Passport Prime costs $349. For that price you get a Bitcoin hardware wallet, FIDO security keys, two-factor authentication storage, a secrets vault, and 50 gigabytes of encrypted file storage. But the real shift is what you can do with it after you buy it. Foundation announced on May 22 that it had closed a $6.4 million funding round led by Fulgur Ventures and Arche Capital, shipped Passport Prime to general availability, and opened its KeyOS developer platform to outside builders. Cake Wallet, with 1 million active users, is the first outside team shipping on KeyOS. This reframes the entire self-custody stack from signing device to programmable security OS.
Passport Prime runs KeyOS, a Rust microkernel operating system Foundation spent three years building. The operating system includes QuantumLink, a post-quantum-secure encrypted communications protocol using ML-KEM (a lattice-based key encapsulation mechanism standardized by NIST in 2024) and ChaCha20-Poly1305 for symmetric encryption, running over a dedicated, isolated Bluetooth chip. This matters because it means the threat model already embedded in Passport Prime assumes quantum-capable adversaries recording encrypted channels now. Most hardware wallets still ship with classical cryptography. Passport Prime ships assuming that classical crypto may be broken retroactively. The same week Foundation shipped, AI coding agents began accessing the KeyOS developer platform via USB-connected MCP (Model Context Protocol) servers that let agents build, screenshot, and test applications directly on real hardware. This is not metaphorical infrastructure for agents; it is real, shipping API access.
Foundation's total capital raised now stands at $16.5 million across three rounds: a $2 million pre-seed in 2021, a $7 million seed from Polychain Capital in 2022, and this $6.4 million expansion round. The capital velocity matters less than what it is being deployed into. The $6.4 million funds acceleration of the developer platform, manufacturing scale at a U.S. ITAR-compliant facility, and the KeyOS app store launching by end of Q2 2026. The store is the inflection point. Right now, integration partners like Cake Wallet ship through direct SDK work. By end of June, any Bitcoin developer with KeyOS documentation and a simulator can publish to real hardware in customers' hands without Foundation's approval. That is the actual competitive shift. Titan keys, YubiKey, and Apple's Secure Enclave remain single-purpose security devices. Passport Prime becomes a platform.
Cake Wallet's integration proves real adoption pressure exists. Cake Wallet serves 1 million users who want better cold storage than legacy hardware wallets offer. By shipping Cake for KeyOS, those users get a Cake interface they already know running on dedicated hardware they can trust. Foundation gets proof that developers will move if the platform is real. The ecosystem signal is clean: Cake did not build this because Foundation asked. Cake built this because its users asked. That gap between announced platform and shipped integrations has killed dozens of developer platform bets. Foundation appears to be closing it on the first week.
The competitive implication is sharp. Self-custody hardware makers can now ship either signing devices or platforms. If you ship a signing device, you own the user experience and the attack surface. If you ship a platform, you own the developer ecosystem and the feature velocity. Passport Prime chose velocity. Ledger, Trezor, and Coldcard remain signing devices with excellent interfaces. Passport Prime becomes a Trojan horse into 1M+ users' security stacks because Cake moves first and other developers follow. Watch three markers: whether the app store launches on schedule at end of Q2, how many external developers publish in the first ninety days, and whether any of those apps gain adoption at scale (measurable in number of downloads or GitHub stars within six months). If the store launches and stays empty, this was a nice announcement. If it launches and fills, the hardware wallet market has a new architecture.
