Most hardware wallet companies commission a security audit, publish the parts that flatter them, and move on. Keystone hired Keylabs, the firm formerly known as Wallet.fail, which is the team that stood on stage at a hacker conference and publicly broke both Trezor and Ledger devices. Then it published what they found, including a high-severity failure in the exact feature Keystone markets hardest.
That single decision tells you more about a wallet vendor than any specification sheet. It is also the reason Keystone deserves a longer look than its market share suggests.
This review covers the company's unusual origin, the three-chip architecture, what the audits actually said, the limits of its transparency claims, and one practical issue that changes the price comparison for anyone buying from Greece.
Where Keystone came from
The lineage runs through Cobo, a Chinese crypto company founded in November 2017 by Shixing "Discus Fish" Mao and Changhao Jiang, a former Facebook and Google engineer. Cobo raised roughly 13 million dollars in a 2018 Series A led by DHVC and Wu Capital. Its hardware line was Cobo Vault, launched on Indiegogo in 2018 and billed as the first "military-grade" hardware wallet, meeting the American MIL-STD-810G robustness standard. [1][2][3]
Lixin Liu was head of hardware at Cobo and led that product line. In June 2021 Cobo decided to reduce its cold storage hardware business to "minimum maintenance" so it could concentrate on centralised services, meaning no new devices would be manufactured. Liu and the original engineering team left and relaunched the product line as Keystone, keeping the same firmware platform and legacy features. Aaron Chen is chief technology officer. [4][5][6]
Liu published his reasoning at the time, and it is worth repeating because it explains the company's character. Cobo wanted to focus on Chinese users and its centralised wallet, while Cobo Vault served a mostly Western self-custody audience. He judged there was no synergy between the two and left rather than watch the product decay. [5]
Cobo still exists as an institutional custody provider headquartered in Singapore. Keystone is a separate company and should not be conflated with it. [1][7]
Where Keystone itself is based is genuinely unclear. Dealroom and one 2026 review say Hong Kong. PitchBook and CB Insights give a specific address in Minhang, Shanghai. Several reviews simply say "Asia-Pacific" and move on. The most likely reading is a Hong Kong operating entity with mainland Chinese engineering and manufacturing. [7][8][9][10]
Devices are manufactured in China, and one technically careful review frames the implication well: for most buyers this is irrelevant, but a threat model that includes a nation-state adversary should treat the sourcing jurisdiction as a deliberate decision rather than an accident. That is the fair way to present it. Report the fact, let the reader weigh it. [10][11]
Investors named across databases include Qiming Venture Partners in a mid-2022 seed round, plus Atom Capital, Hash Global, NGC Ventures and SNZ Holding. Amounts are not disclosed. In May 2023 Keystone merged with UniPass to form Account Labs, a corporate structure invisible in almost every review of the product. Employee count, revenue and valuation are not public. [8][9][12]
The product line
| Product | Type | Price |
|---|---|---|
| Keystone 3 Pro | Flagship air-gapped wallet, 4-inch touchscreen, fingerprint sensor | 126 to 169 dollars, depending on source |
| Keystone Essential | Lower-tier model | Lower |
| Keystone Tablet | Stainless steel seed backup | Sold separately |
| Bundle Pack | Wallet plus Tablet | About 223 dollars |
[6][13][14][15][16]
The Keystone 3 Pro price is genuinely inconsistent across sources. 126.65 dollars, 129, 149 and 169 all appear in 2025 and 2026 reviews. Regional pricing and promotions likely explain the spread, but it means any price quoted in an article needs a date attached. [6][13][14][15][17]
In the box: the device, a USB-C cable, a manual, six recovery seed cards and adhesive tape for concealed storage. A microSD card is not included, which several reviewers flag as an irritation given that firmware updates depend on one. The device accepts either a rechargeable pack or four AAA batteries, and the battery is detachable. [17][18]
Security architecture
The Keystone 3 Pro is fully air-gapped. No USB data connection, no Bluetooth, no Wi-Fi, no NFC. Data moves by QR code and microSD card only, and the USB-C cable carries nothing but power.
