PLEBLINEfree software for cold storage
Hold the line

Cold storage gets opened only once.
It comes out with the next months already signed.

One ceremony, the next months of payments signed in a batch, and the words going back into the titanium. In the months after, a payment is broadcast when it is needed. The seed does not move.

Signet trial coming soonwhere a mistake costs only time

version 0.1 · tested on signet · not yet reviewed by third parties

RustBDKTailssignetMIT

one night · the seed outall the rest · the seed in the safe
The problem

The risk is not in the device. It is in how often the words touch a machine.

Stackers receive often and spend rarely: a few times a year, sometimes never. And receiving needs no keys, no signatures, no software running: an address is enough.

Yet cold storage gets opened more often than that. To check the balance, for a top-up, for peace of mind. Each time, the 12 or 24 words end up in front of a computer again. It is an exposure born of a habit of checking, not of a need.

to receive

Never. An address prepared in advance is enough for good.

to spend

A few times a year. The only real reason to take the words out.

to check

Whenever doubt creeps in. It is the opening nobody needs, and the most frequent one.

The device is switched off in the drawer.
The exposure is not.

The idea

Pre-sign. Open one night, then leave the seed alone.

In one ceremony the next months of payments get signed, each on a coin of its own. Then the words go back into the titanium. When a payment is needed, it gets broadcast: it is already signed, and nothing is opened.

The method is old and proven. By hand it works, until two payments end up on the same coin.

Cold storage opens once.
It comes out with the next months already signed.

How it works

Four steps, always in the same order.

PlebLine holds no keys and replaces no wallet. It takes the ceremony that would otherwise be done by hand — coin control, planning, signing, verification — and makes it repeatable without depending on anyone's attention on a bad night.

The machine that forgets1

Tails

It boots from a USB stick, runs in memory and remembers nothing when the session ends. No dedicated computer needed. The network goes through Tor, and the program checks it before anything else: without a network, the words are not even asked for.

no disk, no trace

The coins2
statusfree
statusused by a signature

Before signing, a table shows every coin and its status. A coin used by a signature is still in the wallet and still on the chain: it is only already promised to a ready payment.

seen before, not after

The words, one night3

24

The 12 or 24 words are typed, and that is all. They never end up in a file, in an argument or in the terminal history. Once signing is done they go back into the titanium, and stay there.

never on disk

The next months, already signed4
signed paymentsN
receive addressesN

The already signed payments, each with its QR. And the addresses to receive on, in QR as well. Before leaving, the program checks the whole batch again.

two directions, no seed

the recipient

A wrong amount can be reread. A wrong but valid address is a payment to a stranger, and nobody notices. That is why the address is never typed by hand: it is pasted, or read from a QR. Then it is shown again in groups of four characters, for comparison by eye.

the confirmation

It never has «yes» preselected. On mainnet, before broadcasting, the amount is typed out in full. Nothing gets confirmed out of habit.

three programs

The terminal for those who know it, the guided path with a single road, the window for those who prefer the mouse. Underneath is the same code: one fix applies to all three.

The guarantee

No coin in two payments.

It is the exact point where the manual procedure breaks. Two payments signed on the same coin both look valid. It shows months later, when the network rejects one of them.

PlebLine makes that point impossible. To the program, a coin already used by a signature is not discouraged: it does not exist. No payment can ruin another.

It is not a single check. Around the selector sit other barriers, and they hold even if the selector got it wrong.

the selector

Picks coins without seeing the ones already used by a signature.

after each signature

The coins each payment actually spends are recorded. A coin used twice is an error that stops everything, not a warning.

before the files

The whole batch is checked again: no coin in common, and no payment depending on another.

across ceremonies

Even months later, a new ceremony does not touch coins already used by a signature, in any folder on the same machine.

When there are not enough coins

Every payment needs a coin of its own. With 4 coins, 6 payments cannot be made, and it is not a limit of the program: it is how bitcoin works.

the line moves

5 payments

coins available7to be created0

Each payment spends a different coin: that is what makes broadcasting one leave the others intact.

The program says so before signing, and prepares the fix: a payment back to the same wallet that splits the coins into more parts. It gets broadcast, one confirmation is awaited, then the real ceremony takes place. How many coins can be reached is computed by the program and stated before anything is chosen: below 10,000 sat a coin costs more than it is worth.

If they are stolen

A pre-signed payment is not bearer cash.

Whoever steals the pre-signed payments can do one thing only: send that money where it was already decided to go, on the night of the signing.

They cannot change recipient or amount. The signature covers both: changing either breaks it, and the network rejects the payment.
They cannot spend anything else. That would take the words, which are in the titanium. The phone that keeps the payments holds no key.
Privacy, yes: that is lost. A stolen payment reveals coins, amounts and addresses. That is why the files are written readable by their owner only: they hold no keys, but they hold a financial history.
From the drawer to the phone

The payments go on the phone. The words stay where they are.

Every signed payment also comes out as a QR, in hex or as a PSBT. The phone scans it, and when needed it gets broadcast from there.

out of cold · almost never

An already signed payment goes out. Signed on the night of the ceremony.

The rare one. A few times a year, sometimes not at all. Already signed, it is a file to broadcast: nothing gets opened, nothing gets retyped.

into cold · always

Scan the QR and send. From the everyday wallet.

The usual one. Stacking never required opening anything: an address is enough. PlebLine hands them out unused, each with its QR.

The other direction works the same way: the receive addresses leave the ceremony with their QR. Sending coins to cold storage does not require opening it.

And if the program disappeared one day, the payments stay signed. Next to each one is a file with its hex, which is all the network asks for: it can be broadcast from any computer, even without PlebLine installed.

