Keystone
Keystone is an air-gapped hardware wallet whose current model, the Keystone 3 Pro ($149), pairs a 4-inch touchscreen and camera with a fingerprint sensor and three secure elements, and can hold up to three seeds at once, each behind its own passcode. It talks to coordinators such as Sparrow only by QR code (a microSD slot handles firmware and multisig files), and it ships a Bitcoin-only firmware alongside the multi-coin one. The older Keystone Essential and Keystone Pro (the 2021 generation, formerly Cobo Vault) are still documented separately, with different menus, AAA or detachable batteries, and a wipe after five wrong passwords. Distinctive features are the multi-seed design, native Shamir backup shares, a passphrase wallet identified by its own master fingerprint, and a supply-chain verification that runs from the device’s camera against the maker’s website. The trade-offs are a rechargeable battery that will not charge from a laptop, multisig documented only on the Bitcoin-only firmware, and an address check that the maker describes as visual comparison rather than a scan.
What this is
Vendor: Keystone (formerly Cobo Vault), a hardware-wallet maker whose documentation is split across a current-generation guide (guide.keyst.one) and a legacy support site (support.keyst.one).
Product line as of 2026-09-12:
- Keystone 3 Pro ($149) — the current device. 4-inch touchscreen, camera, fingerprint sensor, USB-C, microSD slot, a 1000 mAh internal battery, and three secure elements, two of which protect the seeds. Holds up to three seed phrases, each with its own passcode. A non-Pro Keystone 3 is named in the maker’s setup guide.
- Keystone Essential / Keystone Pro (the 2021 generation) — the Essential runs on four AAA cells; the Pro adds a rechargeable battery, a fingerprint sensor and a self-destruct mechanism that bricks the device on disassembly. Both hold one seed. Their menus and rules differ from the 3 Pro throughout.
Firmware: three tracks updated together — Multi-Coin, Cypherpunk (BTC, ZEC, XMR) and Bitcoin-only (version 3.0.4 of each as of 2026-08-12). The Bitcoin-only track exists “to ensure the asset security of each user with minimal code complexity and attack surface”, and the move to it is one-way. Updates arrive by microSD (a single keystone3.bin on a FAT32 card) or WebUSB with Air-Gap Mode switched off; a device below 1.0.4 must update by card first. Firmware source is published; a checksum shown on the device can be compared with the website.
Connectivity: QR codes for every wallet interaction; the maker’s own page says USB connection to software wallets is “coming soon”. The device shows no balances — a coordinator is required for that.
Who this is for
Keystone is a strong fit for:
- Holders who want a large screen and a camera for QR signing — the 4-inch touchscreen makes reviewing transactions and typing words easier than on button devices
- Holders managing more than one seed — three seeds on one device, each behind its own passcode
- Shamir-backup users — 20- or 33-word shares are created and imported natively
- Multisig participants on the Bitcoin-only firmware — configs import by camera or card and are written to the secure chip
- Holders who want a checkable supply chain — device verification runs from the camera against the maker’s site and can be repeated at any time
Keystone is less appropriate for:
- Holders who want USB signing with Sparrow — Sparrow lists Keystone only among its air-gapped QR devices
- Multi-coin users who need multisig — the maker documents multisig for the Bitcoin-only firmware only
- Holders who prefer a device with no battery to manage — the 3 Pro needs a wall adapter or power bank, not a laptop port
- Holders who want a scan-to-verify address check — the maker’s address guidance is to compare the device’s receive screen with the coordinator’s by eye
Features and capabilities
Keystone 3 Pro
- Three seeds, three passcodes — add, delete and switch wallets under Device Settings › Wallet Settings; each unlocks with its own PIN, password or fingerprint
- Fingerprint — up to three prints, usable for unlocking, for signing, or both
- Shamir backup — create or import shares of 20 or 33 words with a chosen threshold
- Passphrase wallet — entered on device, identified by a distinct master fingerprint, never stored; a Passphrase Quick Access option on the lock screen
- Seed Phrase Check — confirms typed words against the stored seed (standard and Shamir; not the passphrase)
- Address settings — native segwit by default; nested segwit and legacy selectable; Taproot with Sparrow from firmware 1.3.0
- Bitcoin-only firmware — a reduced code base; one-way upgrade
