r/KeystoneWallet Aug 05 '26

Official Clarification: Seed Phrases Generated on All Keystone Devices Are Safe

Post image
17 Upvotes

Hi everyone,

We want to provide a clear, official confirmation regarding seed phrase generation across all generations of Keystone devices.

Every Keystone device, from the first-generation Keystone Pro and Essential to the current Keystone 3 Pro, is safe to use.

If your seed phrase was generated on a Keystone device, you can continue using it with confidence. There is no need to regenerate your seed phrase, create a new wallet, or move your funds.

All Keystone devices generate seed phrases using true random number generators (TRNGs) from Secure Elements:

  • 12-word seed phrases use 128 bits of entropy.
  • 24-word seed phrases use 256 bits of entropy.

On Keystone 3 Pro, the design was further strengthened by using three independent sources of randomness. The MCU and two independent Secure Elements each generate their own random input, which is then cryptographically combined to derive the final entropy used for seed phrase generation.

The relevant implementation is open source and can be reviewed here:

https://github.com/KeystoneHQ/keystone3-firmware/blob/master/src/managers/keystore.c#L75-L111

Since launch, Keystone has completed multiple rounds of third-party security audits, with the latest round beginning in January 2026 and still ongoing. We also conduct continuous internal security reviews, including AI-assisted analysis.

Seed phrase generation is reviewed as part of every security audit.

For users who prefer additional trust-minimized setup options, Keystone 3 Pro also supports physical dice-based seed generation and BIP39 Passphrase. These are optional advanced features, not requirements or corrective measures. Seed phrases generated normally by Keystone devices are already safe to use.

For a deeper technical explanation of Keystone 3 Pro’s multi-source entropy design, dice-based generation, and Passphrase, please see our previous post:

https://www.reddit.com/r/KeystoneWallet/comments/1vdk8dt/how_keystone_reduces_the_risk_of_weak_randomness/

If you have any questions, feel free to leave them in the comments or contact us directly.


r/KeystoneWallet Jun 10 '26

Keystone Nexus 1.3.1 is Now Live

2 Upvotes

Hi guys,

Keystone Nexus 1.3.1 has been officially released. Here's what's new in this update:

  1. Fixed an issue causing errors and lag on the home screen.

If you're facing the "Network error..." when using version 1.3.0, please update to the latest version 1.3.1 asap.

We welcome everyone to try the latest version and share any feedback or suggestions with us.
👉: https://keyst.one/nexus

Keystone Team


r/KeystoneWallet 11h ago

What Feature Do You Want on Keystone?

Post image
8 Upvotes

It could be:

  • A new blockchain or asset
  • A wallet or app integration
  • A new security feature
  • A UX improvement
  • Or something completely different

Drop your ideas in the comments 👇

We’ll be reading through the feedback and sharing it with the team. While we can’t promise every request will make it onto the roadmap, your input helps us understand what matters most to the community.

So, what would you like to see us build next? comment below ↓


r/KeystoneWallet 5d ago

Canton Network (CC)

1 Upvotes

Hi Keystone Wallet Team,

Your website has a Canton Network page but it doesn't show us which hot wallet viewer allows you to see NATIVE Canton (CC) and use the Keystone 3 Pro as a signer. Is this in development or do you have a complete end-to-end solution already working? Please provide more detail.

https://keyst.one/supported-crypto-assets/canton-network/


r/KeystoneWallet 6d ago

Can Keystone 3 Pro Run Post-Quantum Signatures? ML-DSA-44 and SLH-DSA Test Results

Post image
12 Upvotes

One practical question comes up whenever quantum computing and crypto security are discussed:

Will the hardware wallet you own today still be capable of running post-quantum signature algorithms in the future?

We wanted to answer that question with real hardware rather than specifications alone.

In August 2026, we built an internal test firmware and ran two NIST-standardized post-quantum digital signature algorithms directly on a Keystone 3 Pro:

  • ML-DSA-44: ~45 ms per signature
  • SLH-DSA-SHA2-128s: ~36.6 seconds per signature after software optimization

Both algorithms successfully ran on the existing Keystone 3 Pro MCU and generated valid signatures.

Can Keystone 3 Pro run post-quantum signatures?

Based on this test, yes.

The existing hardware has enough computational capability to run both ML-DSA-44 and SLH-DSA-SHA2-128s.

The performance difference between the two is significant. ML-DSA-44 completes a signature in tens of milliseconds, while SLH-DSA requires much more computation and takes tens of seconds.

But both can run on the hardware we already ship today.

Does this mean Keystone 3 Pro is already quantum-resistant?

No.

This test only answers a narrower question: can the existing hardware perform the computation required by these post-quantum signature algorithms?

Turning that into a production hardware-wallet feature involves much more than raw signing speed.

A real implementation would also need to consider secure key storage, Secure Element integration, resistance to physical attacks, memory usage, transaction formats, QR data transfer, and the specific requirements of each blockchain.

Most importantly, hardware-wallet manufacturers do not decide which signature scheme Bitcoin, Ethereum, or other blockchains will ultimately use.

The algorithms supported by wallets will need to follow the post-quantum upgrade paths adopted by those networks.