The signing flow: your companion app or software wallet builds the transaction and displays an unsigned QR code. The device scans it with its camera. You verify the details on the 4-inch screen. The device signs internally and displays a signed QR code, which the app scans back to broadcast. At no point does a data cable or radio touch the device. [11][14][19]
Three secure element chips, which Keystone markets as an industry first. The design principle is that key operations are distributed across chips rather than concentrated in one, so compromising a single chip does not unlock the wallet. Two chips protect key material; one protects fingerprint data. [14][16][20]
Here the article has to be careful, because public sources contradict each other badly. At least four incompatible accounts of the chips exist: Microchip ATECC608A plus Maxim MAX32520 plus Microchip DS28C50 in one detailed technical review; Microchip ATECC608B and Maxim DS28S60 in Keystone's own 2023 blog post; three Infineon chips with two certified at CC EAL5+ in another review; and three CC EAL6+ chips in Keystone's marketing and several reviews. One source reduces it to a single EAL6+ secure element. [11][14][16][17][20][21][22]
Do not publish a chip list or a single certification figure without checking the current official specification page. What can be stated safely is that the device uses three secure elements, that Keystone publishes secure element firmware, and that the Maxim MAX32520 appears in more than one independent source as the chip protecting fingerprint data.
Other protections: PCI-level anti-tamper self-destruct that wipes keys on physical intrusion, and device authentication that verifies the unit against supply-chain tampering, which can be re-run at any time rather than only at setup. [16][19][23]
Recovery options, and why they matter more than the chip count
This is where Keystone quietly outclasses most of the category, and it deserves proper space.
- The seed is generated on the device before any pairing with software, removing one extraction route entirely
- Random numbers are drawn from both secure elements and combined
- Dice-roll seed generation is available for users who do not trust the chips, with a documented verification method
- You can choose your own 11th or 23rd word and have the device compute the checksum word
- Up to three separate recovery phrases, each with its own password, isolated from one another
- Passphrase support as a 25th word
- Shamir Secret Sharing backup
- Standard BIP32, BIP39 and BIP44, so recovery works on any compatible wallet [16][19][20][23]
Keystone also co-authored BIP-129, the standard process for setting up Bitcoin multisig wallets securely across different protocols. That is a contribution to the commons rather than to its own product line, and very few wallet vendors can claim anything comparable. [23]
Open source, assessed honestly
Keystone publishes considerably more than its rivals: application firmware on GitHub under a permissive licence, circuit schematics, the bill of materials, the secure element firmware, and the application framework. It claims the industry's first open-source secure element firmware. [16][19][21][24]
The Keystone 3 Pro firmware was rewritten largely in Rust rather than built on Android, which Keystone argues makes it leaner, more reproducible and easier to inspect. Reproducible builds are supported, meaning a technically capable user can compile from source and verify that the result matches the firmware on their device. That is a meaningfully higher bar than "we published some code." [22][24][25]
Keystone's answer to the hidden-keys problem in open systems is neat: every device generates its own unique encryption keys at setup, so there is nothing pre-programmed to hide in published code. [24]
But "open source" is not the whole device, and the article must say so. The MH1903 microcontroller library ships as a pre-compiled binary blob because of intellectual property restrictions, and the secure element firmware belongs in part to the chip vendors. You cannot audit the entire stack line by line. Keystone itself acknowledges the vendor-imposed constraints. [11][26]
Placed against the rest of the category: Keystone is more open than Ledger, NGRAVE, Tangem and ELLIPAL, publishes more hardware documentation than almost anyone, and sits roughly level with Trezor on published code, with the important difference that Trezor's TROPIC01 opened the secure element design itself. Neither is auditable end to end.
