My main concern is beta units seem to be going out, but source code is nowhere to be found.
I am sure they are cooking something behind the scenes

Not that I like anything about Bitkey, except maybe unusual hexagonal shape.
My main concern is that even if we get the source code, we will see that the device is an insecure privacy nightmare, due to the software and hardware architecture they chose: no screen, server-side verification of addresses, and more. There is no way that (open-source or not) code will solve these glaring issues.
Perfect scenario for disaster, but people some people probably decided to blindly trust Jack and his team.