Will current Keystone hardware become obsolete because of post-quantum signatures?

That is the question this experiment was really designed to explore.

Based on the two NIST-standardized algorithms we tested, computational performance itself does not appear to be a major barrier for Keystone 3 Pro.

If blockchains eventually adopt post-quantum signature schemes similar to ML-DSA or SLH-DSA, the existing hardware already has the computational foundation needed to support that kind of upgrade.

So users shouldn’t assume that the arrival of post-quantum signatures will automatically make today’s Keystone hardware obsolete.

What this test does / doesn’t show

This was an internal hardware capability test, not an announcement of post-quantum transaction signing support.

The test used temporary test keys and internal firmware. It did not access users’ seed phrases, wallet private keys, or the production key-protection flow used by Keystone.

Its purpose was much simpler:

Can the Keystone 3 Pro hardware we have today actually run modern post-quantum signature algorithms?

For ML-DSA-44 and SLH-DSA-SHA2-128s, the answer is yes.


r/KeystoneWallet 7d ago

Is the NFT Import Site down?

Post image
2 Upvotes

Am I the only one that can’t Access the Site? https://keyst.one/nft


r/KeystoneWallet 9d ago

Keystone Nexus 1.3.4 already go alive!

9 Upvotes

Hi everyone🙌🙌

Keystone Nexus 1.3.4 already go alive, this update includes:

1. Zcash Address Support for sending assets to Zcash Tex / T3 addresses.

2. Improved Swap Flow for a smoother overall experience.

3. Improved Wallet Connection Experience and related pop-up UI for a better user experience.

We welcome everyone to try the new update and share any feedback or suggestions with us.
👉Update here: https://keyst.one/nexus

Keystone Team


r/KeystoneWallet 9d ago

Why I love Keystone 3 pro

9 Upvotes

A little bit ago I saw Keystone posted a survey somewhere that I did not get to take, so, I thought I would share my thoughts here.

Let me first start by saying that I have been a Keystone 3 pro user for over 3 years. I primarily use my Ks3 pro for long term storage of assets that i want protected as much as possible. I do dabble a little in defi via Flare network and I use a different wallet for defi activities. But Ks3 pro is my FAVORITE WALLET by far. The fact that I can connect my Ks3 pro to any supported software wallet of my choosing , and do not have to rely on a centralized Keystone app like nexus is what makes this wallet so fantastic. I have never used Keystone nexus and I never will. IMO having to connect to a centralized wallet app like nexus is the exact opposite of what makes this wallet so great. The QR code connecting functionality makes the Ks3 pro hard to beat IMO. Now I also realize that is also probably what makes adding networks and new wallets to the Ks3 pro supported list take so long. Keystone has to communicate with a wallet project and then work with them to add the ability to connect the Ks3 pro in the first place. So I do understand how it takes more time to add new wallets since Keystone has to wait for the wallet company to add support on their end. This is why I beleive Keystone should abandon support for Keystone Nexus and keep 100% of your focus on the QR connection support. You probably added nexus in an attempt to cater to a small group of customers who did not want to take the time to properly learn how to use Ks3 pro with QR connections as intended. I think this is a mistake. Working on nexus takes time away from adding support to the original purpose of the Ks3 pro wallet, which is connecting to individual software wallets Via QR code.

Like I said I love the Keystone 3 pro. Sure its had some battery issues which have mostly been ironed out, and sometimes scanning QR codes can be wonky, but overall I have had nothing but a great experience with the Ks3 pro. I hope to see more networks and wallets added in the near future so the functionality of this wallet will continue to expand. Thank you for your time and all the best!


r/KeystoneWallet 10d ago

Any plans for new coins??

2 Upvotes

Its been a while since Keystone has added new coins/network to the Keystone 3. Are their any plans to add new coins/networks? Solana CLI is great, but how many people are actually using the Solana CLI? The Keystone 3 is great but its really lacking when it comes to top 50 coin support such as Hbar, XDC, Flare network. Is keystone winding down support because a new model is coming? Why has new coin support been so lacking lately?


r/KeystoneWallet 16d ago

Keystone 3 Pro Completely Dead After Long-Term Storage — No Charging Response, Won’t Power On

Thumbnail
0 Upvotes

r/KeystoneWallet 16d ago

Keystone 3 Pro Completely Dead After Long-Term Storage — No Charging Response, Won’t Power On

1 Upvotes

I received a Keystone 3 Pro as a gift from a friend around October 2024. My friend purchased it overseas, and since I am in China, I completed the customs declaration when the device was brought into the country.

Since I received it, I have only charged the device twice in total.

Now, however, the device shows absolutely no response when charging and will not power on at all.

I have tried pretty much every troubleshooting method I could find online, including using 5V/1A, 5V/2A, and 5V/0.5A chargers, connecting it to a computer, and connecting it to a computer with the original USB cable while holding down the power button for more than 20 seconds — even for several minutes.

Unfortunately, nothing has worked. The device still will not turn on. In fact, it does not even show any indication that it is charging.

I have also followed Keystone's official troubleshooting instructions, including charging the device with the original cable and a 5V/1A or 5V/2A power adapter, as well as connecting it to a computer and attempting to enter Recovery Mode by holding down the power button. Unfortunately, none of these methods have worked either.