The audits, and why they are the reason to take Keystone seriously
Keylabs, formerly Wallet.fail, audited the Keystone 3 Pro hardware. SlowMist audited the firmware. Keystone committed in advance to publishing both reports. [24][26]
The Keylabs audit found a high-severity issue relating to tamper response inadequacy, alongside two low-severity firmware issues and three low-severity hardware vulnerabilities. Keystone published this itself. The same audit also judged the wallet's tamper response a major strength that outperforms competing products, and Keystone states all issues were resolved. [27]
Consider what that means in context. Tamper response is one of the features Keystone advertises most prominently. The auditors found a high-severity flaw in it, and the company put that finding on its own blog rather than in a footnote.
Separately, Offside Labs found a firmware vulnerability that was patched in firmware version 1.2.8, with the partnership and the fix announced in January 2024. Audits by SlowMist and Least Authority across 2024 and 2025 reported no critical vulnerabilities in the firmware's cryptographic implementation. [11][22]
No public exploit, physical attack or firmware vulnerability resulting in stolen user funds has been documented against any Keystone device. [11][21][22]
And no Keystone customer data breach surfaced in this research. That is worth stating plainly, because Trezor disclosed a customer data breach on 13 August 2026 and SafePal on 16 August 2026, both exposing names, phone numbers and home addresses. The honest caveat is that Keystone's customer base is smaller, and absence of evidence in a general search is not proof of absence.
Assets, software and the real friction
Keystone supports roughly 5,500 coins and tokens across more than 200 blockchains, including Bitcoin with SegWit and Taproot, Ethereum and EVM chains, Solana, Cosmos, Sui, Aptos, Cardano, XRP, Tron and NFTs. [13][15][17][28]
There is also a Bitcoin-only firmware, released in overhauled form in April 2024, adding BlueWallet, Sparrow and Nunchuk support, Taproot through Sparrow, XPUB QR display, testnet, passphrase and Shamir backup. It minimises the code base and therefore the attack surface. The switch from multi-coin to Bitcoin-only is one-way and cannot be reversed, which the article should state clearly because buyers do get caught by it. [25][29]
Keystone was the first hardware wallet with official MetaMask integration, including MetaMask mobile, and it works with Rabby, Sparrow, BlueWallet, Solflare, OKX Wallet, Core and dozens of others. Keystone now also has its own app, Keystone Nexus. [11][15][19][30]
The main practical limitation is staking. There is no on-device staking. To stake you must move assets into a software wallet. Users also report that Keystone Nexus does not yet cover every chain the hardware supports, with DOGE, ADA, SOL, BCH and BNB named as gaps, which means juggling different third-party wallets depending on the asset. [17][30]
One structural point worth a sentence: the security of any signing session is only as good as the software wallet at the other end of the QR scan. Air-gapping the device does not air-gap the counterparty application. [11]
Recurring complaints: QR scanning is sometimes slow or fails and needs a retry, the device cannot be used while charging, battery life is unremarkable, no microSD is included, and the device is larger and heavier than most rivals. [15][17][18]
Buying one in Greece
Keystone ships worldwide to all countries from its official store, with free shipping in most regions, standard delivery around 5 to 15 days, and an express option at roughly 25 dollars extra. Payment by card, PayPal or crypto. [18][31][32]
Here is the point that changes the price comparison, and no affiliate review will make it. Keystone ships from Asia. Trezor ships from the Czech Republic and NGRAVE from Belgium, both inside the European Union. That means a Greek buyer may face import VAT plus a courier handling fee on top of the advertised price, while an equivalent Trezor arrives as an intra-EU shipment with no customs procedure.
At a similar sticker price, a Keystone 3 Pro and a Trezor Safe 5 are therefore not actually the same cost to a buyer in Athens. Verify the landed cost at checkout before you compare.
Buy from the official store, an official regional store, or an authorised reseller. The device authentication feature lets you verify your unit against supply-chain tampering on first boot, and you can repeat that check at any time. [23][31]
Not verified in this research and worth checking yourself: whether Keystone Suite offers a Greek-language interface, whether its transaction export is usable for Greek tax filing, and how warranty and returns are handled for EU customers.
