Keystone
Best for verifiable firmware openness
How it rates
- Firmware source published in a public repository
- Device security or specification page published
- Technical documentation reachable without an account
- No dedicated security or audit disclosure identified at this check
- Terms page not found at the conventional address at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetFirmware source published in a public repository
Vendor repository reachable at this check.
github.com/KeystoneHQ - MetDevice security or specification page published
Security or specification page reachable at this check.
keyst.one/ - Not metIndependent security research or audit programme published
No published security research or audit programme identified at this check.
- MetTechnical documentation reachable without an account
Documentation open at this check.
support.keyst.one/ - MetVendor organisation identifiable from the repository
Repository published under the vendor organisation (Keystone).
github.com/KeystoneHQ
- Met
- Met
- Not metLegal or terms page public
Not found at the conventional address at this check.
- Met
- MetPurchase information viewable without an account
No account required to reach the shop at this check.
keyst.one/shop
- Met
- Met
- Met
- MetDocumentation site separate from marketing
Dedicated documentation or support resource published.
support.keyst.one/ - Met
- Met
- Met
- Not metSecurity or disclosure page published
Not identified at this check.
- Not metTerms or legal documentation published
Not found at the conventional address at this check.
- Met
- Met
- Met
- Met
- Met
- Not metLegal documentation reachable
Not found at the conventional address at this check.
An air-gapped multi-chain wallet isolating keys across three secure elements, with QR-only signing and a screen large enough to review contract calls.
Our assessment
Keystone 3 Pro isolates keys across three separate secure-element chips and signs every transaction by QR code — no Bluetooth, no Wi-Fi, no NFC, and a charging port that carries power only. Its 4-inch touchscreen makes it one of the few air-gapped devices where reviewing a complex contract call is actually practical.
Three chips, and a self-destruct
The design splits key material across a Microchip ATECC608A, a Maxim MAX32520 and a Microchip DS28C50, with anti-tamper circuitry that wipes the seed on physical intrusion. Redundancy across vendors is the same reasoning Coldcard applies with two chips, taken one step further.
The screen is a security feature
Most air-gapped devices force you to verify a long address on a small display, which is precisely where users stop checking carefully. A 4-inch screen showing a full address and a readable breakdown of a contract interaction removes the most common reason people approve something they did not intend to.
What is not published
The firmware and hardware designs are on GitHub, but the main MCU library and the secure-element firmware are not. The company is a Hong Kong entity manufacturing in China, which is a supply-chain consideration for a strict threat model rather than a defect. Our openness indicators record the published parts and the gaps alike.
Who it suits
Keystone fits multi-chain users who want air-gapped signing without giving up readable transaction review — particularly people interacting with DeFi from cold storage. Buyers who require every component to be open should look at Trezor, BitBox or Blockstream Jade.
How rivals compare
| Service | Score | Best for | |
|---|---|---|---|
| Trezor | 9.9 | verifiable firmware openness | Read → |
Frequently asked
Does this score mean Keystone is secure?
No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.
Why does firmware openness matter so much here?
It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.
What would raise this score?
Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.