Your personal crypto bank

100% offline cold wallet BTC, ETH, USDT, and 27,000+ more

Your independence arsenal

Pick your setup. No cables, no charging, no back doors.

Still deciding on a plan?

Create your first wallet for free

You can always add physical cards later.

Get Started for Free
Why Mitilena is better

We don’t ask you to trust a black box

Let’s be clear: a standard hardware wallet (a "secure element") isn’t just a place that "simply stores" your private key. It is a MICROCOMPUTER. Beyond generating a wallet, it can perform thousands of complex operations behind your back.

01

You are dealing with a closed-source microcomputer built in a distant factory. Gaining access there requires signing NDAs, getting your business application approved, and pre-paying for chip batches. Yet, you hand this device the absolute power to manage your master keys.

If you start asking uncomfortable questions, they can simply reject you as a "difficult" client. And a regular buyer off the street? They have zero access.

02

At the factory, they hardwire their own closed operating system directly into the board. This system independently generates your private keys and signs your transactions.

You will never know what is truly hidden inside its silicon: a hardware backdoor for intelligence agencies, a data leak triggered by a specific command, or predictable key generation.

A logical contradiction

You are trusting someone else’s black box. On one hand, you say:

"They are smarter than me, so I’ll give them the right to manage my seed phrase."

But at the exact same time, you are saying:

"They are dumber than me: intelligence agencies, greedy factory workers, hackers, and the local mafia—none of them can exploit this."

This is a massive logical contradiction.

Secure element

A "smart" microprocessor that makes decisions for you.

The Mitilena card

It is purely a secure data carrier. It holds a private key (or seed phrase) that was encrypted by you, and only you.

You could literally write your private key onto a basic door fob, and it would still work with our app.

A python-skin handbag in your house is just a handbag. A live python behind your sofa is a dangerous, unpredictable threat. They might seem similar from a distance, but the difference is deadly.

We live in the era of Snowden, the NSA, China’s Great Firewall, and Europe’s Chat Control. In this climate, believing that a factory can mass-produce black-box crypto microcomputers and ship them globally without being monitored by "the right people" is hopelessly naive.

You trust him more than yourself

"Good day. I am Jamaha Nichaja. I moved here from a poor, distant province. My daily wage is less than what you pay in a single transaction fee. I live in the factory dorms, sleeping in shifts with two roommates, and I build your devices. Today, I am the guy who programmed the chip you are about to trust with your life savings. With great respect!"

Jamaha Nichaja, production line operator
A historical overview

This isn’t paranoia. It’s documented reality.

2013 · NSA and NIST
A backdoor in the global cryptography standard

The NSA pushed the Dual_EC_DRBG pseudo-random number generator—containing a mathematical weakness—into NIST standards. They then paid RSA Security* $10 million to make this flawed algorithm the default setting in their products.

* In cryptography RSA Security is what the IOC is in sport: the leading authority of the field, and the RSA algorithm itself is named after it.

2015 · Hacking Team and the NIS
Intelligence agencies buying "hacking-as-a-service"

A database leak from the Italian firm Hacking Team revealed that South Korea’s NIS was purchasing their Remote Control System. They used it to break into citizens’ phones, read KakaoTalk messages, and remotely activate microphones. The agent responsible for the purchase later took his own life, leaving a note claiming they were only watching "northern spies."

2017 · Vault 7, CIA
Weeping Angel: tech that pretends to be turned off

A joint CIA and MI5 program infected Samsung smart TVs. The TV would turn off its screen and indicator lights, appearing completely powered down, while the microphone secretly recorded room conversations and transmitted them to CIA servers.

Neutrality.
Reliability.
Guarantees.
1970–2018 · Operation "Rubicon"
The scam of the century: "Swiss reliability" was a CIA front

Switzerland’s Crypto AG was the absolute global leader in cipher machines and hardware cryptography. Everyone bought their equipment based on a simple logic: it’s Switzerland, they are neutral, they must be trustworthy! In 1970, the CIA and West Germany’s BND secretly purchased the company together, and intelligence engineers deliberately planted vulnerabilities into the key generation algorithms.