Credibility
Trustpilot: 4.6 to 4.7 out of 5, from roughly 639 to 704 reviews across captures between October 2025 and August 2026. That is the highest score of any company covered in this entire series, exchanges included. [30][33][34]
Positive themes: the air-gapped QR system inspiring confidence, the 4-inch touchscreen making transaction verification genuinely easier than on Ledger or Trezor, build quality, managing multiple wallets on one device, responsive support with the company replying to reviews, and the steel Tablet backup product. [30][33][34]
Negative themes: coin gaps in Keystone Nexus, having to use different software wallets depending on the asset, slow shipping in some cases, fiddly PIN entry on the touchscreen, and battery design. Notice what is missing from that list: the complaints are about convenience, not about trust. [30][33]
One honest reservation for balance, from a Bitcoin-focused reviewer: the brand is smaller than Trezor or Ledger, which means fewer independent eyes on it despite the published audits, and multi-coin support means a larger attack surface than a Bitcoin-only device would have. [21][35]
How it compares
| Wallet | Air-gapped | Secure elements | Firmware open | Reproducible builds | Price |
|---|---|---|---|---|---|
| Keystone 3 Pro | Yes, QR and microSD | Three | Yes, MCU blob excepted | Yes | 129 to 169 dollars |
| Trezor Safe 5 | No, USB | One, EAL6+ | Yes | Yes | About 129 dollars |
| Trezor Safe 7 | No, USB and Bluetooth | Three | Yes | Yes | About 249 dollars |
| NGRAVE ZERO | Yes, QR | One, EAL5+ with EAL7 OS | No | No | About 398 dollars |
| ELLIPAL Titan 2.0 | Yes, QR | One, EAL5+ | No | No | 149 to 169 dollars |
| SafePal S1 | Yes, QR | One | Partial | No | About 50 dollars |
| Tangem | No, NFC | One, EAL6+ | No | No | About 55 dollars |
| Foundation Passport | Yes, QR | Yes | Yes | Yes | About 199 dollars |
| Blockstream Jade Plus | Optional QR | Varies | Fully open | Yes | About 65 dollars |
[11][13][14][19]
Among air-gapped wallets, Keystone is the usability pick. It has the largest screen and the broadest software-wallet compatibility in the category. NGRAVE beats it on isolation marketing and loses badly on openness and price. SafePal beats it on price and loses on transparency and screen size. ELLIPAL matches the air gap and the price but has no published audit and closed firmware.
The one rival Keystone cannot answer is Foundation Passport, which offers the same air-gapped QR signing, open firmware and a non-Chinese supply chain. If jurisdiction is part of your threat model, that is the comparison to make.
The risks, stated plainly
- Import VAT and customs. Shipping from Asia, not from inside the EU. Calculate the landed cost.
- Jurisdiction. Hong Kong entity, Chinese manufacturing. Irrelevant for most threat models, a deliberate choice for some.
- Chip documentation is inconsistent across public sources, and Keystone has not made the part list unambiguous in its marketing.
- Open source is not total. The microcontroller library ships as a binary blob.
- No on-device staking, and the in-house app does not cover every supported chain.
- QR signing adds friction. Fine for monthly rebalancing, tiring for daily DeFi.
- The Bitcoin-only firmware switch is irreversible.
- Your signing session is only as safe as the software wallet scanning the QR at the other end.
- Smaller community than Trezor or Ledger means fewer independent eyes, even with published audits.
What we could not verify
Deliberately absent above, because public sources did not support it: whether the operating entity is in Hong Kong or Shanghai and the current corporate relationship with Account Labs; employee count, revenue, profitability and funding amounts; the definitive secure element part numbers and certification tiers; the current Keystone 3 Pro price; whether Keystone operates a public bug bounty; import VAT and customs treatment for Greek buyers; Greek-language interface and tax export; warranty and returns handling for EU customers; and whether any Keystone customer data breach has ever occurred.
