pico-quorum

Recommended configuration: a Trust M signer in a 3-of-5 Safe on Ethereum

This is a recommendation for you to decide on. Nothing in it has been frozen on a chip.

The short version:

What protects what

Layer What it enforces What it does not
The Safe (3 of 5) No single owner, the Pico included, can move anything. Owners can be rotated out. Three colluding or compromised owners.
The console firmware It rehashes every transaction on the device, with the chain and Safe pinned, and shows every page. It refuses a hash mismatch, another Safe, and delegatecalls outside the pinned batchers. Red pages need a 3 s hold. Anyone who holds the board with a USB cable. The REPL is open, so they can run their own code.
The Trust M The key was made inside the chip and can never be exported, regenerated or replaced (T7). After T9, nothing else on the chip can be written or get a key. What it signs. It signs any 32-byte digest it is handed. There is no PIN, no use limit and no record of each use.

So whoever holds the board can make it sign anything, and nothing on a Trust M records that it happened. (The ATECC’s LimitedUse counter does.) That costs one signature toward three, and the remedy is rotation (RUNBOOK.md, “Lost or compromised”).

Address lock-down: three options

Today the Safe address, the chain, the service and the batchers live in secrets.py and quorum_cfg.py on the board’s flash. Nothing checks those files at boot, and none of it is on the chip.

(a) Config only (reversible).

(b) A signed config record, frozen on the chip.

(c) (a) now; (b) only on a dedicated mainnet chip, if you still want it after (a) has run for a while.

Recommendation: (a), the Safe stays off the chip (2026-10-01, after talking it through).

Still open: the spare key slots. T9 freezes E0F2 and E0F3 empty, so each chip holds exactly one key and one owner address.

The mainnet Safe

Version. Safe v1.4.1, the L1 singleton (0x41675C099F32341bf84BFc5382aF534df5C7461a, proxy factory 0x4e1DCf7AD4e460CfD30791CCC4F9c8a4f820ec67). Check both onchain (cast code) before you deploy, and check the Safe’s VERSION() and masterCopy after.

Owners: 3 of 5, and no single kind of device can reach three.

Threshold changes and owner changes:

Delegatecall. Keep the console’s refusal. Only multiSend to the pinned MultiSendCallOnly (1.4.1 or 1.3.0) is signable.

Modules and guards. None at the start.

Execution.

Tokens. Mainnet USDC is already pinned in quorum_cfg.py with 6 decimals. Any other token the Safe will hold should be added to quorum_cfg.py’s chain 1 list, after checking its symbol() and decimals() onchain, so it shows by name and amount.

The service.

The mainnet chip

Use a fresh chip, not TM1.

The order:

  1. TM2 as the sacrificial chip: it confirms T9 and the refusals on silicon.
  2. T9 on TM1.
  3. The mainnet chip (TM3).

Later, not in this round