Open-source firmwareShips to anywhereBitcoin-only mode available7,000+ supported assetsFree firmware updates for lifeSince 2014Fully auditable hardwareTHORChain swaps built-inOpen-source firmwareShips to anywhereBitcoin-only mode available7,000+ supported assetsFree firmware updates for lifeSince 2014Fully auditable hardwareTHORChain swaps built-in

Founded 2014 — Open Source Firmware + Hardware

The wallet you can verify.

Firmware, hardware schematics, and standard off-the-shelf parts — all published, all verifiable. Built-in decentralized swaps. All EVM chains. Clear signing. Premium aluminum.

Get Started
10+ years
Open source
400+ coins

Why KeepKey

Your crypto deserves a black box you can open.

Most hardware wallets ask you to trust them. KeepKey asks you to verify. Every line of firmware code, every circuit on the board — published on GitHub.

Fully Open Source

Device OS, firmware, AND hardware schematics on GitHub — built from commodity parts anyone can source.

Clear Signing

Auto-detects contract calls from public ABIs. No registry opt-in needed. Shows decoded transaction details on the device screen.

Built-in Swaps

Trade cross-chain directly from your wallet via THORChain, ShapeShift, and ChainFlip. Decentralized protocols only.

All EVM Chains

Every EVM chain works via EIP-155. Add custom chains by chain ID — the same 'Add Network' as MetaMask but with hardware security.

Scrambled PIN & Recovery

PIN entry uses a randomized grid — keyloggers capture nothing. Recovery uses scrambled cipher entry.

Vault Desktop App

Free companion app for macOS, Windows, and Linux. Portfolio dashboard, cross-chain swaps, staking, activity tracking.

Chain Support

Every chain. No app installs.

All chains available simultaneously from firmware. No storage limits. No switching between apps.

ChainKeepKeyLedgerTrezorOneKeyMetaMaskCoinbase
Bitcoin
*
Ethereum
*
Solana
*
TON
*
TRON
*
Zcash
*
THORChain (RUNE)
3rd party
Avalanche
*
Cosmos
*3rd party
BNB Smart Chain
*
BNB Beacon
*
Dogecoin
*
Bitcoin Cash
*
Litecoin
*
Osmosis
3rd party
Ripple
*
Maya Protocol
3rd party
Any EVM (EIP-155)
3rd party3rd party
*

Ledger requires installing a separate app on the device for each chain. Device storage is limited.

Based on official vendor documentation as of March 2026.

Cross-Chain Swaps

Decentralized cross-chain swaps.

Swap between chains via decentralized protocols — THORChain, ShapeShift, and ChainFlip. No KYC, no account.

Decentralized-only providers: THORChain, ShapeShift, ChainFlip
No centralized exchange, no KYC, no account
Full swap transparency — route, fees, slippage visible before signing
Confirm every swap on the device screen
Resume in-progress swaps from the activity panel
PDF export for tax records

How a swap works

1

Select assets

Choose source and destination chains. Enter amount.

2

Review details

See route, fees, slippage, and estimated output.

3

Confirm on device

KeepKey displays exact amounts. Press button to approve.

4

Track progress

Monitor the swap through to completion in Vault.

Clear Signing

See what you sign.

KeepKey auto-detects contract calls using public ABIs and displays decoded transaction details on the device screen.

KeepKey

Auto-detected from public ABIs

Works on ANY EVM chain (including custom)
No DApp developer opt-in needed
Native TON clear-signing
Two-step blind signing confirmation

Ledger

ERC-7730 registry (manual opt-in)

EVM only (via ERC-7730)
Each DApp must submit metadata to registry
Falls back to blind signing when metadata missing
Metadata controlled by Ledger signing keys

Trezor

Per-chain firmware implementation

No Solana message signing
No TON support
No TRON support
No custom EVM chains in Suite

Security Model

Verify, don't trust.

Your private keys are generated on the device and never leave it. Every transaction is signed on the KeepKey and displayed on the OLED screen.

Large OLED Display

Verify every transaction detail on-device before signing

Scrambled PIN

Randomized grid defeats keyloggers and screen-watchers

BIP-39 Recovery

12 or 24-word seed phrase. Your keys, your coins, forever

BIP-39 Passphrase

Hidden wallets for plausible deniability

BIP-85 Derived Seeds

Generate hot wallet seeds on-device. Re-derive anytime from your KeepKey

Auditable Code

Firmware + hardware schematics on GitHub. Verify every circuit and every line

Hardware Transparency

What's inside a KeepKey.

KeepKey is a small, auditable computer. Every component is a standard, off-the-shelf part. No proprietary chips. No black boxes.

STM32F405 ARM Cortex-M4

Industry-standard 32-bit microcontroller. Public datasheet, no NDA required.

256×64 SSD1322 OLED Display

High-contrast OLED for on-device transaction verification.

Aluminum Enclosure

Premium aluminum body. DIY builders can 3D-print a case from published designs.

USB Connection

Standard USB for power and data. Compatible with any operating system.

No Proprietary Secure Element — By Design

Uses standard commodity components. Security through transparency, not obscurity.

Build Your Own

Hardware schematics, PCB layouts, and BOM on GitHub. github.com/keepkey/keepkey-diy

Hardware VerificationKeepKeyTrezor (Safe 7)Trezor (Safe 3/5)Ledger
Firmware / Device OSOpen sourceOpen sourceOpen sourceClosed (BOLOS)
Hardware SchematicsPublished on GitHubPublished (OSHWA certified)Published (OSHWA certified)Not published
Secure ElementNone (by design)TROPIC01 — not yet independently auditedATEC/SE050 — proprietaryST33 — NDA required
DIY ReproducibleYes — commodity partsNo — requires TROPIC01No — requires SE chipNo
Silicon-Level VerificationN/A (no custom silicon)No published RTL/GDSIINot publicly verifiableNot possible

Sources: vendor documentation, github.com/keepkey/keepkey-diy, OSHWA certifications. March 2026.