- Multisig (Bitcoin-only firmware 1.1.0 or later) — export the multisig xpub, import a coordinator’s config by camera or microSD, set it as the current wallet, sign by QR
- Device verification — scan a QR on the maker’s site, enter the code the device shows
- Dice entropy at seed creation
Keystone Essential / Pro
- Password, pattern or fingerprint (Pro) unlock; wipe after five wrong passwords
- 12-, 18- or 24-word import, plus Shamir shares
- Watch-only wallet export to Sparrow by QR or microSD file
- Multisig by exported xpub file and an imported
Sparrow Multisig-Keystone.txt - Self-destruct (Pro) — wipes on detected disassembly; component lifespan rated at two years
Tradeoffs vs alternatives
| Dimension | Keystone 3 Pro | Foundation Passport Prime | Coldcard Q | SeedSigner |
|---|---|---|---|---|
| Price | $149 | $349 | $249 | Under $50 in parts |
| Seeds held | 3 | 1 | 1 (+ temporary seeds) | 0 — stateless |
| Secure element | 3 | Yes | Yes | No |
| Air-gap channel | QR (+ MicroSD for files) | QR (+ Bluetooth to Envoy) | QR + MicroSD + NFC | QR only |
| Seed entry | Touchscreen keyboard | Touch keyboard, SeedQR, Keycards | QWERTY keyboard | Thumb-stick keyboard, SeedQR |
| Shamir shares | Yes (20/33 words) | Keycards (2-of-3) | No (Seed XOR instead) | No |
| Multisig | Bitcoin-only firmware | Yes | Yes | Co-signs; stores nothing |
| Battery | Internal, 1000 mAh; wall adapter only | Internal | AA cells | None |
| Address check | Visual comparison | Scan-to-verify | Address Explorer | Scan-to-verify |
Compared to Passport Prime, Keystone is cheaper and holds several seeds, while Prime offers a scan-to-verify address check and NFC keycard backups. Compared to Coldcard, Keystone’s touchscreen is the easier entry surface and its multi-seed design is unique, while Coldcard’s MicroSD workflow, BIP-85 and trick PINs are deeper. Compared to SeedSigner, Keystone stores the seed and adds secure elements at the cost of a battery and a vendor.
Setup and operation
The setup flow (Keystone 3 Pro):
- Charge — the battery must be above 20 percent; use a 5 V/1 A or 2 A wall adapter or a power bank, not a laptop port or a fast charger
- Power on and choose a language
- Device verification (skippable) — scan the QR on the maker’s authentication page with the device, enter the code shown on screen
- Firmware update (skippable)
- Set a passcode — a numeric PIN or a password; add fingerprints later
- Create or import a wallet — 12 or 24 words, or Shamir shares; name the wallet
- Optionally set the address type under BTC › Address Settings
- Connect a coordinator by QR — Sparrow, Nunchuk, BlueWallet, Specter and the maker’s own Keystone Nexus app
The signing flow:
- Coordinator builds the PSBT and shows it as an animated QR
- Keystone scans it with the bottom Scan button, shows the details, asks for the passcode or fingerprint
- Keystone signs and shows the signed PSBT as a QR
- Coordinator scans it, finalises and broadcasts
Recovery — restoring the wallet on a fresh device
As of 2026-09-12, checked against Keystone’s own guide and support pages (linked inline). The two generations have different menus, so each step names both where they differ: 3 Pro (the ”···” icon top-right › Device Settings) and Gen 2 Essential/Pro (the Menu icon top-left › Settings).
What may be in hand
A 4-inch colour touchscreen with a fingerprint sensor at the bottom and a USB-C port is a Keystone 3 Pro; a device with a detachable battery pack or four AAA cells is a Gen 2 Essential or Pro. The 3 Pro’s battery will not charge from a laptop or a fast charger: use a 5 V/1 A or 2 A adapter or a power bank. A dead 3 Pro is charged for an hour, then the power button is held for 16 seconds. Wipe, restore and update all need at least 20 percent charge. Restore is offered from first boot without a firmware update; the update step is marked skippable.
Unlocking a device that still holds the seed
3 Pro: a numeric PIN or alphanumeric password per wallet, or a fingerprint. The 3 Pro can hold three seeds and associates each wallet with its own password during unlocking, so one passcode may open a different wallet than expected. A forgotten passcode is reset by verifying the seed phrase: Device Settings › Wallet Settings › Fingerprint & Passcode › Reset Passcode › Forgot Passcode. No lockout count is published for the 3 Pro, and no duress or decoy PIN exists on either generation. Gen 2: password, pattern or fingerprint; twelve wrong patterns force the text password, and five wrong passwords wipe the device, after which only the recovery phrase restores it. A correct unlock lands on the wallet’s home page, from which xpubs can be exported and transactions signed; the seed itself is never shown, only checked.
