09-24, the real Pico (buildlog)
1 Local fork tools/quorum up: Safe 1.4.1 on an Anvil fork of Base, chain 31337 Alice and Bob, the chip ✅ emulator (tools/quorum e2e) · ✅ real Pico, 2026-09-25 (buildlog)
2 Base Sepolia testnet: the Safe web app and api.safe.global your browser wallet, the chip ✅ rehearsal with the emulator · ✅ real Pico, end to end over HTTPS, 2026-09-25 (buildlog)
3 Base a few dollars your browser wallet, the chip ☐
4 Ethereum mainnet a few dollars (base fee about 0.05 gwei in Sept 2026) your browser wallet, the chip ☐

Tools

Everything is tools/quorum. tools/quorum doctor checks what’s installed.

Command What
serve the simulated Family Safe (rung 0)
up [--manual-exec] anvil forking Base, plus the service on a real Safe (rung 1). --manual-exec makes it wait for live exec, as Safe’s real service does
e2e rung 1 end to end with the emulator’s chip, checked onchain
live key [--from URL \| --usb \| --emu] the console’s P-256 key and its owner address, kept in live.json (public values only)
live enroll --chain C deploy the key’s signer proxy (about 110k gas)
live status --chain C --safe 0x… the Safe and its queue, every signature checked here
live rehearse --chain C the emulator’s console, with a throwaway key, signs on the real service: the spike before the Pico
live exec --chain C NONCE execute, with the signatures laid out right (see Known issues)
live pico --chain C[,C…] point the board’s console at the Safe recorded for each chain (QUORUM_SAFES); several chains are watched together (guide/NETWORKS.md)

C is local, basesep, base or eth.

How live sends. Writes go through your browser wallet, the one you co-sign with in the Safe web app: live opens a one-page form on 127.0.0.1 and the wallet shows the transaction and asks. --account NAME sends from a Foundry keystore instead, and asks you to type yes.

Rung 1: the local fork

Rung 2: Base Sepolia

Before you start:

Rehearsal: the emulator’s throwaway key. No hardware, and it settles the biggest unknown, whether api.safe.global takes the console’s confirmation.

The real Pico (with you at the board). Its own key needs its own Safe, or it has to be added to the rehearsal Safe as an owner.

Rung 3: Base, a few dollars

Same steps as rung 2 with --chain base and QUORUM_URL = ".../tx-service/base". The plan (2026-09-25):

  1. The signer. tools/quorum live enroll --chain base for the sealed slot 0 key, owner 0x2843…5E53. The deploy is paid from MetaMask, about $0.002: tx.
  2. The Safe. Jason creates it in app.safe.global on Base:
    • owners: MetaMask 0x61D2…637F, the Pico 0x2843…5E53, and his other wallet 0x1289…f2DA
    • threshold 2
    • Not the emulator’s key, which is public. The Safe: 0xDebDE58b3ed0867d19285f6C8B0d81AdBC326Da9. Its owners are MetaMask, the Pico and 0xb78e…AdBD8 (an EOA, not the 0x1289… in the plan; confirmed Jason’s on 2026-10-06).
  3. The check (2026-09-25): Safe 1.5.0 L2, whose singleton and handler match safe-deployments for 8453. 2 of 3, nonce 0, no guard, no modules. live status --chain base --safe 0x…, plus the version, owners, threshold, modules and guard read onchain, and the singleton and handler matched against safe-deployments.
  4. Funding. A small amount of ETH to the Safe, about $1.
  5. The Pico switches to Base: tools/quorum live pico --chain base, or --chain basesep,base to keep watching the Sepolia Safe too (QUORUM_SAFES; each chain’s service comes from quorum_cfg.py, so QUORUM_URL goes). The same API key.
  6. One approval:
    • Propose a small send and sign it with MetaMask: in the web app, or in the PicoQuorum app (docs/app/, New transaction).
    • The Pico approves over HTTPS.
    • Try Execute in the web app. Expect GS021, and capture it for upstream: a screenshot, the simulation link, the app version.
    • Then live exec --chain base.
  7. The milestone: the same with the Pico on another Wi-Fi (a phone hotspot will do).

Costs. About $5 of ETH on Base in your wallet is plenty. Each of these is a fraction of a cent: signer 110k gas, a Safe 310k, an execution 110k.

Before any real money, on the board (and the chip: LOCKING.md):

Milestone:

Rung 4: Ethereum mainnet, a few dollars

Same steps with --chain eth. The console can watch it alongside Base: live pico --chain base,eth.

The Trust M rung

The same ladder for the OPTIGA Trust M (TRUSTM.md). The shareable docs are in mainnet/.

Known issues

Open questions