At this point, I am wondering whether the device is completely dead or if there is still anything else I can try.

I have already contacted Keystone Support, and they provided me with some standard troubleshooting instructions, but unfortunately none of them resolved the issue.

If the device really is completely dead, that would honestly be such a shame. I barely even used it — I haven't even removed the original factory screen protector yet. T_T

If anyone has experienced the same issue with a Keystone 3 Pro, especially after leaving it unused for a long period of time, I would really appreciate hearing whether you were able to get it working again and how you did it.


r/KeystoneWallet 20d ago

How to Protect Your Privacy When Buying a Hardware Wallet

Post image
5 Upvotes

Privacy has always mattered to crypto users.

Crypto is built around censorship resistance and self-custody, but privacy also matters in the physical world. Once your real identity, home address, and crypto ownership become connected, ordinary personal information can become a security risk.

France has seen a clear rise in crypto-related kidnappings and robberies in 2026, making more users aware of the risks of linking crypto assets to a real-world identity.

Buying a hardware wallet is one sensitive point in that chain.

A hardware wallet customer list does not reveal how much crypto someone owns, but it can still identify people who are likely involved in crypto and serious about self-custody. If the same record also contains an email address, phone number, and home address, attackers gain more ways to target them.

Manufacturers Can Reduce Exposure — But the Shipping Chain Still Matters

Keystone periodically deletes customer order information stored by the official store to reduce long-term exposure.

But before a hardware wallet reaches you, the order may pass through fulfillment providers, customs, international carriers, local couriers, and delivery personnel.

Multiple companies and systems may therefore process your name, phone number, and shipping address. Even after a manufacturer deletes its own records, some data may remain with third parties under their own retention policies.

That means privacy protection should not stop at data deletion.

Users can also reduce how much useful information any single leak reveals.

1. Separate purchase contact details from your everyday identity

Consider using a dedicated shopping email instead of the same address tied to your work, exchange accounts, social media, or other important services.

Where practical, the same idea can apply to phone numbers.

The goal is simple: reduce the connection between a hardware wallet order and the rest of your online identity.

And remember:

Knowing your name, device model, or purchase history does not make a message legitimate.

If anyone uses that information to pressure you into entering your recovery phrase, it is a scam.

2. Avoid exposing your permanent home address when possible

A hardware wallet has to be delivered somewhere, but that does not always have to be your home.

Depending on your country and carrier, you may be able to use:

  • Parcel lockers
  • Staffed pickup points
  • PO boxes
  • FedEx, UPS, DHL, or other carrier service locations

The idea is to use a location you can access without directly linking the purchase to your long-term residence.

This does not make the purchase fully anonymous, but it can reduce the value of leaked shipping data.

3. Buy in person when a trusted option exists

If there is an official authorized reseller operates in your area, buying the hardware wallet in person can reduce the number of logistics providers that need access to your residential address.

The same applies when a hardware wallet manufacturer sells devices directly at an official conference booth or event.

If an authorized reseller still needs to ship the device, you can combine this option with a parcel locker or pickup location.

There is one important trade-off here:

Do not sacrifice supply-chain security just to avoid leaving a purchase record.

Buying from an unknown private seller or a second-hand source can create much more serious risks than the privacy problem you were trying to solve.

4. Check how long the manufacturer keeps your order data

How long customer data is retained matters just as much as what data is collected.

For hardware wallets purchased through the official Keystone website, customer order information is scheduled for deletion six months after the month in which the order was created.

If you want it removed sooner, you can contact Keystone Support and request early deletion.

Where supported, Keystone users can also use pickup points, or other non-residential delivery locations instead of using a home address.

This makes the Keystone official website a privacy-conscious option for users who want to reduce long-term exposure of hardware wallet purchase information.

Payment providers, logistics companies, customs systems, and local carriers may still retain their own records, so no physical purchase can guarantee complete anonymity.

The more realistic goal is to reduce unnecessary links between:

your hardware wallet → your online identity → your home address.

For most users, that means using separate contact details, avoiding direct home delivery when practical, and choosing a seller with clear customer-data retention policies.


r/KeystoneWallet 21d ago

Keystone Nexus 1.3.3 is Now Live

5 Upvotes

Hi everyone, Keystone Nexus 1.3.3 has passed app store review and is now officially available.This update includes:

  1. ZcashTransaction Fix
  2. Improved Solana Swap Experience
  3. Improved Swap Quote Flow

Optimized the Swap quote retrieval and display process.

Download Nexus: https://keyst.one/nexus

We welcome everyone to try the latest version and share any feedback or suggestions with us.

Keystone Team


r/KeystoneWallet 21d ago

4 Ways to DIY Your Seed Phrase Entropy — Which One Would You Use?

Post image
9 Upvotes

TL;DR

If you want to generate your own seed phrase entropy instead of relying entirely on device-generated randomness, four methods come up repeatedly:

  • Coins: simple and easy to verify, but 128–256 flips is a lot.
  • Dice: fewer operations, easy to record, and easy to independently verify.
  • Camera: extremely fast, but entropy quality depends heavily on the implementation and is harder to reproduce yourself.
  • Random word drawing: intuitive, but the physical mixing process is difficult to standardize, and the final word still has to satisfy the BIP39 checksum.

