Skip to content
Crypto Almanac Daily
F
Hardware Wallets

Foundation Passport

Best for verifiable firmware openness

Firmware repository:PublicSecurity or spec page:PublishedDocumentation:OpenVendor:Foundation DevicesRubric:v2.0 · verified 9 Aug 2026
Last verified August 9, 2026
Confidence ARubric v2.0Verified August 9, 2026
8.0
out of 10
Open account
Scorecard

How it rates

Key security & openness · 40%8.0
Purchase transparency · 10%8.0
Product openness · 20%10.0
Vendor transparency · 20%6.0
Public documentation surface · 10%8.0
Pros
  • Firmware source published in a public repository
  • Device security or specification page published
  • Technical documentation reachable without an account
Cons
  • No dedicated security or audit disclosure identified at this check
  • Terms page not found at the conventional address at this check
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Key security & openness · 40% weight8/10 points · 8.0/10
  • Met
    Firmware source published in a public repository

    Vendor repository reachable at this check.

    github.com/Foundation-Devices
  • Met
    Device security or specification page published

    Security or specification page reachable at this check.

    foundation.xyz/passport/
  • Not met
    Independent security research or audit programme published

    No published security research or audit programme identified at this check.

  • Met
    Technical documentation reachable without an account

    Documentation open at this check.

    docs.foundation.xyz/
  • Met
    Vendor organisation identifiable from the repository

    Repository published under the vendor organisation (Foundation Devices).

    github.com/Foundation-Devices
Purchase transparency · 10% weight8/10 points · 8.0/10
  • Met
    Shop or purchase page public

    Reachable without an account at this check.

    foundation.xyz/
  • Met
    Model-specific product page public

    Model page reachable at this check.

    foundation.xyz/passport/
  • Not met
    Legal or terms page public

    Not found at the conventional address at this check.

  • Met
    Support or help resource public

    Reachable at this check.

    docs.foundation.xyz/
  • Met
    Purchase information viewable without an account

    No account required to reach the shop at this check.

    foundation.xyz/
Product openness · 20% weight10/10 points · 10.0/10
Vendor transparency · 20% weight6/10 points · 6.0/10
  • Met
    Vendor site resolves to automated verification

    HTTP 2xx at this check.

    foundation.xyz/
  • Met
    Vendor entity identifiable

    Vendor organisation identifiable as Foundation Devices.

    github.com/Foundation-Devices
  • Not met
    Security or disclosure page published

    Not identified at this check.

  • Not met
    Terms or legal documentation published

    Not found at the conventional address at this check.

  • Met
    Product range documented publicly

    Product information published.

    foundation.xyz/passport/
Public documentation surface · 10% weight8/10 points · 8.0/10

A Bitcoin-only air-gapped signer with open hardware and firmware, assembled in the United States, working through QR codes and microSD only.

Our assessment

Foundation Passport Core is a Bitcoin-only air-gapped signer with a keypad and camera. There is no Bluetooth, no Wi-Fi, no NFC, and the USB-C port carries power only — everything in or out goes through a QR code or the microSD slot. Hardware and firmware are both open source, and the device is assembled in the United States.

Air-gapped without qualification

Several devices marketed as air-gapped keep a USB data path available. Passport does not — the physical design removes the option rather than defaulting it off. Combined with open hardware schematics, this is one of the few devices where the isolation claim can be checked rather than taken on trust.

Supply chain as a stated position

US assembly and published hardware designs answer the question most hardware wallet buyers cannot otherwise resolve: who built this, and could something have been added along the way. It does not eliminate supply-chain risk, but it makes the chain shorter and inspectable, which is more than most competitors offer.

It expects you to bring your own wallet

Passport works through PSBTs with Bitcoin Core, Sparrow, Specter, Nunchuk, BlueWallet, Casa, Electrum and BTCPay, alongside its own Envoy app with built-in Tor. That breadth means the device is a signer rather than an ecosystem, and it will outlive any single companion app.

Who it suits

Passport fits Bitcoin-only holders who want open hardware, genuine air-gapping and a Western supply chain, and who are comfortable with QR and microSD workflows. Multi-chain users are in the wrong category — look at Keystone, OneKey or Trezor.

Alternatives

How rivals compare

ServiceScoreBest for
Trezor9.9verifiable firmware opennessRead →
Reference

Frequently asked

Does this score mean Foundation Passport is secure?

No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.

Why does firmware openness matter so much here?

It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.

What would raise this score?

Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.