pico-quorum

Security

Reporting a vulnerability

Please report it privately: open a security advisory on this repository. Don’t open a public issue for anything that could put a Safe’s funds or a key at risk. PicoQuorum is experimental and maintained by one person, so expect a reply within a few days, not hours.

PicoQuorum console (the production image)

The Pico is one owner of a Safe multisig. Losing it, or everything on it, costs one signature toward the threshold, never the Safe: the other owners can execute without it and rotate it out.

The signing boundary is the device’s own rehash.

What is on the board. Exactly the console image in firmware/manifest.json; tools/fw verify checks every hash.

The pin. QUORUM_EXPECT names the chip’s serial, the slot, its lock and the owner address its key must produce. The console checks it at start and again right before each signature. A chip swapped on the board, or another slot, signs nothing.

The counter is an audit hint, not a lock.

Still open to whoever holds the board:

The network.

The chip’s config.