For decades, this deliberately compromised hardware was sold to roughly 130 countries—including Iran, Latin American nations, the Vatican, and even allies like Italy and Austria. Buyers believed they held an ultra-secure, closed "black box," while intelligence agencies read their secret communications like an open book. The CIA internally called it the "intelligence coup of the century."

The bottom line
EAL6+ EAL5+ CC ISO 15408 FIPS 140-3 PP-0084 SOG-IS BSI · NIAP AVA_VAN.5

Renowned cryptographer Bruce Schneier famously stated, “Complexity is the worst enemy of security.” Yet, the hardware wallet industry relies on the exact opposite psychological trick: blinding the user with so much complexity that they naturally assume it must be secure. We are handed the abbreviation EAL6+ as a guarantee of absolute protection, but behind that marketing fog lies a 100% state monopoly. The system rests not on the laws of mathematics, but on closed government agreements. Independent labs only test the chips; the actual certificates are always issued by state bodies (like the BSI in Germany or NIAP in the US). Without a license and strict oversight from governments—the exact same entities that historically love backdoors and mass surveillance—you simply cannot play in this market.

Ultimately, hardware wallet manufacturers are boasting that their "black boxes" are approved by men in suits whose literal job description is to monitor you.

!

Just 30 years ago, exporting strong cryptography from the US was prosecuted as arms smuggling. Cryptography was officially on the munitions list, right next to missiles.

Fact-check: The criminal case against Phil Zimmermann for exporting PGP (1993–1996); cryptography’s classification as a weapon under ITAR and the US Munitions List. US export restrictions were only eased in 2000.

In Europe, the Wassenaar Arrangement applies. Under this agreement, strong hardware encryption is classified as a "dual-use technology"—regulated on the exact same level as missile components and radar systems.

The EU is no exception. A manufacturer or distributor of strong cryptography falls under the dual-use goods regulation (2021/821), which means mandatory licenses, strict reporting, and constant state oversight. Every member state has its own intelligence agencies watching over this. The state never lets encryption out of its sight.

This is why the only person you can truly trust is yourself—not someone else’s microcomputer.

No hardware lasts forever. That’s why we built clones.

One thought used to terrify me about classic hardware wallets. You buy crypto, drop the wallet in a drawer and wait. Five years later, when the asset has done a 100x, you plug that USB stick in and nothing happens. The contacts have oxidized, the chip has simply given up. All those gains turn to dust because of one piece of plastic.

That’s why I built our architecture on redundancy. You don’t just get one device; you get three mirrored copies. Lose the first, damage the second, and you still have a working backup on hand. This is an uncompromising fail-safe. No more blind faith in a single stick.

And a seed phrase on a scrap of paper? Seriously? Trusting millions to a piece of paper that can burn, get stolen, or be accidentally thrown out by your partner, and then buying a safe just for that? You might as well keep your money under the mattress.

Jan Pejša, Founder of Mitilena. I protect your crypto as if it were my own.
Support for 27,000+ coins and tokens

Ethereum (ETH)

Monero (XMR)

Solana (SOL)

Tether Gold (XAUt)

Toncoin (TON)

TRON (TRX)

...and 27,000+ more

Your crypto isn’t yours if the keys are on someone else’s servers. We give you back absolute sovereignty.

And it doesn’t end with servers: third-party chips are just as vulnerable.

Private_User_#1447

Cypherpunk & OTC Trader

A stealth sticker on a piece of furniture is a completely different level of anonymity. Nobody suspects there is a wallet under my desk. And the remote signing feature? It’s unreal. A colleague at the office drafts the transaction, and I approve it with a sticker from the other side of the world.

Security through the eyes of people who know

Arbitrage_Queen

Systematic trader

The crypto industry sells an illusion of control. They hand you 12 words, then chain you to their software. Try importing that seed into another wallet, and it’s a coin flip whether you’ll see a zero balance. Here, you get the absolute baseline: direct access to your private key.

The antifragility principle

The blockchain is indestructible because its data is replicated thousands of times. Your body survives because billions of cells duplicate the same DNA. Yet, a standard hardware wallet is a single point of failure.

