ENTANGLED BIT / OFFLINE KIT 0.4.1 Engineering alpha. Begin with devnet test assets. No independent audit. PUBLISHER KEY UPDATE / 2026-10-10 Release 0.4.1 uses a new publisher verification key because the previous publisher seed was lost. This is a new trust anchor, not an update signed by the old key. Obtain this release from https://entangledbit.xyz/downloads. Older clients trust the previous publisher key; replace them with this kit. Your existing .entb backups, ENTB1 recovery keys, and Solana accounts are unchanged. Do not generate a new vault recovery key for this update. 1. Verify the release signature and file on the online Downloads page. 2. Back up and, if desired, format your USB using your operating system. Formatting deletes its contents. This kit never formats or flashes firmware. 3. Copy this kit onto the USB. Open entangled-bit-offline.html in a current desktop browser on a trusted disconnected computer. 4. Create or recover an ENTB1 vault identity. Keep its recovery key on a separate backup, never beside the encrypted vault. 5. All vault features are free. No account, subscription, or activation receipt is required. Older .entb files and ENTB1 recovery keys remain compatible. 6. Create/import a Solana key, save the encrypted .entb backup, reopen it to verify recovery, then export the PUBLIC account file. 7. At the online /transfer desk, import that public account file, select the network, and prepare a request. Move only the request to the offline client. 8. Check the complete recipient, amount, network and fees before signing. Return only the signed packet to the online desk; simulate and submit. 9. Check confirmation. Submission alone does not mean the transfer succeeded. Recent blockhash requests expire quickly. Durable nonces give more signing time after a separate nonce-creation transaction. A signed nonce packet remains usable until the nonce changes. Deleting it does not revoke it. A failed nonce transaction can still advance the nonce and incur fees. Invalidate pending packets through the nonce-advance operation; confirm it on-chain. OPTIONAL VERIFIED COPY TOOL (Python 3.9+) Extract the ZIP first. From its folder run: python3 install.py /path/to/mounted/USB --manifest-sha256 CHECKSUM Copy CHECKSUM from the trusted Downloads page. Windows: use py instead of python3. The tool checks all files and reads them back after copying into a new folder. It does not independently verify ML-DSA; the checksum must come from the trusted page after publisher-signature verification. No network or administrator access. SECURITY BOUNDARIES Assets remain on Solana. The encrypted USB holds the account's private key. ML-KEM-768 + AES-256-GCM protect backups. Ed25519 authorizes on-chain transfers. ML-DSA approvals on transfer packets are verified by Entangled Bit, not Solana. This is not end-to-end quantum-resistant on-chain custody or secure hardware. Ordinary USB drives can be cloned. Malware and compromised browsers can steal unlocked keys. Imported keys may still exist in other wallets. JavaScript cannot guarantee memory erasure. CSP prevents network fetches, not host compromise. Entangled Plus is planned after launch for paid monitoring and alerts. It is not active in this release and will not gate any existing local vault feature. Your recovery requires: a trusted offline client + encrypted .entb file + ENTB1 key. Test these backups before relying on them. Never discard the only working copy. Supported signing: SOL; classic SPL TransferChecked; nonce create/advance/close. Token-2022 transfers, approvals, arbitrary transactions and messages are rejected.