OneKey
Best for verifiable firmware openness
How it rates
- Firmware source published in a public repository
- Device security or specification page published
- Technical documentation reachable without an account
- No dedicated security or audit disclosure identified at this check
- Terms page not found at the conventional address at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetFirmware source published in a public repository
Vendor repository reachable at this check.
github.com/OneKeyHQ - MetDevice security or specification page published
Security or specification page reachable at this check.
onekey.so/products/onekey-pro-hardware-wallet - Not metIndependent security research or audit programme published
No published security research or audit programme identified at this check.
- MetTechnical documentation reachable without an account
Documentation open at this check.
onekey.so/products/onekey-pro-hardware-wallet - MetVendor organisation identifiable from the repository
Repository published under the vendor organisation (OneKey).
github.com/OneKeyHQ
- Met
- MetModel-specific product page public
Model page reachable at this check.
onekey.so/products/onekey-pro-hardware-wallet - Not metLegal or terms page public
Not found at the conventional address at this check.
- MetSupport or help resource public
Reachable at this check.
onekey.so/products/onekey-pro-hardware-wallet - MetPurchase information viewable without an account
No account required to reach the shop at this check.
onekey.so/
- Met
- Met
- MetModel documentation published
Model documentation reachable.
onekey.so/products/onekey-pro-hardware-wallet - MetDocumentation site separate from marketing
Dedicated documentation or support resource published.
onekey.so/products/onekey-pro-hardware-wallet - MetSecurity posture stated publicly
Security claims published on a reachable page.
onekey.so/products/onekey-pro-hardware-wallet
- Met
- Met
- Not metSecurity or disclosure page published
Not identified at this check.
- Not metTerms or legal documentation published
Not found at the conventional address at this check.
- MetProduct range documented publicly
Product information published.
onekey.so/products/onekey-pro-hardware-wallet
- Met
- MetDocumentation or support reachable
HTTP 2xx at this check.
onekey.so/products/onekey-pro-hardware-wallet - Met
- Met
- Not metLegal documentation reachable
Not found at the conventional address at this check.
A multi-chain wallet with four EAL6+ secure elements from different manufacturers, reproducible open-source builds and an independent security audit.
Our assessment
OneKey Pro carries four EAL6+ certified secure elements from different manufacturers, so compromising any single chip is not enough to expose a key. Its firmware and companion apps are open source with reproducible builds, and it has been independently audited by SlowMist.
Chip redundancy taken further than anyone here
Coldcard uses two secure elements; Keystone uses three; OneKey uses four, sourced across vendors. The reasoning is the same in each case — a certification is a statement about a chip family, not a guarantee about a specific part — and OneKey applies it most aggressively. Whether four is meaningfully better than two is arguable; that the design assumes chips fail is not.
Open source, reproducible builds and an outside audit
Firmware and apps are published with reproducible builds, and the SlowMist audit means the code has been examined by someone with no incentive to be kind about it. That combination — open code, verifiable binaries, external review — is what our openness pillar is built to reward, and few multi-chain devices produce all three.
Air-gap plus convenience, in one device
The Pro supports air-gapped QR signing alongside Bluetooth and USB-C, with fingerprint unlock and a 3.5-inch touchscreen. Offering both is a usability decision rather than a security one: every additional interface is additional attack surface, and buyers who want isolation should use the QR path and leave the radios off.
Who it suits
OneKey fits multi-chain users who want auditable code and chip-level redundancy without giving up a modern interface. Buyers who want no radio hardware present at all should choose Foundation Passport, Coldcard or Keystone.
How rivals compare
| Service | Score | Best for | |
|---|---|---|---|
| Trezor | 9.9 | verifiable firmware openness | Read → |
Frequently asked
Does this score mean OneKey is secure?
No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.
Why does firmware openness matter so much here?
It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.
What would raise this score?
Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.