Keeping a key on one stick is a ticking time bomb. We are dismantling that approach. No more relying on a single piece of metal: copy your private key onto as many NFC carriers as you want, whenever you need.

Absolute stealth

Classic hardware wallets scream that there is money inside. You have to hide them in safes, constantly charge them, and plug in cables. We stripped away the excess and made the device invisible.

The sticker format blends perfectly into its surroundings—just attach it under a desk. It has no battery and emits no signals. Transactions are signed 100% offline (air-gapped) with a quick smartphone tap via NFC.

Protection against insiders

We completely eliminated all third-party scripts. No Google Analytics. No Hotjar (which literally records your screen).

Sundar Pichai or a Silicon Valley board of directors isn’t going to steal your satoshis. But a random sysadmin with access to a database and web logs just might. They can see your screen, swap the address in your clipboard, or scrape your data. And support will simply reply: “We found no vulnerabilities on our end.”

Who really controls the keys, and where are transactions signed?

You and only you. We completely rule out third parties, servers, or centralized exchanges on principle. All cryptography runs strictly locally on your smartphone. Even for heavy, anonymous blockchains like Monero, transactions are built and signed entirely inside our app and never leave your device. Your private key is encrypted with your personal password. A sudden account freeze at the snap of a platform admin’s fingers is impossible here. Not your keys, not your coins.

What happens if the wallet breaks after five years of hodling?

Picture this: you bought Bitcoin, hodled it for five years, and the price went to the moon. You pull out your classic hardware wallet to take profit, plug it into a USB port… and it doesn’t even power on. Game over. Have you ever tried booting up a computer that sat in a closet for five years? Or starting a car? After a couple of years, even an Xbox game won’t launch on the first try.

With our architecture, this scenario is impossible. You aren’t praying to a single fragile device. Your NFC card is a reliable carrier for encrypted data, not complex electronics that die from dust and time. Plus, you aren’t tied to our plastic: you can buy ten blank NFC tags for pocket change at any electronics store and clone your encrypted wallet into multiple backups.

One tag destroyed, or lost while moving house? It doesn’t matter, there is always a mirror copy somewhere else. And no random cleaner will ever realize there is money sitting there, so you don’t even need a safe.

Why is our NFC card more reliable than “secure smart chips”?

Classic hardware wallets use closed smart chips (“Secure Elements”). It’s a microcomputer with closed-source code. You send a transaction in, it does some hidden magic, and signs it.

In reality, you are entrusting your money to a faceless factory worker or a corporate developer you’ve never met. What if the local mafia or a mole is running the production line? Nobody knows what is actually wired into that chip. What stops someone from burying a backdoor that drains keys via a clever trigger, or quietly shaving balances off every thousandth wallet? When your balance hits zero, who are you going to complain to? The UN?

Our NFC card is just a “deaf” memory chip holding your encrypted text. It cannot think, and there are no hidden algorithms. You encrypt everything yourself.

Most signing chips in the industry come from Samsung. But when Samsung sends screenshots from your television to its own servers, it does not even hide it. And the other part of the chips, the ones that are not Samsung, were broken long ago, and so on.

Popular Smart TV models from Samsung and LG take several screenshots of the screen every second, including moments when the television is used as an external monitor for a PC or a games console. Source

And what if a courier or postal worker opens the parcel and swaps the card?

We don’t care who delivers the parcel. Our security doesn’t depend on who held the card before you. Cards arrive absolutely empty. You initialize the card yourself, and the private key is generated locally on your phone. Even if a courier slipped you their own NFC card, you would simply wipe it, write your encrypted key onto it, set your PIN, and it becomes yours. Blind trust in the supply chain is eliminated.

Why? Because there is no firmware running on the card. You can read the contents of the card with any NFC app. There is only encrypted text there, and you are welcome to try decrypting it, if you happen to have 40,000 years spare.

What guarantee is there that the manufacturer has no access to the keys?

Every single carrier—from the Basic plan up to Trust—arrives completely empty. Keys are generated locally on your device, not on our servers. After writing, the card is permanently locked with your personal PIN. Without it, nobody can read the key—not even us, even if we physically confiscated the card from you.