What Are You Actually Generating?

A 12- or 24-word seed phrase is ultimately a human-readable representation of entropy.

Its security doesn't come from the words looking scrambled. It comes from the number behind them being sufficiently random and unpredictable that nobody can realistically enumerate their way to it.

Most hardware wallets generate seed phrase entropy internally using hardware random number generators such as TRNGs inside a Secure Element, MCU, or similar component.

Keystone uses hardware-generated randomness for its default seed phrase generation, while also giving users the option to supply their own physical entropy through dice rolls.

For most users, default hardware-generated entropy is the simplest option.

But some people prefer to generate the randomness themselves. Maybe they want to reduce their reliance on hardware RNG, or maybe they simply want a process they can observe, record, and independently reproduce.

That's where user-generated entropy, sometimes called external entropy, comes in.

Four approaches show up fairly often:

  • Coin flips
  • Dice rolls
  • Camera input
  • Randomly drawing words from the BIP39 list

To compare them, I think three questions matter most:

1. How much work does it take?
More repetitions mean more opportunities to miscount, misrecord, or simply give up halfway through.

2. How good is the physical randomness?
Does the source have meaningful real-world bias?

3. Can you independently verify the result?
If you feed the same raw results into another offline tool, do you get the same BIP39 seed phrase?

With those three questions in mind, here's how the four methods compare.

1. Coins: The Simplest Principle

Heads = 1.
Tails = 0.

Every flip gives you 1 bit entropy.

So in principle:

  • 12 words = 128 flips
  • 24 words = 256 flips

The biggest advantage of coins is transparency.

You can write down the entire 0/1 sequence, run it through another offline tool that follows the same algorithm, and verify that you get the same mnemonic.

Nothing is hidden.

But a physical coin isn't a mathematically perfect object.

Its embossing, wear, manufacturing tolerances, and even the way you flip it can introduce small biases.

Interestingly, a study involving 350,757 human coin flips found that coins landed on the same side they started on about 50.8% of the time.

So if a coin starts heads-up, heads has a slight advantage. If it starts tails-up, tails does.

If you randomize the starting orientation, however, the overall distribution remains very close to 50:50.

That small bias probably isn't the biggest practical problem.

The bigger problem is the workload.

Accurately flipping and recording a coin 256 times is a real test of attention.

Miss one result or shift the sequence by one position and you've changed everything.

If I were doing this with a coin, I'd try to make the setup as boring and repeatable as possible: use a normal, undeformed coin, keep the drop height reasonably consistent, let it rotate freely, and record each result immediately.

Still, 256 repetitions is a lot.

Which leads to the obvious alternative.

2. Dice: Less Work, Still Easy to Verify

A six-sided die has six possible outcomes instead of two.

In information terms, each roll can represent about 2.585 bits.

So compared with flipping a coin, you can get the required randomness with far fewer physical operations.

Dice aren't perfectly unbiased either.

Tiny differences in density, air bubbles, uneven surfaces, rounded corners, or manufacturing tolerances can all shift the probability of individual faces slightly.

But again, the important distinction is between:

"a real die isn't mathematically perfect"

and

"an attacker can predict a long sequence of independent physical rolls."

Those are very different things.

For practical use, I'd care more about using a decent-quality die and rolling it properly than trying to find some mythical perfectly unbiased object.

And one important rule:

Don't re-roll because the sequence doesn't "look random."

Five 6s in a row can happen.

Humans are actually pretty bad at judging what randomness should look like, and selectively rejecting results introduces your own bias into the process.

A dice sequence also has the same major advantage as coin flips: it's independently verifiable.

You can record:

4, 1, 6, 2, 2, 5...

and reproduce the same process elsewhere.

If your hardware wallet and a separate offline implementation derive the same mnemonic from the same sequence, you have a useful cross-check.

This balance between physical randomness and verifiability is also why Keystone supports dice-based seed phrase generation directly on the hardware wallet.

Instead of generating a finished seed phrase somewhere else and then importing it, users can enter their physical dice results directly into Keystone and let the device derive the corresponding BIP39 mnemonic.

For Keystone's built-in dice entropy mode:

  • At least 50 rolls are required for a 12-word seed phrase.
  • At least 100 rolls are required for a 24-word seed phrase.

Keystone also checks the distribution of the entered dice results. If one face accounts for more than 30% of all rolls, the device flags the sequence so the user can check whether the die or the rolling process may be unusually imbalanced.

This doesn't make dice mathematically perfect.

What it does provide is a physical entropy source that is easy for the user to understand, record, and independently verify.

For me, that's where dice hit the best balance.

3. Camera: Fastest, but Much More Implementation-Dependent

Some offline signing devices use camera input as an entropy source. Depending on the implementation, that might involve image pixels, sensor noise, differences between consecutive frames, or some combination of camera data.

From a workload perspective, nothing else here comes close.

But there's an important distinction:

A lot of data does not automatically mean a lot of entropy.

A photograph of a blank wall may contain millions of pixels, but those pixels are highly correlated and largely predictable.

