Privy is a strong default for consumer embedded wallets and now for agent wallets too. People look for alternatives when they need every policy enforced inside the trusted boundary, a human escalation path, a root they hold themselves, or simply a vendor that is not Stripe. Here are the options.
| Who holds the root key | Policy | Cold root | Pricing | |
|---|---|---|---|---|
| Coldstar | You; encrypted on your own drive | Limits, allowlists, daily cap, escalate to human | Yes | Free |
| Turnkey | Turnkey-operated enclaves | Rich Solana instruction rules; no daily caps | No | 25 free signatures/mo, then $0.10 |
| Crossmint | Owner: you. Agent key: Crossmint TEE | On-chain limits and rolling caps | Owner key could be | Free to 1,000 active wallets |
| Coinbase CDP Wallets | Coinbase Nitro enclaves | Per-transaction Solana rules | No | $0.005 per op; 5,000 free/mo |
| Openfort | Openfort TEE on Google Cloud | Solana rules incl. Anchor IDL checks | No | 2,000 ops free, then $0.01 |
| Para | 2-of-2 MPC: device + Para HSM | Scopes, default deny; API layer | No | Free to 1,200 MAU |
| Magic | Magic Nitro enclaves | None documented | No | Free to 1,000 active wallets |
| Web3Auth | Reconstructed on the client at login | None documented | No | Free to 1,000 active wallets |
Short cells; the linked pages carry the detail and the sources. Coldstar is beta software with an independent audit planned before its production release, and that is stated on every page.
Privy describes itself as non-custodial: the key is split with Shamir's Secret Sharing and only recombined inside its TEE, and it says it cannot sign alone. The key material lives on Privy-operated infrastructure.
Turnkey, Coinbase CDP, Openfort, Crossmint, Para, and Coldstar. Magic and Web3Auth do not document transaction policies.
Coldstar. The root is an encrypted file on a drive you hold, used offline.
Open source, MIT. macOS, Linux, Windows — and on the Solana Seeker dApp Store.
pip install coldstar