Skip to content
Crypto Almanac Daily
K
Hardware Wallets

Keystone

Best for verifiable firmware openness

Firmware repository:PublicSecurity or spec page:PublishedDocumentation:OpenVendor:KeystoneRubric:v2.0 · verified 9 Aug 2026
Last verified August 9, 2026
Confidence ARubric v2.0Verified August 9, 2026
8.0
out of 10
Open account
Scorecard

How it rates

Key security & openness · 40%8.0
Purchase transparency · 10%8.0
Product openness · 20%10.0
Vendor transparency · 20%6.0
Public documentation surface · 10%8.0
Pros
  • Firmware source published in a public repository
  • Device security or specification page published
  • Technical documentation reachable without an account
Cons
  • No dedicated security or audit disclosure identified at this check
  • Terms page not found at the conventional address at this check
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Key security & openness · 40% weight8/10 points · 8.0/10
  • Met
    Firmware source published in a public repository

    Vendor repository reachable at this check.

    github.com/KeystoneHQ
  • Met
    Device security or specification page published

    Security or specification page reachable at this check.

    keyst.one/
  • Not met
    Independent security research or audit programme published

    No published security research or audit programme identified at this check.

  • Met
    Technical documentation reachable without an account

    Documentation open at this check.

    support.keyst.one/
  • Met
    Vendor organisation identifiable from the repository

    Repository published under the vendor organisation (Keystone).

    github.com/KeystoneHQ
Purchase transparency · 10% weight8/10 points · 8.0/10
  • Met
    Shop or purchase page public

    Reachable without an account at this check.

    keyst.one/shop
  • Met
    Model-specific product page public

    Model page reachable at this check.

    keyst.one/
  • Not met
    Legal or terms page public

    Not found at the conventional address at this check.

  • Met
    Support or help resource public

    Reachable at this check.

    support.keyst.one/
  • Met
    Purchase information viewable without an account

    No account required to reach the shop at this check.

    keyst.one/shop
Product openness · 20% weight10/10 points · 10.0/10
  • Met
    Public repository organisation

    Vendor organisation public.

    github.com/KeystoneHQ
  • Met
    Firmware repository is the vendor's own

    Repository published by the vendor.

    github.com/KeystoneHQ
  • Met
    Model documentation published

    Model documentation reachable.

    keyst.one/
  • Met
    Documentation site separate from marketing

    Dedicated documentation or support resource published.

    support.keyst.one/
  • Met
    Security posture stated publicly

    Security claims published on a reachable page.

    keyst.one/
Vendor transparency · 20% weight6/10 points · 6.0/10
  • Met
    Vendor site resolves to automated verification

    HTTP 2xx at this check.

    keyst.one/shop
  • Met
    Vendor entity identifiable

    Vendor organisation identifiable as Keystone.

    github.com/KeystoneHQ
  • Not met
    Security or disclosure page published

    Not identified at this check.

  • Not met
    Terms or legal documentation published

    Not found at the conventional address at this check.

  • Met
    Product range documented publicly

    Product information published.

    keyst.one/
Public documentation surface · 10% weight8/10 points · 8.0/10
  • Met
    Root site reachable without an account

    HTTP 2xx at this check.

    keyst.one/shop
  • Met
    Documentation or support reachable

    HTTP 2xx at this check.

    support.keyst.one/
  • Met
    Public code repository reachable

    HTTP 2xx at this check.

    github.com/KeystoneHQ
  • Met
    Shop reachable

    HTTP 2xx at this check.

    keyst.one/shop
  • Not met
    Legal documentation reachable

    Not found at the conventional address at this check.

An air-gapped multi-chain wallet isolating keys across three secure elements, with QR-only signing and a screen large enough to review contract calls.

Our assessment

Keystone 3 Pro isolates keys across three separate secure-element chips and signs every transaction by QR code — no Bluetooth, no Wi-Fi, no NFC, and a charging port that carries power only. Its 4-inch touchscreen makes it one of the few air-gapped devices where reviewing a complex contract call is actually practical.

Three chips, and a self-destruct

The design splits key material across a Microchip ATECC608A, a Maxim MAX32520 and a Microchip DS28C50, with anti-tamper circuitry that wipes the seed on physical intrusion. Redundancy across vendors is the same reasoning Coldcard applies with two chips, taken one step further.

The screen is a security feature

Most air-gapped devices force you to verify a long address on a small display, which is precisely where users stop checking carefully. A 4-inch screen showing a full address and a readable breakdown of a contract interaction removes the most common reason people approve something they did not intend to.

What is not published

The firmware and hardware designs are on GitHub, but the main MCU library and the secure-element firmware are not. The company is a Hong Kong entity manufacturing in China, which is a supply-chain consideration for a strict threat model rather than a defect. Our openness indicators record the published parts and the gaps alike.

Who it suits

Keystone fits multi-chain users who want air-gapped signing without giving up readable transaction review — particularly people interacting with DeFi from cold storage. Buyers who require every component to be open should look at Trezor, BitBox or Blockstream Jade.

Alternatives

How rivals compare

ServiceScoreBest for
Trezor9.9verifiable firmware opennessRead →
Reference

Frequently asked

Does this score mean Keystone is secure?

No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.

Why does firmware openness matter so much here?

It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.

What would raise this score?

Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.