For maximalists: if honest architecture isn’t enough and you want a mathematically provable guarantee, choose the Ultimate plan. Key generation and signing happen on a device physically disconnected from the internet (air-gapped). The keys simply have nowhere to leak.

And what if my phone has viruses? Can they steal money from the app?

Modern smartphone architecture (especially Apple iOS) is radically different from a Windows PC where viruses run wild. It relies on a strict sandbox. Our app lives in an isolated digital bunker. Even if you download a trojan or a malware-infected flashlight app, it physically cannot break into our wallet’s memory or intercept processes.

The only thing a mass-market virus (a clipper) can do is swap the destination address in your clipboard. But our physical architecture saves you: before sending, the app displays the final address in huge font. Until you verify it with your own eyes and physically tap your NFC card to the phone, the signature isn’t generated. A virus cannot tap a card for you.

And all of that applies to the variant without offline signing. In the offline version, thousands of viruses on your phone can do absolutely nothing.

And what if my phone is hacked with Pegasus-class spyware?

Ordinary wallets are helpless here. Commercial zero-click exploits can quietly read your screen and memory. If you are a target at that level, your choice is the Ultimate plan.

How do you defend against it? You take a separate smartphone (an old one is fine), install Mitilena Keys and Mitilena Offline, remove the SIM, forget all Wi-Fi networks, and put it permanently in airplane mode. That is a total air-gap. Key generation and signing happen in absolute physical isolation.

So how do you send a payment in that mode? Data moves to your main (online) phone exclusively by scanning QR codes via the camera. No cables, no Bluetooth. Not even a $100 million virus can extract your keys because the device is physically cut off from the world.

What do you do about a physical attack or blackmail?

Let’s be honest: no ordinary wallet or classic multisig will save you from a $5 wrench attack. With standard multisig, criminals work to a script: hold the first signer hostage, call the partner, dictate the seed phrase, and the money is gone. It happens remotely.

Our Trust (multisig) plan destroys that script. If you are backed into a corner, you call your partner. But they cannot just dictate a code or send a seed phrase over Telegram. For the transaction to send, their card must be physically tapped to your phone. The remote hold-up is canceled. Criminals have to arrange a face-to-face meeting, show their faces to cameras, and risk 20 years in prison. They will just give up and go find someone with a standard Ledger.

Is there a weak spot? Technically yes. If the person leaning on you is a cyber genius who decompiles our app on a laptop right there in the woods. But the odds of running into someone like that are close to zero.

The blockchain multisig cultists will tell you smart contracts are safer. Nonsense. Classic multisig is broken with a single phone call to a frightened partner, who blurts out the seed phrase in fear and you are robbed remotely.

We could have gone full hardcore and tied the mathematics directly to the hardware chip of one specific card. But then the slightest fault in that plastic would mean the irreversible death of the assets. To avoid that, you would have to back the chip data up onto paper.

And here the circle closes: the blackmailers simply force your partner to take that paper out of the safe, photograph it and send it over Telegram. You are robbed remotely all over again.

Our architecture is armor for the real world. We make the remote holdup impossible, which filters out 99.9% of crime, while still leaving you the right to make a mistake and keep convenient backups.

What is the difference compared to a USB stick?

Let’s drop the illusions. Buying a USB stick with buttons looks like a spy gadget on a website, but in real life, it’s pure security theater.

First, that stick is a radioactive target. The moment you pull it out at airport security or leave it on an office desk, certain people start salivating. You’ve basically hung a neon sign on your back saying, “I own crypto.”

Second, the seed phrase circus. The manufacturer tells you: “write 12 words down on a piece of paper”. And where are you going to hide it? Buy a safe? A home safe is a magnet for every burglar. Let us be honest: for 90% of people that piece of paper simply sits in a book or a bedside drawer.

The cleaner, a curious teenager or a thief who breaks in while you are on holiday simply photographs that piece of paper and puts it back where it was. You may only find out you have been wiped out six months later.

Buying a sophisticated crypto stick and then keeping access to it on a scrap of cardboard in a drawer is like fitting a million-dollar titanium door to your house and hiding the key under the doormat. By the manual you did everything right, but in the end you outsmarted only yourself.