Both directions without the seed.
The seed came out one night, and has not moved since.

Don't trust, verify

Verification runs without keys and without a network.

plebline verify redoes every calculation from the bytes of the payments. Anyone can run it, on any computer: it checks, but it cannot spend anything.

It also looks at where the change goes, which in a payment is almost always the largest amount. Every output goes to the recipient that was written, or comes back. There is no third case.

And it recomputes every signature from the bytes. A broken signature shows up the same night, not six months later in front of a rejected payment.

Where each promise lives

The code will be published. These are the places to look.

coin_select.rs · batch_regtest.rs

No coin in two payments of the same ceremony.

wizard.rs · committed_outpoints

No coin in two payments of different ceremonies on the same machine.

verify.rs · signatures.rs

Verification without keys and without a network, and signatures recomputed from the bytes.

no_secrets_on_disk.rs

Every file produced is opened and checked byte by byte: no words, no passphrase, no private keys.

tor.rs

The network goes through Tor or to a node of one's own. A public server in the clear is refused before the first packet leaves.

address.rs

Pasted, from a URI or from a QR, the address goes through the same check. A wrong network is stopped, and a mistyped address is never «fixed».

split.rs

Splitting coins, and the maximum that can be reached.

Where it stands

What it does. What it does not.

Version 0.1. One full run on signet, coin splitting included, confirmed on chain. Not yet reviewed by third parties, and not yet used with real amounts.

What it does

  • Signs the next months of payments in one ceremony.
  • Prevents two payments from spending the same coin, even across different ceremonies on the same machine.
  • Lets every signed batch be verified without keys and without a network.
  • Never writes the words to disk.
  • Talks to the network only through Tor or with a node of one's own. No telemetry.
  • Splits coins when there are not enough.
  • Prepares a QR for every payment and every receive address.

What it does not

  • It does not generate the words, on purpose. Those without them make them by hand, with dice or cards.
  • It is not an everyday wallet, and it does not replace a hardware wallet.
  • It is not a service: no account, no server of ours.
  • It does not handle multisig, Lightning or hardware wallets.
  • It does not hide the addresses from the server being queried.
  • It does not change the fee after signing. If the market rises, a payment can get stuck, and only CPFP frees it.
Try it

On signet the coins are worth nothing. Everything else works as on the real network.

It is the right place to make mistakes: a mistake costs only time.

The coins

  1. Receive addresses are prepared with PlebLine.
  2. At the faucet (signetfaucet.com) a separate payment is requested for each address: one payment is one coin.
  3. One confirmation is awaited, then the ceremony takes place.

On Tails

  1. The PlebLine-prova folder is copied into Home.
  2. In the terminal: sh, a space, then the installa file dragged in.
  3. PlebLine is in Applications → Office. No administrator password.

On the Mac

  1. The package folder is opened.
  2. Double click on PlebLine.app, left inside the folder.
  3. Try it out. The real ceremony needs the machine that forgets: the Mac is only for testing.

The real test is the last step. Payment #2 is broadcast, then #0, then #1, days apart. If one is rejected, two payments were competing for the same coin — and the flaw shows on chain, not just on paper.

For wallet developers

A signed PSBT, inside a QR.

what comes out

For each payment, a QR with the BIP174 PSBT in base64, already signed and finalized. Each input carries only the coin's value (witness_utxo) and the final signature. No derivation paths, no wallet fingerprints.

what we ask

Import it from a QR or a file. Keep more than one, encrypted. Broadcast it when the user decides, showing amount, recipient and fee.

optional

Warn if a coin of the payment turns out to be already spent: it means that payment will never go through.

what we do not ask

No server of ours. No library of ours. No commercial agreement.

Questions

The objections, in full.

Is it safe?
Here is what is tested: one full run on signet, confirmed on chain, and automated tests on the points listed above. Here is what is missing before mainnet: a third-party review, signed fingerprints, a reproducible build. The place to try it is signet.
Why isn't my hardware wallet enough?
It can stay in use: PlebLine does not decide where the keys are kept, it reduces how often they come out. But a hardware wallet, as has been shown, is a single point of failure: it depends on its firmware, its updates, and exploits that can come from the inside. To a thief it is an object that draws attention: a keyring with the keys inside, lying around the house. And it was not built as cold storage: it was built to make paying on chain convenient.
What if today's fee is not enough in six months?
It can happen, and it is the cost of pre-signing. A high fee is chosen, and a stuck payment is freed with CPFP. Changing the fee means signing again, that is, opening cold storage again.
What if I lose the payment files?
The coins stay where they are. The signed payments will not go out any more, but the coins are not locked: the program counts a coin as used only as long as the signed file that spends it exists.
Who sees my coins?
The server being queried sees the addresses. It is the one thing the program cannot hide: that is why traffic goes through Tor, and a node of one's own can be used. The server in use is always shown on screen.
Why Tails?
Because the real protection is the machine. While signing, the key has to sit in memory, and on a normal computer it can end up on disk. Tails runs in memory and forgets everything when the session ends: the words pass through one night, and leave no trace.
Do I need to know the terminal?
No. There is a window that asks the same questions in the same order. On Tails, installing it takes one line in the terminal, once.
Is there anything to buy?
A USB stick for Tails and a metal backup for the words. The program is free software, MIT licensed.
In two lines

Simple does not mean little. It means fewer things that can break.

Nothing to buy and nothing to subscribe to. It is an old method, written down so that nobody has to remember it.

A wallet asks where.
PlebLine asks how often.

Signet trial coming soon