Register and share your invite link to earn from video plays and referrals.

FOUNDATION
@FoundationHQ
Passport Prime is Human Authority Hardware. Secure your Bitcoin, codes, wallets, agents, and apps built with KeyOS SDK. Nothing happens without your approval.
482 Following    26.6K Followers
Something is coming. Built for those ready to make the switch. No starting over. No looking back. September 15.
Passport Prime got a refresh. New launcher. New icons. New look. How are we feeling about the new UI? 👀
Sending Bitcoin with no mobile app, no desktop wallet, no Electrum server. Air-gapped Foundation Passport @FoundationHQ , @we_satoshis broadcasts two devices, QR to QR, straight to the bitcoin network. No middlemen. No servers. No permission. A @we_satoshis user filmed the whole thing 👇
Show more
The robot has been robotting again 👀🤩
I built a @SeedSigner style SeedQR transcriber app for Passport Prime. When you are done it scans your copy to confirm successful transcription. Nothing stored and the seed is zeroed when the app closes. Very much a POC and the UI could use some love, but the code is open 👇
Show more
4000 BTC GONE IN LIQUID NETWORK HACK | THE BITCOIN BRIEF 89
As AI changes the speed and accessibility of vulnerability research, responsible disclosure has never been more important. We’re working alongside researchers and other industry leaders to support coordinated disclosure, responsible communication, and sufficient time for vulnerabilities to be fixed before they are made public. 🤝 Protecting users must remain the priority.
Show more
📌 AI made finding bugs cheap, but it didn’t make responsible disclosure optional. Finding and exploiting vulnerabilities has never been easier. A few hours of prompting now does what used to take a skilled researcher weeks. Unfortunately, defenders no longer enjoy the asymmetry they relied on. Security is still a cat-and-mouse game, but with many more cats, the user suffers. Which is exactly why the process around disclosure matters more than ever. How it works, and it is not complicated: ➤ A researcher finds a bug and contacts the vendor privately. ➤ The vendor reproduces, acknowledges, and both sides agree on a timeline. 90 days is the common default, more or less depending on severity, capacity to fix... ➤ During that window both sides keep it secret while the vendor fixes and ships. ➤ Once users are protected, both sides publish. The ecosystem learns. The researcher usually gets paid. The issue now is the barrier is so low that anyone can surface a finding with no security background, and some skip straight to the audience: ❗Presenting a reproduction of an already-fixed bug as a live compromise. ❗Full disclosure of a bug that is not fixed yet. ❗"Critical vulnerability found" teasers, dripping details for engagement. Call it what it is: attention farming with someone else's risk. When the bug sits between a user and their funds, this is reckless. Especially in crypto, where there is no chargeback. But the damage doesn't require live funds to be at stake. Manufactured panic causes harm of its own, because it drives people away from self-custody, and that damages the whole ecosystem. So I have three asks: 1️⃣ For users: software and hardware have bugs, always. The single most effective thing you can do is stay updated and follow basic security hygiene. That has never mattered more than today. The time between releases and malicious actors exploiting the vulnerabilities have shrunk dramatically due to LLMs and that one can't afford to be passive and postpone security updates any more 2️⃣ For new researchers with a fresh model and a real, validated finding: welcome, we need you. Use the vendor's disclosure process. That is not bureaucracy. It is the difference between making the ecosystem safer and putting users in the crosshairs for a few likes. Remember that security communication must be accurate and proportionate. State the severity, affected versions, and fix status in the first sentence, not the tenth. 3️⃣ And to everyone building in this industry, vendors and researchers alike: let's make coordinated disclosure the norm we defend out loud, not the fine print. Reward the researchers who do it right. Refuse to amplify the ones who trade user safety for reach. This is how we win, together. Some of the actors already support the initiative. @Ledger @Trezor @FoundationHQ @AnchorWatch @_SEAL_Org and others Spread the message.
Show more
Coconut Wallet is now integrated with Passport! With the KeyOS 1.4.0 update for Passport Prime, you can now pair Coconut Wallet as a watch-only wallet. Whether you use Passport Core or Prime, connect your device to Coconut Wallet today and manage your Bitcoin with ease! Free on App Store & Google Play
Show more
Open Source FTW! Down to even the hardware designs 🧡
In case you missed how thoroughly open source Passport Prime is, here's a link to the machining drawing of the chassis for no reason
Your password and second factor shouldn't live in the same place. How to setup 2FA on your Passport Prime from your google account, all offline. 😎👇🏼
Envoy v2.3.1 is now available! 🚀 This release focuses on bug fixes, privacy, and reliability: • Activity-feed privacy for passphrase accounts • More reliable Tor connectivity • QuantumLink pairing restored on Android 10 and 11 • Passport Prime message-signing fixes Details 👇
Show more
Passport Prime is assembled in the USA! That matters because hardware security begins long before you switch a device on. Who assembled it? Who tested it? Who handled it before it reached you? The reason is practical, not patriotic. When you’re building a device people will trust with their keys, you should know exactly where it has been and who handled it before it reached them. With Passport Prime, we do.
Show more