Wiping the device
3 Pro: Device Settings › System Settings › Wipe Device, with the password; all user data goes, the firmware stays. One of the three wallets can be removed alone with Delete Wallet in Wallet Settings. Gen 2: Menu › Settings › Wipe Device, or the automatic wipe after five wrong passwords.
Restoring from the backup
3 Pro: first boot runs language, optional verification and optional update, then asks for a passcode and a wallet name and offers Import Wallet; the words are typed on the touchscreen keyboard, never on a computer. Word counts named by the maker are 12 and 24, plus Shamir shares of 20 or 33 words entered in order until the threshold is met; the maker’s guide does not name an 18-word option for the 3 Pro. On a device that already holds a wallet, a second or third seed is added under Wallet Settings › + Add Wallet with its own new passcode. The seed is written to the secure elements and unlocked by the passcode from then on. There is no encrypted backup file on either generation. Keystone states that seeds from Ledger and other BIP-39 wallets import with the same Bitcoin paths, and that a lost device is recovered by entering the seed into any BIP-39 wallet.
Gen 2: power on, language, web authentication, set a password, then Import Wallet › Import a Wallet with Single Backup › choose 12, 18 or 24 words › enter them › Import Wallet; or Import a Wallet with Shamir Backup, entering shares one by one.
The passphrase
3 Pro: Device Settings › Wallet Settings › Passphrase, unlock with the passcode or fingerprint, type the passphrase on screen. The passphrase wallet has its own master fingerprint, which the maker calls the wallet’s identification; the passphrase is not stored, must be entered each time, and the device reverts to the original wallet on restart. The lock screen’s Passphrase Quick Access shortens the round trip. Seed Phrase Check cannot test a passphrase. Gen 2: Menu › Settings › Passphrase Wallet, with the same rules: hidden wallets are invisible after every restart, and the default wallet’s passphrase is blank.
Connecting to Sparrow and confirming the first address
Keystone is an Airgapped Hardware Wallet in Sparrow; it is absent from Sparrow’s USB list, and no driver or app is needed beyond a webcam. 3 Pro, multi-coin firmware: the ”···” icon › Connect Software Wallet › BTC › BTC Wallets shows the QR. 3 Pro, Bitcoin-only firmware: ”···” › Connect to Software Wallet › Sparrow. In Sparrow: New Wallet › name › Settings › Airgapped Hardware Wallet › Keystone › Scan… › Apply. The device exports native segwit by default; for nested segwit or legacy, set Sparrow’s script type first and scan the same QR, and for Taproot set Sparrow to Taproot (firmware 1.3.0 or later). Sparrow syncs one script type at a time. Gen 2 (Bitcoin-only firmware): Settings › Watch-Only Wallet › Sparrow Wallet › Confirm › the ”•••” menu › Export Wallet, by QR or as a file on the microSD that Sparrow imports.
Address check: the maker’s method is comparison. On the 3 Pro tap BTC (multi-coin) or RECEIVE (Bitcoin-only) to show the receiving address; in Sparrow click Receive; the two must match exactly, and the maker adds that no QR not generated by the device should be scanned. A first address that differs is almost always a script-type mismatch between Sparrow’s wallet and the device’s Address Settings — nothing lost; align them and re-scan. The 3 Pro may not list change addresses because of memory limits; the coordinator’s address list covers that.
Multisig
3 Pro (Bitcoin-only firmware 1.1.0 or later): export the multisig key from the top-left menu › Wallet Profile › View/Export Extended Public Key › Multisig Wallet; in Sparrow choose Keystore › Airgapped Hardware Wallet › Keystone Multisig › Scan. Bring the finished wallet back onto the device with Sparrow’s Settings › Export › Keystone Multisig (Show QR code, or Export File to a FAT32 card) and Keystone’s Wallet Profile › Add MultiSig Wallet › Via Camera or Via MicroSD Card › Confirm with the password; the device writes it to the secure chip. To sign, set the multisig wallet as the current wallet first. The maker’s warning is to back up the wallet configuration or risk irreversible loss. Gen 2: Menu › Multisig Wallet › export the xpub file to the card; import Sparrow’s Sparrow Multisig-Keystone.txt under Import Multisig Wallet. See Multisig setups.