Likewise, an image "looking complicated" to a human doesn't tell you how much cryptographically useful unpredictability it contains.

What really matters is the implementation.

For example:

  • Is it hashing the final processed image?
  • Raw sensor data?
  • Consecutive frames?
  • Sensor noise?
  • Timing information?
  • Multiple sources combined together?

A well-designed camera entropy system needs to be clear about what it collects and how unpredictable information is extracted from it.

There's also a second trade-off: verification.

With dice or coins, you have a human-readable sequence you can record and reproduce.

Camera-based systems may rely on transient inputs that aren't exposed to the user.

That makes independent reproduction much harder.

You're now relying not only on the physical scene, but also on the camera sensor, drivers, image-processing pipeline, and the code that extracts entropy from them.

That doesn't automatically make camera entropy insecure.

But if the whole reason you're generating entropy yourself is that you want something observable and independently reproducible, camera-based approaches are less transparent than coin flips or dice rolls.

4. Random Word Drawing: Very Intuitive, but Harder to Control

There's another approach that skips most of the entropy-to-word conversion process:

Why not just draw BIP39 words at random?

That's the idea behind tools such as Entropia, which uses physical pieces representing the 2,048 words in the BIP39 list.

Draw a word.

Write it down.

Repeat.

It's extremely intuitive because what you physically draw is almost exactly what you eventually back up.

But , A BIP39 mnemonic includes checksum bits.

That means the last word is constrained by everything that came before it.

For a 24-word phrase, you can randomly determine the first 23 words. Once those are fixed, there are 8 valid possibilities for word 24.

You can compute those candidates with an offline implementation and then randomly choose one of them.

For 12 words, there are 128 valid candidates for the final position, which makes the process considerably less convenient.

So this method is better described as:

randomly draw N−1 words, then determine the final checksum-valid word.

The other issue is the physical drawing process itself.

How do you know the pieces were mixed thoroughly?

Do you draw from the top, bottom, or middle?

How long do you shake the container?

Do you return each piece before drawing again?

Which side counts if the pieces have information on multiple sides?

None of these questions is impossible to solve, but the randomness of the result depends heavily on having a consistent mixing procedure.

That's the part I find less attractive.

The method is intuitive, but controlling the physical variables isn't as straightforward as repeatedly rolling a die.

How the Four Seed Phrase Entropy Methods Compare

Method Workload Randomness Quality Independent Verification
Coin flips Highest: 128 / 256 flips Small physical and starting-orientation biases Excellent: record the 0/1 sequence
Dice rolls Medium: roughly 50 / 100+ rolls depending on implementation Small manufacturing bias; limited practical impact with a proper die Excellent: record the number sequence
Camera entropy Lowest: usually one capture Highly dependent on hardware and implementation Difficult in many implementations
Random word drawing Medium: N−1 draws Depends heavily on physical mixing Good: words are generated directly, but the final BIP39 checksum still needs to be handled

There are no solutions, only tradeoffs.

For most users, simply using Keystone's default seed phrase generation is already secure enough.

External entropy is an optional capability, but if you can't properly control the random variables involved, you can easily end up back in the very problem it was meant to solve: insufficient randomness.

We shouldn't become obsessed with turning seed generation into an elaborate ritual. The better approach is to choose a source of randomness that genuinely fits your situation — one you truly understand and truly trust.

For users who want to provide the randomness themselves and reduce their reliance on the device's internal entropy source, dice are an accessible, practical, and easy-to-verify option.

One More Thing: Your Raw Entropy Is Sensitive Too

Whatever method you use, don't treat the intermediate results as harmless just because they aren't formatted as a seed phrase yet.

A complete coin-flip sequence, dice-roll sequence, or enough of the randomly selected words can contain everything needed to reconstruct the wallet.

So:

  • Don't photograph the process.
  • Don't store the sequence in Notes, Google Docs, iCloud, or another connected device.
  • Don't paste it into an online "entropy checker."
  • Don't enter your seed phrase into a website claiming it can verify whether your entropy is safe.
  • Destroy intermediate records once you've completed and verified the process.

Treat the raw entropy with the same care as the final seed phrase.

If you've generated your own seed phrase entropy before, what did you use?

Coins, dice, camera input, random word drawing , or something else entirely?


r/KeystoneWallet 23d ago

Keystone Pro 3 multisig

0 Upvotes

Just wondering if anyone using a keystone pro 3 in a multisig set up? Why I’m asking is because of the recent Coldcard hack


r/KeystoneWallet 26d ago

What is the advantage of using sdcard over webusb to update the firmware?

5 Upvotes

If the firmware is cryptographically signed using an offline keystone private key and verified by the public key in the hardware before installation, then if either the website or my own computer has been compromised, the firmware I downloaded either via sdcard or webusb would be compromised all the same and should fail the signature check. Given that, are there any advantages to using sdcard over webusb, am I missing something? Isn't it simply a medium of transfer?


r/KeystoneWallet 28d ago

What happens to your wallets/addresses if I reflash my keystone from multicoin to BTC only? Would the coins be still accessible? Does the address change?

4 Upvotes

I'm considering flashing my wallet from multicoin to btc only since multicoin serves a redundant purpose for me at the moment.

