Summary

When a new Ryder One wallet is created:

  • It is generated inside the Infineon SLC38 secure element.
  • It uses 256 bits of entropy.
  • The entropy comes exclusively from the secure element’s hardware TRNG.
  • The TRNG uses a physical noise source designed in accordance with AIS 31.
  • The wallet generation fails-fast, which means that the process is aborted if the TRNG is unavailable.
  • The TRNG output is tested using standardised statistical tests across multiple sample sizes during development.
  • The Secure Element applet code relating to wallet generation was independently audited by Halborn.
  • The seed phrase never leaves the device.

Following the recent Coldcard entropy incident, we understand that hardware-wallet users are reviewing how their wallets generate private keys and protect recovery information.

That scrutiny is healthy.

The security of a hardware wallet begins with one fundamental question: How is the randomness used to create the wallet generated, and can users trust that the correct source is actually being used?

We want to explain clearly how wallet generation works on Ryder One, what we verify, and what has been independently audited. If you already secure your crypto with Ryder One, your tokens are completely safe, and no action is required.

Ryder One uses 256 bits of hardware-generated entropy

Every new wallet generated by Ryder One uses 256 bits of entropy.

This entropy comes exclusively from the hardware True Random Number Generator (TRNG) inside the Infineon SLC38 Secure Element. It does not offer a software-based pseudorandom number generator, and it does not mix the TRNG output with another software entropy source.

The SLC38 generates randomness using a physical noise source designed in accordance with AIS 31, a recognised standard for evaluating random-number generators used in security-sensitive applications.

The resulting 256 bits of entropy are used to generate the wallet’s 24-word BIP-39 recovery phrase.

Wallet generation takes place exclusively inside the secure element

Wallet generation happens exclusively inside the secure element itself. The seed never leaves the device. It is never sent to the Ryder mobile app, Ryder’s servers, or any online service.

Your phone helps you interact with Ryder One, but it does not generate or receive the private keys controlling your wallet. The Ryder mobile app provides the wallet interface and the Ryder One is the signer.

The wallet generation process has no fallback by design

Our wallet generation process is designed such that it must complete properly or not at all. It has no fallback mechanism and will instead end in an error state. This is by design and called “fail-fast”. If the Secure Element, for whatever reason, fails to acquire the necessary amount of true random data or entropy, then it will refuse to generate the wallet.

Random data quality is tested routinely

Apart from strict design choices, we also routinely test the quality of the random data coming from the Secure Element. We collect output from the Secure Element’s True Random Number Generator and run standardised statistical randomness testing to verify that there is no bias and that the data is patternless and independent.

Testing randomness quality is important because the quality of the seed is only as good as the quality of the random data that was used to generate it.

The Secure Element applet is independently audited

All critical code paths pertaining to wallet generation, private key derivation, and signing are independently audited by Halborn. The report can be found here.

Does Ryder support user-supplied entropy?

Ryder One does not currently allow users to contribute additional entropy through dice rolls, coin flips, or another external mechanism during wallet setup.

Wallets generated by Ryder One therefore rely on the hardware TRNG inside the Infineon SLC38 secure element.

We recognise that some advanced users prefer independently contributed entropy as an additional safeguard. It is not currently supported, but we welcome users submitting and voting on feature requests through the Ryder feedback portal.

Does Ryder support a BIP-39 passphrase?

Ryder One does not currently support an additional BIP-39 passphrase, sometimes referred to as a “25th word.” However, we are always open to feedback via our feedback portal.

 

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More