Software Ecosystem

One device. Three free apps.

Comparison

KeepKey vs Ledger vs Trezor.

Side-by-side comparison based on publicly available specifications. March 2026.

FeatureKeepKeyLedger Live*Trezor Suite*
Price$79–$399$79–$299
Open Source Device OS
Open Source Hardware Schematics
No Proprietary Secure Element
Custom EVM Chains in Companion App
No App Install on Device
Built-in Cross-Chain Swaps
THORChain (RUNE) Support3rd party
TON Support
TRON Support
Zcash Shielded (Orchard)
Solana DApp Message Signing
Clear Signing (Auto-Detect from ABI)
BIP-85 Derived Seeds
REST API for Developers
Full Aluminum BodySafe 7 only

Both KeepKey and Trezor publish open-source hardware schematics.

For Developers

REST API. Build on KeepKey.

KeepKey Vault exposes an optional REST API on localhost:1646 for developers who want to build integrations with hardware wallet security.

REST API with Swagger documentation
Audit log with sanitized signing payloads
Paired app management
Off by default — opt-in via Settings
Timing-safe API key validation

# get device features

curl http://localhost:1646/api/device

# get portfolio

curl http://localhost:1646/api/portfolio

# swagger docs

open http://localhost:1646/spec/swagger.json

Get Started

Set up in 5 minutes.

01

Buy KeepKey

Premium aluminum. Available in 5 colors. Free shipping.

02

Download Vault

Free desktop app for macOS, Windows, and Linux. Plug in your KeepKey and the setup wizard handles the rest.

03

Secure Your Crypto

All chains available immediately. Send, receive, swap, and stake — all signed on your device.

FAQ

Common questions.

What makes KeepKey different from Ledger and Trezor?
KeepKey publishes firmware, hardware schematics, and uses standard off-the-shelf components with no proprietary secure element. Both KeepKey and Trezor are open-source hardware wallets — Trezor also publishes OSHWA-certified schematics. Ledger open-sources chain apps but their device OS (BOLOS) and hardware design are closed. KeepKey also lets you add custom EVM chains in the Vault app (Ledger Live and Trezor Suite cannot), has built-in cross-chain swaps via decentralized protocols like THORChain, and costs significantly less than competitors.
How many cryptocurrencies does KeepKey support?
KeepKey supports all EVM-compatible chains (unlimited, via EIP-155 chain ID) plus Bitcoin, Solana, TON, TRON, Zcash (including Orchard shielded transactions), Cosmos, Osmosis, THORChain, Maya Protocol, Dogecoin, Litecoin, Bitcoin Cash, Ripple, and more. You can also add any custom EVM chain by entering its chain ID and RPC URL — the same "Add Network" feature found in MetaMask, but with hardware wallet security. No other hardware wallet companion app offers this.
What is clear signing and how does KeepKey handle it?
Clear signing means the hardware wallet displays human-readable transaction details on its trusted screen instead of raw hex data. KeepKey auto-detects contract calls using publicly available ABIs — no registry submission required by DApp developers. This gives broader coverage than Ledger's ERC-7730 registry (which requires each DApp to manually opt in) and works on any EVM chain including custom ones you add yourself. KeepKey also has native TON clear-signing. For transactions that cannot be decoded, a two-step confirmation with a permanent-change warning is required.
Can I swap crypto directly on KeepKey without an exchange?
Yes. KeepKey Vault has built-in cross-chain swaps via THORChain, ShapeShift, and ChainFlip — all decentralized protocols. You can swap between any supported chain (for example, ETH to BTC) directly from the Vault desktop app. Your keys never leave the hardware device. No exchange account, no KYC. Funds are routed through decentralized protocol vaults controlled by independent node operators via threshold signatures — not through any company's servers. The swap is an on-chain transaction signed by your KeepKey.
Is KeepKey easy to set up?
Yes. Download the free KeepKey Vault app (macOS, Windows, Linux), plug in your device, and the setup wizard guides you through firmware update, PIN creation, and seed phrase backup in about 5 minutes. The app auto-detects your operating system. All supported chains are available immediately — no app installs or storage management like Ledger requires.
What is BIP-85 and why does KeepKey support it?
BIP-85 lets you derive deterministic child seed phrases from your master seed. KeepKey displays derived seeds only on the device screen — they never appear on your computer. Use case: generate a MetaMask seed that is recoverable from your KeepKey at any time. If you lose the MetaMask seed, re-derive it from your hardware wallet. Your master seed stays secure.
Does KeepKey support Zcash shielded transactions?
Yes. KeepKey firmware 7.14 supports Zcash Orchard shielded transactions — z-to-z transfers and shield-wrap using the PCZT builder. As of March 2026, Ledger and Trezor support only transparent Zcash transactions — they cannot create shielded sends. KeepKey Vault enforces ZIP-317 fees so shielded transactions are accepted by the network.
Does KeepKey have a REST API for developers?
Yes. KeepKey Vault exposes an optional REST API on localhost:1646 (off by default, opt-in via Settings). It includes Swagger documentation, an audit log, and paired app management. Developers can build integrations that sign transactions with hardware wallet security.

Get KeepKey updates

New chain support, firmware releases, and security advisories. No spam.

No spam. Unsubscribe anytime.

Stop trusting. Start verifying.

Open-source firmware and hardware schematics. All EVM chains. Built-in swaps. Clear signing. Premium aluminum. Founded 2014.

Download Vault
KeepKey Hardware Wallet — Open Source, 400+ Coins, Built-in Swaps | KeepKey Hardware Wallet