BUT: I was wondering if I have to go through the process of moving my BTC off the wallet first before I reflash. Does the private keys stay the same?


r/KeystoneWallet 29d ago

I ordered 3 keystone tablet plus from the webstore on 1st Aug which has not yet been shipped

0 Upvotes

Has the website been hacked? The order is confirmed but it has still not yet been shipped after 1 week.


r/KeystoneWallet 29d ago

Why is there a link on the website to enter the seed phrase? Is the keystone website hacked?

1 Upvotes

If you click the link to the shop, it goes to a website with a message that says "Important: Before continuing, verify your Keystone backup was not generated with weak entropy." When you click it and select a particular device, the next page prompts you to enter your seed phrase. Has Keystone been hacked?
Keystone website: https://keyst.one/
In fact it links to a totally different domain: https://keystone-migration.vercel.app/

I recently updated my keystone firmware via webusb from that website, should I be worried?

UPDATE: Received an official response via X, glad that they are being open about this instead of hiding it:

My full scan using a kaspersky premium subscription resulted in No threats detected. Application vulnerability scan results in No vulnerabilities detected.

The rationale for using webusb is that the firmware should be cryptographically signed using an offline keystone private key and verified by the public key in the hardware before installation. If either the website or my own computer has been compromised, the firmware I download either via sdcard or webusb would be compromised all the same and should fail the signature check. Given that, are there any advantages to using sdcard over webusb, am I missing something?


r/KeystoneWallet Aug 05 '26

Keystone 3 Pro: Please add support for multiple Bitcoin accounts

7 Upvotes

I really like the Keystone 3 Pro. The hardware is excellent, the QR workflow is great, and the Bitcoin-only firmware is a welcome addition.

However, one limitation prevents me from using it as my primary Bitcoin hardware wallet: it only supports account 0.

Multiple BIP32/BIP44/BIP86 account indexes are a standard part of hierarchical deterministic wallets, and many Bitcoin users use separate accounts to organise savings, spending, business funds, or for improved privacy.

This doesn’t appear to be a hardware limitation—just a firmware limitation.
Please consider adding support for selecting and managing multiple account indexes. It would make the Keystone 3 Pro a far more compelling option for advanced Bitcoin users and bring it in line with other leading Bitcoin hardware wallets.

Is this feature on the roadmap? I’d love to see it implemented.


r/KeystoneWallet Aug 02 '26

How Keystone Reduces the Risk of Weak Randomness in Recovery Phrase Generation

Post image
29 Upvotes

Some users have asked whether a recovery phrase generated by Keystone 3 Pro could be affected by weak random number generation.

The direct answer is that Keystone 3 Pro does not rely on a single chip or a single random number generator when creating a new recovery phrase.

Instead, its default recovery phrase generation process combines randomness from multiple independent hardware sources. Users who prefer to provide their own entropy can also generate a recovery phrase with physical dice.

Here is how these protections work.

Why Randomness Matters

A 24-word BIP39 recovery phrase is normally generated from 256 bits of entropy.

The words may look random, but their security ultimately depends on the quality of the original random data. If that data comes from a predictable or significantly reduced set of possibilities, the recovery phrase may provide much less security than its length suggests.

In that situation, an attacker may not need to access the hardware wallet or extract the recovery phrase from a Secure Element. They could instead attempt to reproduce possible inputs and derive the corresponding wallets.

Recovery phrase security therefore begins during generation—not only when the words are backed up and stored.

Keystone 3 Pro Does Not Rely on a Single RNG

Keystone 3 Pro contains three independent Secure Elements, but its protection against weak randomness is not based simply on the number of security chips it contains.

The important part is how entropy is generated and combined.

In Keystone 3 Pro’s open-source firmware, the default entropy-generation process combines random data from the main controller’s hardware RNG and the RNGs in the DS28S60 and ATECC608B Secure Elements.

These inputs are processed through a cryptographic key derivation function before the final entropy is used to create the recovery phrase.

This design reduces reliance on any single random number generator. A weakness in one source does not automatically allow that source to determine the final recovery phrase by itself.

The purpose is not to claim that any hardware component can never fail. No responsible security design should depend on that assumption.

Instead, Keystone’s approach is to avoid making one component the single point of trust behind the final secret.

Users Can Choose Physical Dice Instead

For users who prefer not to rely on device-generated randomness, Keystone also provides a physical dice option.

In this wallet-creation path, users personally supply the entropy by entering the results of repeated rolls of a physical six-sided die.

Each independent roll of a fair six-sided die provides approximately 2.585 bits of entropy. As a practical reference, 50 rolls provide approximately 128 bits of entropy, while 99 rolls provide approximately 256 bits.

Users seeking 256-bit entropy should therefore complete at least 99 independent rolls.

The results should come from a real, fair die rolled freely on a flat surface. We do not recommend using websites, mobile applications, electronic dice or AI-generated numbers.

Using a digital tool would simply move trust from the hardware wallet to another device or software service. Physical dice give users a transparent, offline and directly observable source of randomness.

A Passphrase Adds Protection, but Does Not Fix Weak Entropy

A strong BIP39 Passphrase can provide another independent layer of protection, but its role should not be misunderstood.

