Every claim on this site is checkable. This page is how.
Independently audited and signed 29 August 2026. This is the only image we ship. Every stick we seal was flashed from this image, then read back and re-hashed before it went into the bag — a stick that did not match was never sealed. Fingerprints are always shown here in full: anyone who shows you a truncated hash is asking you to trust the part you cannot see.
Hash the stick’s contents, not its partition table. The first 32,768 bytes of any USB stick hold its partition table. Windows rewrites a few of those bytes the moment a stick is plugged in — it stamps its own disk signature there — silently, on every stick, whether or not the stick is ours. That area is not part of our software. So the check skips it and hashes everything after it: bytes 32,768 through 14,137,344 of the raw stick, which is the entire boot image, byte for byte. Hashing the whole stick will not match, because the stick is physically far larger than the image. Hashing from byte 0 on a stick Windows has touched will not match either. Neither is a fault.
This is the fingerprint every command below should print. It is derived from the signed release image above by skipping its first 32,768 bytes; the release fingerprint itself is unchanged and remains the signed artifact of record. Nor can you hash the files you see when the stick is mounted — the fingerprint covers the raw image, not the files inside it. Every command below reads the raw device. None of them writes anything, to the stick or to your computer.
macOS. Find the stick with diskutil list external physical, then replace 4 with your disk number:
Linux. Find the stick with lsblk, then replace sdb with your device:
Windows. Open PowerShell as Administrator. First, find your stick’s disk number:
Find your KŌINIkeystick in that list — it’s the small USB drive, a few GB in size. Put its Number on the first line below, in place of the 2, then paste the whole block:
Honest note on that last one: the macOS and Linux commands are the exact commands we run on every stick before we seal it. The Windows script does the same work using only what already ships with Windows, and skips the same 32,768 bytes. If you see a red STOP message, it means the disk number was wrong or the stick wasn’t reachable — go back and re-check the list above; it is not a sign of a bad stick, and no fingerprint is shown in that case because it would not be valid. If it still gives you any trouble, email support@koini.io and we will check the stick with you.
A match proves the stick in your hand carries the exact image we published and an independent reviewer audited: byte for byte, nothing added, nothing swapped, by anyone anywhere between our bench and your desk.
It does not prove the computer you ran the check on is clean. A compromised computer can lie to you about anything, including this. Run the check on a computer you trust, and read it alongside the seal on the bag — the seal tells you nobody opened the package, the fingerprint tells you nobody altered what is inside it.
If the fingerprint does not match, stop. Do not boot the stick, and do not put funds on any address it produces. Email support@koini.io and we will replace it.
The fingerprint above is only as trustworthy as the page you are reading it on. To close that gap, the release is signed with minisign. Download SHA256SUMS and SHA256SUMS.minisig, then check them against our public release key:
A good signature means that fingerprint was produced by the holder of our release key — not by whoever served you this page.
The Mac edition is an app, not a bootable image, so it proves itself a different way: it is signed by Koini Global LLC and notarized by Apple. When you open it and it launches with no warning, macOS has already confirmed it is genuinely ours and has not been altered. If macOS ever warns that the app is damaged, unverified, or from an unidentified developer, do not use it — email support@koini.io.
For belt-and-suspenders assurance, the Mac disk image carries its own published fingerprint:
The Mac edition is a separate product with its own fingerprint; the bootable image’s fingerprint above is unaffected.
KŌINIkeystick is a commercial product, not an open-source project. Keeping the operating system closed means no one can clone it, counterfeit it convincingly, or ship a tampered fork under our name. You don’t need the source to trust the stick — you need proof the stick is genuine and proof the generator is sound, and you have both: the published hash confirms authenticity, the independent audit confirms correctness, the seal confirms it reached you untouched. Guard your stick like the tool it is; if it’s ever lost or the seal is broken, replace it.