Firefly - Build your own hardware wallet by Richard Moore | Devcon SEA
Devcon·Tue, Oct 7, 2025, 12:00 AM
Speaker
Build your own Firefly hardware wallet and write your first custom firmware in a short interactive session. All parts provided, just bring a laptop and USB-C cable. Speaker(s): Richard Moore Skill level: Intermediate Track: Developer Experience Keywords: DevEx, Hacks, Hardware wallets, arduino Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Transcript
[Music] so um a lot of you probably know me from my slides are excellent um most you probably know me from ether's JS um but today I'll be talking to you about Firefly um our new exciting Hardware wallet that we want to like get in the hands of everyone um so keeping an eye my time I see all the things okay so what do we have so what is Firefly so Firefly it's an open source firmware open Hardware Hardware wallet um it's going to be cost effective hopefully everyone will get them for free we have like 126 to give out today so feel free to drop by after and grab one um and it's customizable you can do whatever you want with it if you want to like start your own Firefly competitor and just take our hardware and our software you can run with it um if you can produce this cheaper than us we want we welcome you to the goal is to get security in the hands of people everywhere no matter what and so if you have a more cost- effective or a better way to disseminate to a group of people we can't reach we want that um so again it's about making hard worlds fun again um whether you want to put a game on it whether you want it to be like a a little animated gif thing pong uh if you have a crypto Kitty you really like and you just want like a harder wall is just dedicated to that crypto Kitty only forever um you can do it ah so assembly originally this was going to be a like 2hour like assembly thing so um if you want to build your own you're starting your own Empire for Firefly you're trying to take us out first thing you need is a crew so uh my parents and my wife over here uh we got together and in an evening I mean it took about an hour and a half and I think we made 200 Firefly um so I mean my parents aren't super technical and they can build these things I actually have one here I was going to build on stage but I think I will forgo that just because I'm running out of hands um so um things you need you need basically a pile system you need a pile of like the panelized boards so six fireflies come per board this is all in a script in the repository if you want a single PCB board you can do it and just have one one Firefly per board if youve got like a crazy manufacturing facility and you want like a kilometer square of these things you can just type those numbers in and I mean power to you um so you have a pile for like your completed fireflies your displays the cases and that's really it it just like Clips together um again it's designed to be nice and simple we're trying to like reduce costs to make it easier to do what you want to do um right so step one I guess I just cover this you D panel it it just snaps off and there you go there's your Firefly um then you clip your little screen in I'm not going to do that right now again lack of hands and it snaps in it's like a snap fit so it has a nice satisfying click once it all works um okay so that's assembling provisioning um so this is where you might if you were trying to like compete with us do your own thing so we have a private key that we use to sign each device um so the device generates the private key for attestation on the device it's never been on any computer ever um it also is why it takes like two minutes to to provision device sometimes um RSA is kind of crazy you basically pick a bunch of random numbers do some rudimentary math to make sure it's not obviously not co-prime um and then you burn that to the Chip And it well first it sends that to assigning server which signs it it's a bunch of like back and forth but at the end of the day you get like proof on the device sorry evidence on the device that it can use to prove that it's a genuine device so if you're trying to if you're trying to build your own uh crypto Kitty Empire that each crypto Kitty lives on a device now the device can prove to the world I am a genuine device issued by axom Zen and uh I have not been tampered with and cost breakdown just for those that are curious um I mean the costs are there you can take a look at the big cost for us right now is the case which is 3D printed I mean we're doing low runs of like 500 at a time so uh that's a huge cost right now but once we move to injection molded you can imagine that goes down to like 12 cents that's like $2 off of the cost so we get down from $9 to 10 Canada has a lot of extra tariffs um so there's another like dollar we're paying so anyways there's places to save money and we're trying to keep the C we're trying to bring the cost down um yes and huge thanks to to ens Dow public goods working group um their funding helped us the with the first 2,000 devices and so we're like 650 out of those 2,000 um so the next event we'll have another th000 and I that is my talk and I have 10 seconds left but I think there is time allotted for questions so yes thank you we got our first thank you hello how can you Ure that uh each of the devices are unique and no duplicates have been made uh duplicates in what sense uh in their baked in private key so uh the private key is generated using like thermal noise on the device during the provisioning process we also jam it full of extra entropy and so it mixes the entropy we give it and takes its own entropy and smushes them together to like make I mean we could produce fraudulent devices but that a test station key is more of a threat to us if someone else gets it but there's a digital signing peripheral on the device that makes sure that private Keys encryption key is all stored and the CPU can't reach it like even if you write your own firmware which you're more than welcome to do you can't ever get that private key off like we can't so thank you next okay thank you this is this is amazing uh if someone was to try to dedicate some time to hack either the firmware or the hardware stack um where should we start please come see me um we will be I'm hoping to get a bounty out for I exactly want to pay people to try hacking it awesome I want you to like if you think you found a way to like glitch the device or undervolt it um the devices are currently based on the esp32 C3 version rev 0.4 so the glitching issue that affected the previous esps is not currently known to affect this but if you can do it I mean a we would love it and B I'm sure espressif would like love to talk to you as well because yeah um sorry yes oh sorry I was just being reminded off stage uh to check out the Twitter because it's Firefly pocket um because that well I should have put that on the slides um because that will be a good place for you to kind of track all the crazy things we're working on and if you if we post a bounty that's where it'll be sorry I cut someone off that was asking oh yeah um I have a question when it compares to other Hardware wallets right like there seems to be a dominant player called Ledger how do you compare to that how would you sell how would you help us sell Firefly to the users of leder and make them convinced we should all use Firefly now so in that regard I mean I feel like there's still space for all these players out there that we're not trying to conquer the world the goal is not market share the goal is just I mean providing that competition that maybe makes them do a different thing better or uh there's there's definitely yeah we're we're not trying to conquer the world um but one huge Focus we are dedicated to is a we're ethereum first basically ethereum only I mean e ethereum adjacent only obviously like your your arbitrum and all that work but we don't focus on bitcoin or those other things um and so a huge part of ethereum is really meaningful clear signing like we don't want the word blind signing should never occur in your device unless you're calling a method in a contract called Blind sign in which case it's a ter name don't call your your project I get so yes that's that's the big thing we're aiming for is like yeah death to Blind signing last [Applause] question okay yeah um not quite a question I actually just want to say thank you for ether's J JS you've like made ethereum accessible thanks thanks I'll be talking about ethers on Friday if you're around and want to hear some hidden gems for the API but aming and then so to see you do another project like this that makes you know signing accessible and um it's amazing so thank you awesome [Applause] thanks last question okay all right thank you guys and Richard thank you so much for this let's give a hand of Applause to Richard wow all too soon thank you
Automatic transcript — names and jargon may be misspelled.