On the table
- Five casino dice. You must be able to read every face.
- Pencil, and extra copies of the recording grid.
- A closed door. No camera in the room.
At-home self-custody · no hardware-wallet company
(PLAY-boom doh-MIN-ee-oom)
Absolute Ownership by the Common People
Plebum dominium is a goal, not a product. “Pleb” is an everyday Bitcoiner. “Dominium” is Latin for absolute ownership. This site is the how-to. A company, an app, or a custodian can fail the people who handed it the coins. The keys are made in private.
A computer that forgets the session. Dice you can see. Metal in three houses. Hardware signers are optional later — and only from more than one maker.
Before you start
Gather these before the first roll.
These are the files the process runs on. Check each one before it is copied.
Not required to start. A signer can come later, and only from more than one maker. It does not create the key.
One seed
One list of words that can spend alone. A leak, a fire, or one demand takes the coins.
An app or an exchange
The company holds the keys. A login is not a key. The company can refuse the withdrawal, or close.
One place
One house, one drawer, one safe. Fire, water, or a theft at that address takes every copy kept together.
One device, one company
A hardware wallet is a tool. If it is the only copy, the coins depend on that device and on the company that made it.
A cloud or a computer
A photo, a note, a password manager, an email. One hacked account is the whole seed.

Their own sites
Tails, Sparrow, Electrum, and the Ian Coleman page. No shortened link. No look-alike download page.
Hash and signature
Check both on the online computer before a file is copied to the USB. If either fails, stop and download again.
Two tools
The same 24 words, and later the same addresses, in two programs. If they disagree, stop.
Then the USB
Run verify_kit.sh first. It checks hashes only, not signatures.

How the checksum is checked
The 24 words are not 24 free choices. The last word carries a short check so a copying mistake is caught before you stamp metal. Three ways to validate it. Use at least two.
Two tools, same words
Run the dice bits through the verified converter, then through the offline Ian Coleman page. Both must print the same 24 words. If they differ, stop. Do not pick the prettier list.
Let the wallet refuse a bad list
On Tails, networking off, Sparrow or Electrum will open a valid list and reject a broken one. If it will not open, stop. Do not change a word to force it. That is how a seed gets destroyed.
Check the math yourself
Each word is 11 bits. Twenty-four words are 264 bits. The first 256 are the entropy from the dice. The last 8 are the checksum. Hash those 256 bits with SHA-256. The first 8 bits of that hash must equal the last 8 bits in the list. Only word 24 can change to make that true. You do not choose it.
The converter in this kit appends that checksum after you have verified the file. The hand check is so you know what it did.



The home plate
The 24 words alone open one wallet. Leave a little bitcoin there. A thief who takes only that plate and loads the words sees that balance and may stop.
The same words plus a passphrase open a different wallet. Use that one for modest spending. Write the passphrase down. Do not stamp it on the plate. Do not keep it in the same drawer.
Those words are still one key of the long-term fund. The fund needs any two plates. Do not put a passphrase on the 2-of-3.

Tails with networking Disabled. 2-of-3 native SegWit (P2WSH), path m/48'/0'/0'/2'. Unsigned payment file = PSBT. Wallet map = output descriptor. Public watch key = xpub. Dice bits follow the unbiased 1–4 map; extra bits fold with SHA-256. Verify hashes and signatures before anything runs.
verify_kit.sh checks pinned SHA-256 hashes. It does not check signatures.