Keystone 3 Pro: what the sources say
Current 2 disclosed weaknesses 0 company incidents
The questions, with sources
"n/v" or "not verified" means we could not confirm it from a source we could read. Maker claims are marked as such. Confirm on the maker's site before you buy. Education only, not investment advice.
Five facts
- The Keystone 3 Pro is an air-gapped hardware wallet with a 4-inch touchscreen, fingerprint sensor and three secure-element chips (ATECC608B, DS28S60, MAX32520), listed at $149 on the official store [source 1][source 4].
- The firmware repository is public on GitHub, but a vendor MCU library is a precompiled binary and the fingerprint secure-element code is not in the repo [source 5].
- Security partners listed by Keystone are Offside Labs, BlockSec, SlowMist and Keylabs; a Keylabs audit dated November 2023 covered the Keystone 3 Pro [source 2][source 8].
- A USB SDK vulnerability affecting firmware below v2.4.0, disclosed jointly with OneKey ANZEN in 2026, requires physical access and was fixed in v2.4.0 according to the write-up [source 10].
- Keystone runs a bug bounty program for hardware and firmware, paid in Bitcoin, with no published reward amounts [source 3].
Audits
- 2023-09 SlowMist. Scope: Listed as security partner; scope not stated by Keystone source
- 2023-11 Keylabs. Scope: Keystone 3 Pro hardware and firmware; per vendor blog 1 high (tamper response, marked fixed/verified by third-party compilation), 2 low firmware, 3 low hardware findings source
- date n/v Offside Labs. Scope: Firmware review of Keystone 3 Pro; one vulnerability found, addressed in firmware v1.2.8 (per Keystone blog) source
- 2025-03 Least Authority. Scope: Keystone hardware wallet code for Zcash (commissioned by Zcash Community Grants); not whole-device source
Publicly disclosed weaknesses
- 2026-03 USB SDK (MCU vendor library) unchecked host-controlled lengths allowed out-of-bounds read/write escalating to code execution; authors state it could be chained to extract BIP39 mnemonic. Disclosed by OneKey ANZEN research team during a joint audit with Keystone (OneKey is a competing wallet maker; joint announcement per the write-up). Requires physical possession, correct PIN, unlocked device, user approval of USB connection and connection to attacker-controlled computer. Affects firmware below v2.4.0; air-gapped QR signing avoids the USB path. No real-world attacks found as of announcement. Funds lost: no. Fixed source
- 2023-11 Keylabs audit: 3 low-severity hardware findings reported as not fixed in the third-party compilation of the report; high-severity tamper-response finding marked fixed and verified. Report PDF itself not read. Funds lost: no. Fix status not verified source
Disclosed weaknesses are listed whatever their severity. "Funds lost" is what the sources say. "Fixed" means the source states a fix exists, which only helps if you update.
Incidents at the maker or its service providers
- No company incident found in our search.
These affect the company or its customers and apply to every device of the brand. They are not weaknesses of this device.
Questions about Keystone 3 Pro
Is Keystone 3 Pro safe?
We do not give a yes or no, because safety depends on what you need to protect and on facts that change. We found 2 publicly disclosed weaknesses and 0 company incidents in our search. Read the sources above before you buy.
Does Keystone 3 Pro need an internet connection?
Signing happens on the device. How the device talks to your phone or computer depends on its connections: USB, QR. The companion app or software that builds the transaction is online.
Who found the weaknesses listed for Keystone 3 Pro?
The page names who disclosed each one when the source does. Several were found by a competing maker's research team or by independent security firms. We cite the affected company's own statement where we found one, and label press-only reports.
Where this comes from
- [1] Keystone 3 Pro product page accessed 2026-10-11
- [2] Keystone home page (security partners, footer) accessed 2026-10-11
- [3] Keystone bug bounty program accessed 2026-10-11
- [4] Keystone Secure Elements blog accessed 2026-10-11
- [5] keystone3-firmware GitHub accessed 2026-10-11
- [6] Keystone verify.md accessed 2026-10-11
- [7] Keystone x Offside Labs blog accessed 2026-10-11
- [8] Keystone blog: Crashing Keystone3 Pro Audit (Keylabs) accessed 2026-10-11
- [9] Least Authority audit of Keystone for Zcash accessed 2026-10-11
- [10] OneKey ANZEN write-up on Keystone USB SDK vulnerability accessed 2026-10-11
- [11] Walletbeat PR #1359 (third-party compilation: license, company, audits) accessed 2026-10-11
- [12] Coin Bureau Keystone 3 Pro review accessed 2026-10-11
Not verified: No EAL/CC certification stated by Keystone. Legal entity name taken from a third-party PR, not an official page. EUR price, warranty, app open-source status, passkeys, recovery service not verified. Keylabs/SlowMist/Offside reports not read directly (vendor blog and third-party summaries only). Official GitHub firmware license name not read directly. blog.keyst.one open-source philosophy post blocked by robots.txt. No company incidents (breach, supply chain) found in the limited searches; absence not proven.
See how we check. To report an error, use corrections and right of reply.