Skip to content
Crypto Almanac Daily
O
Hardware Wallets

OneKey

Best for verifiable firmware openness

Firmware repository:PublicSecurity or spec page:PublishedDocumentation:OpenVendor:OneKeyRubric:v2.0 · verified 9 Aug 2026
Last verified August 9, 2026
Confidence ARubric v2.0Verified August 9, 2026
8.0
out of 10
Open account
Scorecard

How it rates

Key security & openness · 40%8.0
Purchase transparency · 10%8.0
Product openness · 20%10.0
Vendor transparency · 20%6.0
Public documentation surface · 10%8.0
Pros
  • Firmware source published in a public repository
  • Device security or specification page published
  • Technical documentation reachable without an account
Cons
  • No dedicated security or audit disclosure identified at this check
  • Terms page not found at the conventional address at this check
How this score was built

Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.

Key security & openness · 40% weight8/10 points · 8.0/10
  • Met
    Firmware source published in a public repository

    Vendor repository reachable at this check.

    github.com/OneKeyHQ
  • Met
    Device security or specification page published

    Security or specification page reachable at this check.

    onekey.so/products/onekey-pro-hardware-wallet
  • Not met
    Independent security research or audit programme published

    No published security research or audit programme identified at this check.

  • Met
    Technical documentation reachable without an account

    Documentation open at this check.

    onekey.so/products/onekey-pro-hardware-wallet
  • Met
    Vendor organisation identifiable from the repository

    Repository published under the vendor organisation (OneKey).

    github.com/OneKeyHQ
Purchase transparency · 10% weight8/10 points · 8.0/10
Product openness · 20% weight10/10 points · 10.0/10
Vendor transparency · 20% weight6/10 points · 6.0/10
  • Met
    Vendor site resolves to automated verification

    HTTP 2xx at this check.

    onekey.so/
  • Met
    Vendor entity identifiable

    Vendor organisation identifiable as OneKey.

    github.com/OneKeyHQ
  • Not met
    Security or disclosure page published

    Not identified at this check.

  • Not met
    Terms or legal documentation published

    Not found at the conventional address at this check.

  • Met
    Product range documented publicly

    Product information published.

    onekey.so/products/onekey-pro-hardware-wallet
Public documentation surface · 10% weight8/10 points · 8.0/10

A multi-chain wallet with four EAL6+ secure elements from different manufacturers, reproducible open-source builds and an independent security audit.

Our assessment

OneKey Pro carries four EAL6+ certified secure elements from different manufacturers, so compromising any single chip is not enough to expose a key. Its firmware and companion apps are open source with reproducible builds, and it has been independently audited by SlowMist.

Chip redundancy taken further than anyone here

Coldcard uses two secure elements; Keystone uses three; OneKey uses four, sourced across vendors. The reasoning is the same in each case — a certification is a statement about a chip family, not a guarantee about a specific part — and OneKey applies it most aggressively. Whether four is meaningfully better than two is arguable; that the design assumes chips fail is not.

Open source, reproducible builds and an outside audit

Firmware and apps are published with reproducible builds, and the SlowMist audit means the code has been examined by someone with no incentive to be kind about it. That combination — open code, verifiable binaries, external review — is what our openness pillar is built to reward, and few multi-chain devices produce all three.

Air-gap plus convenience, in one device

The Pro supports air-gapped QR signing alongside Bluetooth and USB-C, with fingerprint unlock and a 3.5-inch touchscreen. Offering both is a usability decision rather than a security one: every additional interface is additional attack surface, and buyers who want isolation should use the QR path and leave the radios off.

Who it suits

OneKey fits multi-chain users who want auditable code and chip-level redundancy without giving up a modern interface. Buyers who want no radio hardware present at all should choose Foundation Passport, Coldcard or Keystone.

Alternatives

How rivals compare

ServiceScoreBest for
Trezor9.9verifiable firmware opennessRead →
Reference

Frequently asked

Does this score mean OneKey is secure?

No. It measures what a buyer can verify before purchase: published firmware source, documented security claims, and open documentation. Physical security is not tested by us and is not scored.

Why does firmware openness matter so much here?

It is the one substantive security property an outsider can check without specialist equipment. Everything else on a hardware wallet requires trusting the vendor or a third-party teardown.

What would raise this score?

Publishing firmware source, a dedicated security or audit page, and open technical documentation at stable public addresses — all of which are checkable by anyone.