Security considerations
Strengths
- Three secure elements on the 3 Pro, two dedicated to seed storage
- QR-only wallet interaction — no USB data path to a coordinator; microSD is for firmware and files
- Device verification against the maker’s site, repeatable at any time
- Bitcoin-only firmware with a reduced code base, and a device-side firmware checksum
- Passcode reset gated on the seed phrase — the written backup is the master credential, not the vendor
Known concerns
- Charging constraints — a battery that refuses laptop ports and fast chargers is a practical failure mode for a device pulled from storage
- Multisig only on the Bitcoin-only firmware in the maker’s documentation, and the switch is one-way
- Address verification by eye — the maker documents no scan-to-verify flow on the 3 Pro
- Documentation split across two sites with different menu vocabularies; a holder or survivor has to know which generation they hold
- Companion-app churn — the Gen 2 companion app is being retired in favour of a third party’s app; Keystone Nexus is the 3 Pro’s app. Neither is needed for Sparrow.
Supply-chain integrity
Buy from keyst.one or its listed resellers and run device verification on arrival. The Gen 2 Pro’s self-destruct mechanism and the 3 Pro’s verification are the maker’s tamper answers; the seed backup is the recovery answer if either fires.
Pricing and acquisition
As of 2026-09-12:
- Keystone 3 Pro: $149 on the maker’s site; the box includes a USB cable and seed sheets
- Keystone Essential / Pro: no longer the current line; still documented on the legacy support site
Common pitfalls
Charging it from a laptop. It will not charge. A wall adapter or power bank is required, and a fully dead device needs an hour on charge before a 16-second power-button hold.
Opening the wrong wallet. With three seeds behind three passcodes, the passcode that works may open a wallet other than the one expected; the master fingerprint tells them apart.
Losing the passphrase wallet after a restart. The device always returns to the original wallet; the passphrase wallet only exists while the passphrase is applied.
Script-type mismatch. Sparrow’s wallet type and the device’s Address Settings must agree, or the first address differs. Nothing is lost.
Guessing passwords on a Gen 2. Five wrong text passwords wipe it. Use the recovery phrase instead.
Moving to Bitcoin-only firmware casually. The switch cannot be reversed; multi-coin holdings on the same seed are then managed elsewhere.
Updating with extra files on the card. The microSD must be FAT32, at most 512 GB, with only the firmware file in its root.
Tooling and resources
Keystone documentation (as of 2026-09-12):
- guide.keyst.one — the Keystone 3 Pro guide (basic features, advanced features, Bitcoin-only firmware, third-party wallets including Sparrow)
- support.keyst.one — the legacy Essential / Pro support site
- keyst.one/firmware and keyst.one/authentication — firmware downloads and device verification
Coordinator software supporting Keystone:
- Sparrow Wallet — airgapped QR flow; the maker’s own step-by-step pages target it
- Nunchuk, BlueWallet, Specter Desktop — QR-based
- Keystone Nexus — the maker’s own app for the 3 Pro
Open questions for further development
- Does holding three seeds on one device help or hurt operational discipline for the typical holder — a convenience that concentrates keys, or a way to keep a small hot seed and a large cold one apart?
- The maker documents address checking as visual comparison on its flagship. Is that adequate practice, and should the device gain a scan-to-verify flow like its QR peers?
- Multisig gated on a one-way Bitcoin-only firmware is an unusual design choice. Does it reflect a security stance or a documentation lag?
Related notes
The framing context:
- Hardware wallets overview — the framework Keystone is evaluated against
- Self-custody configuration ladder
- Threat modeling for self-custody
Per-device alternatives:
- Foundation Passport — the other touchscreen QR device
- Coldcard — QR and MicroSD air-gap; power-user features
- SeedSigner — the stateless DIY QR signer
- Trezor — the other device with native Shamir shares (SLIP-39)
Capabilities:
- SLIP-39 and Shamir Secret Sharing — Keystone’s 20- and 33-word shares
- Passphrases and the 25th word
- Seed phrases and BIP-39
- PSBT and wallet descriptors
Custody configurations:
Operational practice:
The sub-MOC home: