Trading Education Platform SystemSubscribe for FreeSupport
Wallets / Keystone 3 Pro
HARDWARE WALLET REALITY CHECK · READ 11 OCT 2026

Keystone 3 Pro: what the sources say

Current 2 disclosed weaknesses 0 company incidents

Key facts

The questions, with sources

QuestionWhat the sources saySource
Status
Current — Listed as a current product on the official store on 2026-10-11; no successor named on the page.
Company
Yanssie HK Limited (per third-party compilation; official site shows only 'Keystone' with a Hong Kong address), Hong Kong
List price
$149 — Official store shows $149.00 (USD sign; currency not explicitly stated). No EUR price or EU shipping terms shown. Bundles higher.
Secure element
Yes: 3 chips: Microchip ATECC608B, Maxim DS28S60, Maxim MAX32520 (secure MCU for fingerprint data)
Firmware code
Partial (MIT (per third-party compilation citing the repo LICENSE file; GitHub README page read does not name it)); reproducible build: not verified. MH1903 vendor library is a precompiled binary; fingerprint secure element code not in the repo. A Docker-based verification guide compares a locally built hash to the hash shown on the device; the guide does not claim bit-for-bit reproducibility of the signed release.
Companion app
Not verified. Not verified. Keystone's mobile/companion apps were not checked; the device itself is air-gapped and pairs with third-party software wallets.
—
Connections
USB: USB-C (not confirmed on the product page read; USB path discussed in the 2026 vulnerability write-up). Bluetooth: no (not listed). NFC: no (not listed). QR: yes. microSD: yes.
Screen
4-inch full-colour touchscreen; touch: yes
Assets
5,500+ assets (product page); Coin Bureau reports 5,500+ coins/tokens on 200+ blockchains; Bitcoin-only option: yes (BTC-only page linked; Coin Bureau states a Bitcoin-only firmware exists; not confirmed in detail for the 3 Pro)
Multisig and PSBT
Yes. Product page lists multisig; PSBT handling not separately verified.
Passphrase
Yes. Passphrase (25th word) listed.
Shamir backup (SLIP-39)
Yes. Shamir backup listed; SLIP39 mentioned on the page.
Recovery phrase standard
BIP39 (with SLIP39 Shamir option); dice entropy listed
Optional recovery service
Not verified. No paid recovery service found on the pages read.
—
FIDO / passkeys
Not verified. Not verified.
—
Bug bounty
Yes
Warranty
Warranty terms not found on pages read (footer links to Refund and Shipping policies, not opened).
—

"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.

Summary

Five facts

  • The Keystone 3 Pro is an air-gapped hardware wallet with a 4-inch touchscreen, fingerprint sensor and three secure-element chips (ATECC608B, DS28S60, MAX32520), listed at $149 on the official store [source 1][source 4].
  • The firmware repository is public on GitHub, but a vendor MCU library is a precompiled binary and the fingerprint secure-element code is not in the repo [source 5].
  • Security partners listed by Keystone are Offside Labs, BlockSec, SlowMist and Keylabs; a Keylabs audit dated November 2023 covered the Keystone 3 Pro [source 2][source 8].
  • A USB SDK vulnerability affecting firmware below v2.4.0, disclosed jointly with OneKey ANZEN in 2026, requires physical access and was fixed in v2.4.0 according to the write-up [source 10].
  • Keystone runs a bug bounty program for hardware and firmware, paid in Bitcoin, with no published reward amounts [source 3].
Independent checks

Audits

  • 2023-09 SlowMist. Scope: Listed as security partner; scope not stated by Keystone source
  • 2023-11 Keylabs. Scope: Keystone 3 Pro hardware and firmware; per vendor blog 1 high (tamper response, marked fixed/verified by third-party compilation), 2 low firmware, 3 low hardware findings source
  • date n/v Offside Labs. Scope: Firmware review of Keystone 3 Pro; one vulnerability found, addressed in firmware v1.2.8 (per Keystone blog) source
  • 2025-03 Least Authority. Scope: Keystone hardware wallet code for Zcash (commissioned by Zcash Community Grants); not whole-device source
Device record

Publicly disclosed weaknesses

  • 2026-03 USB SDK (MCU vendor library) unchecked host-controlled lengths allowed out-of-bounds read/write escalating to code execution; authors state it could be chained to extract BIP39 mnemonic. Disclosed by OneKey ANZEN research team during a joint audit with Keystone (OneKey is a competing wallet maker; joint announcement per the write-up). Requires physical possession, correct PIN, unlocked device, user approval of USB connection and connection to attacker-controlled computer. Affects firmware below v2.4.0; air-gapped QR signing avoids the USB path. No real-world attacks found as of announcement. Funds lost: no. Fixed source
  • 2023-11 Keylabs audit: 3 low-severity hardware findings reported as not fixed in the third-party compilation of the report; high-severity tamper-response finding marked fixed and verified. Report PDF itself not read. Funds lost: no. Fix status not verified source

Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.

Company record

Incidents at the maker or its service providers

  • No company incident found in our search.

These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.

Questions

Questions about Keystone 3 Pro

Is Keystone 3 Pro safe?

We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 2 publicly disclosed weaknesses and 0 company incidents in our search. Read the sources above before you buy.

Does Keystone 3 Pro need an internet connection?

Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB, QR. The companion app or software that builds the transaction is online.

Who found the weaknesses listed for Keystone 3 Pro?

The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.

Sources

Where this comes from

Not verified: No EAL/CC certification stated by Keystone. Legal entity name taken from a third-party PR, not an official page. EUR price, warranty, app open-source status, passkeys, recovery service not verified. Keylabs/SlowMist/Offside reports not read directly (vendor blog and third-party summaries only). Official GitHub firmware license name not read directly. blog.keyst.one open-source philosophy post blocked by robots.txt. No company incidents (breach, supply chain) found in the limited searches; absence not proven.

See how we check. To report an error, use corrections and right of reply.