Skip to content

At-home self-custody · no hardware-wallet company

Plebum Dominium

(PLAY-boom doh-MIN-ee-oom)

Absolute Ownership by the Common People

Plebum dominium is a goal, not a product. “Pleb” is an everyday Bitcoiner. “Dominium” is Latin for absolute ownership. This site is the how-to. A company, an app, or a custodian can fail the people who handed it the coins. The keys are made in private.

A computer that forgets the session. Dice you can see. Metal in three houses. Hardware signers are optional later — and only from more than one maker.

PLEBUM // AUTOPLAY_TIMELINE
M1 / M6

00 // Sovereignty, Handmade

Three keys, made at home. Any two can move the coins. No company has to agree. Hardware wallets are optional, not required.

01 // Create Randomness

By rolling casino-grade dice manually on wood, you generate unbiased offline mathematical entropy.

01010110010101010100110101010101011001101010101010101101
⚄
⚂

02 // Go Offline

We isolate calculations entirely. Boot into a temporary, open-source amnesic environment via a USB flash drive.

AIR_GAPPED

03 // Double-Blind Check

Eliminate code bias through software redundancy. Two tools must independently compute the identical public output keys.

APP_A // SPARROW [OK]
APP_B // ELECTRUM [OK]
✓

Match Verified

When both cryptographic code libraries line up, you gain mathematical certainty that your keys are flawless.

04 // Geographic Dispersion

Stamp the three keys in titanium and keep them in three separate places. Compromising one yields a useless fragment.

🏰
🏰
🏰

Before you start

Materials needed

Gather these before the first roll.

On the table

  • Five casino dice. You must be able to read every face.
  • Pencil, and extra copies of the recording grid.
  • A closed door. No camera in the room.

One computer

  • Boot 1 stays on the network. It only watches. It never holds a seed.
  • Boot 2 is a Tails USB on that same computer, with networking off.
  • A second USB carries verified files and payment files only.

Files, from their own sites

These are the files the process runs on. Check each one before it is copied.

  • Tails
  • Sparrow 2.5.5 (required version)
  • Electrum
  • Ian Coleman page
  • Dice converter

Metal

  • Three titanium plates. One seed on each plate.
  • With a StampSeed stamp kit you get the first plate. Choose the 24-word plate. Purchase two additional 24-word plates with that kit.
  • Cryptotag is the other option. It punches the word numbers, and the kit includes two plates. Buy one more. Use one method on a plate. Do not mix them.
  • Three places to keep them, far enough apart that one loss is not all three.

Click here to learn more about inheritance

Sheets in the packetThe presentation teaches the why. These sheets are what you take behind a closed door.

Optional

Not required to start. A signer can come later, and only from more than one maker. It does not create the key.

Hardware signersSeedSigner first. The others are the same kind of tool.

The Process From Start to Finish

1WhyThese are the single points of failure. Any one of them can lose the coins.
  • One seed

    One list of words that can spend alone. A leak, a fire, or one demand takes the coins.

  • An app or an exchange

    The company holds the keys. A login is not a key. The company can refuse the withdrawal, or close.

  • One place

    One house, one drawer, one safe. Fire, water, or a theft at that address takes every copy kept together.

  • One device, one company

    A hardware wallet is a tool. If it is the only copy, the coins depend on that device and on the company that made it.

  • A cloud or a computer

    A photo, a note, a password manager, an email. One hacked account is the whole seed.

2Two bootsSame computer. The Tails USB is the offline machine.
The same computer, first with the network on, then booted from a Tails USB with networking off
3Check filesReal sites only. Two tools must agree.
  • Their own sites

    Tails, Sparrow, Electrum, and the Ian Coleman page. No shortened link. No look-alike download page.

  • Hash and signature

    Check both on the online computer before a file is copied to the USB. If either fails, stop and download again.

  • Two tools

    The same 24 words, and later the same addresses, in two programs. If they disagree, stop.

  • Then the USB

    Run verify_kit.sh first. It checks hashes only, not signatures.

  • Official files
4Make keysKeep 1–4. Three lists of 24 words.
Dice faces 1 through 4 kept, 5 and 6 thrown again

How the checksum is checked

The 24 words are not 24 free choices. The last word carries a short check so a copying mistake is caught before you stamp metal. Three ways to validate it. Use at least two.

  • Two tools, same words

    Run the dice bits through the verified converter, then through the offline Ian Coleman page. Both must print the same 24 words. If they differ, stop. Do not pick the prettier list.

  • Let the wallet refuse a bad list

    On Tails, networking off, Sparrow or Electrum will open a valid list and reject a broken one. If it will not open, stop. Do not change a word to force it. That is how a seed gets destroyed.

  • Check the math yourself

    Each word is 11 bits. Twenty-four words are 264 bits. The first 256 are the entropy from the dice. The last 8 are the checksum. Hash those 256 bits with SHA-256. The first 8 bits of that hash must equal the last 8 bits in the list. Only word 24 can change to make that true. You do not choose it.

The converter in this kit appends that checksum after you have verified the file. The hand check is so you know what it did.

5Two of threeAny two keys spend. One key alone cannot.
Three keys around a vault that needs two signatures
6Practice spendDust in. Two keys sign. Dust out.
Unsigned payment, first signature, second signature, broadcast
7Metal + mapThree plates. Three addresses.
Three houses each holding one plate

The home plate

The 24 words alone open one wallet. Leave a little bitcoin there. A thief who takes only that plate and loads the words sees that balance and may stop.

The same words plus a passphrase open a different wallet. Use that one for modest spending. Write the passphrase down. Do not stamp it on the plate. Do not keep it in the same drawer.

Those words are still one key of the long-term fund. The fund needs any two plates. Do not put a passphrase on the 2-of-3.

Learn more about decoy wallet strategies here

Click here to learn more about inheritance

8House rulesFive walls. Everything else is furniture.
Five house rules
The bench names for this same method

Tails with networking Disabled. 2-of-3 native SegWit (P2WSH), path m/48'/0'/0'/2'. Unsigned payment file = PSBT. Wallet map = output descriptor. Public watch key = xpub. Dice bits follow the unbiased 1–4 map; extra bits fold with SHA-256. Verify hashes and signatures before anything runs.

TermsThe hard word, then what it means.Print one page
entropy
Randomness you made with dice.
airgap / Tails, networking off
A computer that cannot phone home this session.
2-of-3 native SegWit (P2WSH)
A vault that needs any two of three keys.
m/48'/0'/0'/2'
Sparrow fills this in. Confirm it. Do not type it.
PSBT
An unsigned payment file on the USB.
descriptor / xpub
The wallet map. It watches the money. It cannot spend it.
BIP39
The 24-word list.
hash
The file’s fingerprint. The site prints one. Your computer prints one. They must match, every character.
signature
The project saying that fingerprint is theirs. If the check does not pass, stop.
zero-trust
Do not take a company’s word for the key.