Frequently asked questions
Has Keystone ever been hacked? No public exploit or physical attack resulting in stolen user funds has been documented. Auditors found issues, including one high-severity tamper-response flaw, and Keystone published and fixed them.
Is Keystone more secure than a Trezor or a Ledger? For supply-chain and connection-based attacks, materially yes. No USB data connection means no malicious firmware pushed over a cable, and three secure elements mean a single chip compromise does not unlock the wallet. For user-error risks such as a lost seed or a compromised PIN, the device is not the bottleneck, and no wallet is.
Does the air gap slow things down? Yes. For active DeFi with several transactions a day, the friction is noticeable against a USB device. For monthly rebalancing or long-term holding, it barely matters, and individual signings take roughly 15 to 30 seconds once you are set up.
Can I stake directly on the device? No. You must move assets to a software wallet to stake, then move them back.
Should I switch to the Bitcoin-only firmware? Only if you are certain. It reduces the code base and the attack surface, which is a real security benefit, but the change cannot be reversed.
What should I check before buying from Greece? The landed cost. Keystone ships from Asia, so import VAT and a handling fee may apply, unlike a Trezor shipped from within the EU. At similar sticker prices the real costs differ.
Sources
All accessed 19 August 2026.
- businessmodelcanvastemplate, "Brief History of Cobo", Mar 2026
- Bitcoin UK, "Cobo, Creator of the First Military-Grade Hardware Crypto Wallet, Raises $13 Million", Nov 2018
- Cobo, "About Cobo"
- Keystone blog, "Keystone: Who we are"
- Keystone blog, "Leaving Cobo to continue the Cobo Vault legacy", 1 Jun 2021
- CaptainAltcoin, "Keystone Wallet Review"
- Tracxn, Cobo company profile, Jun 2026
- PitchBook, Keystone Hardware Wallet company profile
- CB Insights, Keystone company profile
- Dealroom, Keystone profile
- State of Surveillance, "Keystone 3 Pro Review 2026: Air-Gapped, Multichain, Made in China"
- 99bitcoins, "Keystone Pro Wallet Review"
- ICOBench, "Keystone Wallet Review"
- snout0x, "Keystone 3 Pro Review 2026", Apr 2026
- Coinweb, "Keystone Wallet Review"
- Blockdyor, "Keystone 3 Pro Review", Dec 2025
- hardwarewallets.net, "Keystone 3 Pro Review 2026", Jun 2026
- hardware-wallets.net, "Keystone 3 Pro Review"
- Token Tool Hub, "Keystone Wallet Review", Dec 2025
- Keystone blog, "Secure Elements: The Bedrock of Hardware Wallet Security"
- bestcrypto-wallet.com, "Keystone 3 Pro Crypto Wallet Review"
- Bitget Academy, "Is Keystone Wallet Safe?", Mar 2026
- Keystone, Keystone 3 Pro product page, keyst.one
- Keystone blog, "Open Source, Fully Verified: Inside the Philosophy Behind Keystone 3 Pro"
- Nasdaq and Bitcoin Magazine, "Crypto wallet maker Keystone debuts bitcoin-only firmware for flagship device", Apr 2024
- Keystone blog, "The Role of Open Source Tech in Keystone's Development"
- Keystone blog, "Deep Dive into Next-Gen Hardware Wallet: Crashing Keystone3 Pro Audit"
- Keystone, "Supported Coins & Wallets"
- Cypherock blog, "Keystone 3 Pro Review 2026" (competitor-authored)
- Trustpilot, keyst.one reviews, page 5
- Keystone, "Shipping Regions"
- Keystone homepage, keyst.one
- Trustpilot, keyst.one reviews, main page
- Trustpilot, keyst.one reviews, page 3
- BitcoinerReviews, "Keystone 3 Pro"
Πληροφοριακό υλικό μόνο. Δεν αποτελεί επενδυτική συμβουλή. Η αγορά κρυπτονομισμάτων ενέχει υψηλό κίνδυνο.
Information only. Not investment advice. Cryptocurrency markets carry substantial risk.