PicoQuorum’s OPTIGA Trust M signer is one owner of a 3-of-5 Safe on Ethereum. These pages are the shareable part. The chip profile and its ceremony are in ../TRUSTM.md.
| Page | For |
|---|---|
| COSIGNERS.md | the other owners: check the signer, day to day, execution, a lost device |
| THREAT-MODEL.md | everyone, once: what you can rely on, and what you can’t |
| CONFIGURATION.md | the recommended setup, and the address lock-down options still to decide |
| RUNBOOK.md | the operator: a chip from the bag to an owner, and what to do when things go wrong |
| attest/ | each chip’s ceremony record, checked with tools/quorum verify |
TM1, the first Trust M (serial 0a091b5c000b0062006c, owner 0x47c0998C6a7A1955794071b9f4058e7814178f35):
tools/fw attest on TM1 again.0x5617…DC41. Its signer is deployed
there, and its first approval executed onchain on 2026-09-30.getSigner agrees on both chains. The signer is not deployed on either.tools/quorum verify --chain basesep,base,eth.The mainnet chip will be a fresh one (TM3). The steps before it:
tools/fw ceremony start --unpin), with an explicit yes.tools/fw attest, and every co-signer runs verify.live enroll --chain eth, and the mainnet Safe.Drawn by the real firmware on the emulator’s virtual Trust M (node tools/board/shots_tm.mjs).
The chip in the shots is one that was sealed before T9 existed, as TM1 is.
![]() |
![]() |
| The ceremony image on a sealed chip. PROVISION goes to T8. | T8, the seal checked. The record, the binding, and a test signature. Changes nothing. |
![]() |
![]() |
| T9, freeze the spares. PERMANENT: the arm, then a 3 s hold. Only the lifecycle is written, to operational, never termination. | T9 done. Each group frozen, the key still signs, the security counter before and after. |
![]() |
![]() |
With --keep-open (here F1D2), the screen says what stays open: for example the spare key slots, if a chip should hold a second key later. |
T10. Its last line stays red until tools/fw ceremony finish turns ALLOW_* off. |
![]() |
![]() |
| The console’s Chip page before T9: what is still writable. | And after: nothing else on the chip can be written or get a key. |