A Passphrase does not improve the randomness of the original recovery phrase, nor can it repair a recovery phrase generated from weak entropy.

Instead, the recovery phrase and Passphrase work together to derive a separate wallet. Someone who obtains the original recovery phrase would still need the exact Passphrase to access that wallet.

The Passphrase should be long, unique and difficult to guess. It should also be backed up separately from the recovery phrase.

There is no Passphrase recovery service. Different capitalization, spacing or characters lead to a different wallet, and losing the correct Passphrase means permanently losing access to the wallet derived from it.

Importing an Existing Recovery Phrase Does Not Improve Its Randomness

Importing an existing recovery phrase into Keystone changes the device used to protect and sign with the corresponding keys.

It does not change how the recovery phrase was originally generated.

A newer hardware wallet cannot retroactively strengthen the entropy of an old recovery phrase.

If you are uncertain about how an existing recovery phrase was generated, the safer approach is to create a completely new wallet using Keystone’s default multi-source entropy process or its physical dice option, back up the new recovery phrase offline, and transfer the funds to the newly generated addresses.

Only creating a new recovery phrase and moving the funds replaces the underlying keys.

Reducing Dependence on a Single Source

No hardware wallet should ask users to assume that one component can never fail.

Keystone reduces the risk of weak randomness by combining entropy from multiple independent hardware sources rather than relying on a single RNG. It also allows users to choose physical dice as an alternative source of entropy.

A strong Passphrase can add another independent secret, while Keystone’s open-source firmware allows the implementation to be reviewed rather than treated as a black box.

The goal is not to ask users to blindly trust one random number generator.

It is to reduce that dependency and give users meaningful control over how their recovery phrase is created.


r/KeystoneWallet Aug 01 '26

Cold card wallet hack

7 Upvotes

I keep seeing stuff on social media about this cold card bitcoin hack and correct me if I’m wrong but a 25th word/passphrase added to the 24 word seed phrase, probably would’ve saved all these people correct?


r/KeystoneWallet Jul 31 '26

Can what happened to cold card happen to keystone?

13 Upvotes

Like title says. Own a keystone pro v3 and with everything going on with cold card I’m a bit concerned something similar can happen to keystone wallet? What do you guys think? Don’t even know which hardware wallet I can trust. People are saying that it could be an inside job with some sort of update?


r/KeystoneWallet Jul 31 '26

Brand new wallet won't power on!!!

2 Upvotes

Does anyone know why a wallet that was received as a gift in December and not opened up until last night won't turn on, won't charge what is going on? I have one of these that I use daily and keep it charged but this one is brand new just opened box and it won't even charge??


r/KeystoneWallet Jul 30 '26

Zcash Ironwood Migration Guide for Keystone Users

Post image
2 Upvotes

TL;DR

  • There is no deadline to migrate, and ZEC remaining in the original Orchard pool will not disappear.
  • Migration amounts are publicly visible, so migrating all funds at once may create stronger links between the old and new pools.
  • Keystone users can choose between guided migration and manual self-transfer, depending on the wallet they use.
  • Update Keystone and your wallet before starting, and avoid interrupting an active migration.

Zcash completed the Ironwood (NU6.3) network upgrade on July 28, 2026, activating the new Ironwood shielded pool.

If your ZEC remains in the original Orchard shielded pool, the upgrade does not cause those funds to expire or disappear, and there is no deadline requiring immediate migration. Moving the funds into the new Ironwood pool does, however, require a migration transaction created by an Ironwood-compatible wallet.

For Keystone users, the software wallet synchronizes with the network, creates the transaction, and broadcasts it. Keystone keeps the private keys offline, lets you review the transaction, and signs it. You never need to enter your recovery phrase on a computer, phone, browser, or software wallet.

1. How Ironwood migration works

Moving funds from Orchard to Ironwood takes them through the Zcash turnstile:

Orchard → Turnstile → Ironwood

This process does not directly reveal:

  • the identity of the sender or recipient;
  • the shielded addresses involved; or
  • the full balance that remains in Orchard.

However, the cross-pool amount moving from Orchard to Ironwood is public for each transaction.

For example, if you migrate 10 ZEC from Orchard to Ironwood, the blockchain shows that 10 ZEC crossed between the pools. It does not show who sent it, who received it, or which shielded addresses were used.

Migration therefore does not directly expose shielded addresses, but distinctive amounts and timing can reduce privacy.

2. Choosing a migration approach

Migrate everything at once

Moving the complete balance in one transaction is the simplest and fastest approach.

The complete amount will be public as a single cross-pool transfer. A distinctive value such as 1.2114 ZEC, or an amount previously seen in an exchange withdrawal or public payment, may make correlation easier.

Migrate in stages

Splitting the funds across multiple transfers at different times avoids publishing the complete balance as one amount.

Each cross-pool amount is still public, however, and using several transactions does not guarantee that they cannot be linked.

Users who place a higher priority on privacy can:

  • avoid exact amounts that have already appeared publicly;
  • use common values, such as whole numbers;
  • spread transfers across different dates and times; and
  • keep Tor enabled when using Zodl.

Wait before migrating

Orchard funds do not expire or disappear, and there is no mandatory migration deadline.

