pico-quorum

A Trust M signer for a mainnet Safe

PicoQuorum’s OPTIGA Trust M signer is one owner of a 3-of-5 Safe on Ethereum. These pages are the shareable part. The chip profile and its ceremony are in ../TRUSTM.md.

Page For
COSIGNERS.md the other owners: check the signer, day to day, execution, a lost device
THREAT-MODEL.md everyone, once: what you can rely on, and what you can’t
CONFIGURATION.md the recommended setup, and the address lock-down options still to decide
RUNBOOK.md the operator: a chip from the bag to an owner, and what to do when things go wrong
attest/ each chip’s ceremony record, checked with tools/quorum verify

Where it stands (2026-10-01)

TM1, the first Trust M (serial 0a091b5c000b0062006c, owner 0x47c0998C6a7A1955794071b9f4058e7814178f35):

The mainnet chip will be a fresh one (TM3). The steps before it:

The ceremony’s last steps on the screen

Drawn by the real firmware on the emulator’s virtual Trust M (node tools/board/shots_tm.mjs). The chip in the shots is one that was sealed before T9 existed, as TM1 is.

   
The ceremony image on a sealed chip. PROVISION goes to T8. T8, the seal checked. The record, the binding, and a test signature. Changes nothing.
T9, freeze the spares. PERMANENT: the arm, then a 3 s hold. Only the lifecycle is written, to operational, never termination. T9 done. Each group frozen, the key still signs, the security counter before and after.
With --keep-open (here F1D2), the screen says what stays open: for example the spare key slots, if a chip should hold a second key later. T10. Its last line stays red until tools/fw ceremony finish turns ALLOW_* off.
The console’s Chip page before T9: what is still writable. And after: nothing else on the chip can be written or get a key.