Accepting Q3 2026 engagements

Security audits for
hardware wallets

We break wallets before adversaries do. Deep embedded & cryptographic security reviews by world-renowned researchers — with publishable reports your customers can rely on for due diligence.

15+ yrs
Security auditing

Trusted by teams securing billions in digital assets

Services

Full-stack wallet security

From silicon to signing flow — we audit every layer an attacker can touch.

Hardware Wallet Audits

Secure element review, firmware analysis, side-channel & fault-injection testing, and supply-chain attack surface mapping.

  • Secure Element
  • Side-Channel
  • Glitching

Protocol & Signing Security

Multi-party signatures, key derivation, seed backup strategies, and transaction validation flows reviewed end-to-end.

  • MPC
  • BIP-32/39
  • Multisig

Secure Architecture

Design-stage reviews for new devices: threat modeling, architecture audit, and exchange / custody integration hardening.

  • Threat Modeling
  • Design Review
Public Reports

Most recent reports

Reports released with client permission as part of customer due diligence.

Passport Prime
Foundation Devices · Hardware wallet · firmware & hardware security audit
Keylabs conducted a comprehensive hardware and firmware security audit of the Foundation Passport Prime hardware wallet, finding no critical or high-severity vulnerabilities and only five low-impact issues that were subsequently addressed. The device demonstrates exceptional security through a multi-layered architecture built around the SAMA5D2 microcontroller and ATECC608C secure element, featuring a three-factor seed protection scheme that splits key material across encrypted non-volatile storage, automatically clearing SECURAM, and a user PIN. The audit concludes that Passport Prime’s defense-in-depth design, comprehensive tamper detection, wireless isolation, and unsuccessful fault injection attempts establish a highly secure architecture that exceeds industry standards.
2025-0923 pagesPDF ↓
ERA Wallet
ERA Wallet · Hardware wallet · threat model, hardware & firmware audit
The ERA Wallet security audit evaluated the hardware wallet's threat model, architecture, hardware, and firmware, identifying no critical vulnerabilities but revealing several hardware weaknesses and firmware flaws ranging from informational to medium severity. Key issues included format string vulnerabilities and inadequate entropy generation in the immutable bootstrapper, accessible debug interfaces and missing tamper protection on pre-production hardware, and glitching susceptibility in the STM32H7 microcontroller. Retesting confirmed that medium-severity firmware issues were resolved prior to release, while production hardware incorporated fixes such as epoxy encapsulation and removed debug interfaces, resulting in a robust architecture centered on the STM32H753 processor and ATECC608C secure element.
2024-1237 pagesPDF ↓
Keystone 3
Keystone · Hardware wallet · firmware & hardware security audit
This November 2023 final audit report by Keylabs evaluates the Keystone3 hardware wallet's security across its threat model, architecture, firmware, and hardware. The assessment identified one high-severity firmware vulnerability related to inadequate tamper response verification, alongside several low-severity findings concerning entropy injection, compiler-optimized security functions, and physical tamper circuit limitations. While the device demonstrates robust security innovations—including three secure elements, PUF-based keys, a mesh-shielded PCB, and a battery-backed tamper circuit that irreversibly bricks the device—certain tamper-related hardware behaviors and exposed test points were accepted as requiring no immediate fix. Keylabs verified that the high-severity and two low-severity firmware issues were successfully mitigated and retested, though four low-severity hardware findings remain accepted risks.
2023-1121 pagesPDF ↓
Cypherock X1
Cypherock · Hardware wallet · firmware & secure element audit
The Keylabs audit of the Cypherock X1 hardware wallet found an innovative, distributed security architecture using Shamir Secret Sharing, EAL5+ JavaCards, and an STM32L4 paired with an ATECC608A, though no critical vulnerabilities were identified. Several low-severity hardware and firmware issues were discovered, including accessible PCB test points, lack of potting mitigated by conformal coating in production, outdated third-party libraries, poor random number generator practices, missing SBOMs, and unsafe string handling. An informational finding also questioned the Proof of Work PIN recovery mechanism for risking flash wear-out and effective permanent lockout. Cypherock remediated all findings, which Keylabs subsequently verified.
2022-1012 pagesPDF ↓
Passport (Original)
Foundation Devices · Hardware wallet · boot, firmware verification & login audit
Keylabs conducted a security audit of the pre-production Foundation Devices Passport hardware wallet, uncovering critical vulnerabilities in the bootloader and firmware update mechanisms, including downgrade protection bypasses, unauthorized firmware upgrade triggers, and a defeatable boot counter. The audit also revealed cryptographic and hardware weaknesses such as weak AES-CTR counter reuse, unsigned external flash contents, and susceptibility to fault injection, electromagnetic side-channel leakage, and attacks against the ATECC608A secure element. Foundation Devices remediated the identified issues with defensive guidance from Keylabs, which subsequently sanity-checked the fixes, though the assessment was limited to pre-production hardware and noted the processor's lack of privilege separation and active tamper detection.
2021-065 pagesPDF ↓
Process

How an engagement works

  1. 01

    Scoping

    We map the attack surface: hardware, firmware, companion apps, and update infrastructure.

  2. 02

    Deep-dive audit

    4–6 weeks of manual review, fuzzing, side-channel analysis, and fault injection in our lab.

  3. 03

    Remediation

    Findings reported with severity and PoCs. We work with your engineers until fixes land.

  4. 04

    Publishable report

    A re-test and a polished public report your customers can use for due diligence.

Engagements

Audit packages

Architecture

$40,000

Design-stage architecture & threat-model audit.

Request package
Contact

Get a proper solution

Tell us about your device. We reply within 48 hours.