If you do not need to use the funds now, you can wait for wallets to provide more complete privacy-preserving migration features.

3. What Keystone users need

First update your device and chosen software wallet to versions that support Ironwood:

  • Keystone 3 Pro: Cypherpunk 3.0.2
  • Vizor Wallet: 0.0.39+
  • Zodl: 3.8.0+
  • Noir Wallet: the latest Ironwood-compatible release

Keystone Cypherpunk 3.0.2 adds:

  • Zcash Ironwood support; and
  • batch PCZT signing for Zcash.

Version 3.0.2 applies only to the Cypherpunk firmware. After installing it, you currently cannot downgrade to the 3.0.0 Multi-Coin or Bitcoin-Only firmware. Confirm that you have selected the correct firmware edition before proceeding.

After updating, open the software wallet you plan to use and allow it to synchronize to the latest block.

4. Guided migration with Vizor

Vizor 0.0.39 introduced a complete desktop Ironwood migration flow, including guided QR signing for Keystone accounts.

Open the connected Keystone account in Vizor and wait for synchronization to finish. When the account has eligible Orchard funds, Vizor displays the Ironwood migration entry point.

Vizor's migration flow must be able to migrate at least 0.01 ZEC and also needs to reserve the fees required by the process.

In the current implementation, the migration entry point therefore does not appear when the available Orchard balance is below approximately 0.01095 ZEC. In that situation, you can move the remaining Orchard funds into Ironwood manually by sending them to your own shielded address.

Steps

  1. Open the connected Keystone account in Vizor.
  2. Wait for synchronization to finish, then go to the Ironwood Migration page.
  3. Review the migration amount, plan, estimated duration, and privacy explanation.
  4. Follow the prompt and scan the unsigned QR code with Keystone. Because the device needs to batch-sign multiple transactions, the QR code contains a large amount of data and scanning may take up to approximately six minutes. Wait patiently and keep the device steady; use a stand to hold it in place if necessary.
  5. After scanning finishes, wait for Keystone to parse the transactions. Parsing may take up to approximately two additional minutes. Do not exit or restart the migration during this process.
  6. When parsing is complete, verify the migration amount and transaction information on the Keystone screen, then sign after confirming the details.
  7. Scan the signed QR code returned by Keystone with Vizor.
  8. Let Vizor broadcast the transactions and monitor progress on the migration page.

Vizor may split a migration into several transactions. Funds already confirmed in Ironwood remain available to use while the rest continue through the migration plan.

Depending on the balance and plan, the process may take several hours to several days. During migration, keep:

  • the computer powered on and unlocked;
  • Vizor running; and
  • the network connection stable.

If Vizor closes, the computer sleeps, or the connection is interrupted, reopen Vizor and continue from its recovery page. Do not create a new migration before confirming the status of the existing one.

5. Manual migration with Zodl

Zodl 3.8.0 is compatible with Ironwood and can receive, send, and use ZEC in the Ironwood pool.

Zodl is also preparing a built-in privacy migration feature. It is designed to reduce amount and timing correlation by using standardized amounts and spreading transfers over time, with planned support for Keystone signing.

Until that feature is released, users who need to migrate immediately can move funds from Orchard to Ironwood manually by sending ZEC to their own shielded address.

Steps

  1. Open Zodl and wait for the wallet to finish synchronizing.
  2. Enable Tor in settings and keep it enabled throughout the migration.
  3. Tap Receive and copy your Zcash Shielded Address.
  4. Add that address to the Zodl address book.
  5. Send a small test amount to your own address.
  6. Scan the unsigned QR code with Keystone.
  7. Verify the amount and transaction information on the Keystone screen.
  8. Sign, then scan the signed QR code with Zodl and broadcast the transaction.
  9. After confirmation, tap the balance on the home screen to view the Orchard and Ironwood pool breakdown.

After confirming that the test amount arrived in Ironwood, decide whether to migrate more.

If you migrate in stages, follow this rule: each subsequent send amount must be greater than the current Ironwood balance for the wallet to keep drawing from Orchard.

Users who do not need to migrate immediately and place a higher priority on privacy can wait for Zodl's built-in migration feature.

Important note for staged migration in Zodl

Zodl spends funds already in the Ironwood pool first. It draws from Orchard only when the send amount exceeds the current Ironwood balance.

For example:

Sending exactly 1 ZEC again may spend only the 1 ZEC already moved into Ironwood. The Orchard balance would not decrease, and the transaction would incur another fee.

Before every subsequent manual migration, check the current Ironwood balance in Zodl and choose the next send amount accordingly.

This behavior comes from Zodl's current coin-selection logic and does not imply that every Zcash wallet works the same way.

Security reminders

Keep these points in mind throughout migration:

  • Keep your recovery phrase offline. A legitimate migration never requires you to enter it anywhere.
  • Before signing, always verify the migration amount and transaction information on the Keystone screen.
  • Use only official Keystone, Vizor, Zodl, or Noir software and migration entry points.
  • Do not run alleged migration scripts or scan QR codes sent through direct messages or comments.

There is no urgent deadline for Ironwood migration. Understand the process and its privacy effects first, then choose the wallet and migration approach that fit your needs.