The most user-friendly, open-source, air-gapped hardware wallet 🛡️| Secure BTC, ETH & 1000+ coins.

Decentralized
Buy Keystone Anonymously 💪 The privacy-friendly PO Box delivery option is live now! No home address needed. Order your Keystone to the nearest PO Box. No data shared = no leak risk. Combined with our existing privacy pickup option, this is a perfect addition to your privacy setup. Your asset safety and personal safety are non-negotiable for us. A few things to note before your PO Box order: → Ensure your PO Box is active and able to receive packages. Double-check the PO Box address before ordering. → Once tracking shows "Delivered," the package is considered delivered, and no further shipping claims can be initiated. Privacy is for everyone 🔒
7
16
105
16,823
Your hardware, your code, your rules 🛠️ ForgeBox lets you program Keystone, set your own signing keys, and experiment without limits. Same rock-solid build. Full control. No guardrails. Start building with ForgeBox 👇keyst.one/shop/products/keys…
Hello, ForgeBox. For a long time, cryptography researchers and developers have lacked a dedicated hardware device built for customization and experimentation. Not a finished wallet. Not a closed HSM. But a device you can fully control. • Blockchain researchers running custom firmware to test new cryptographic algorithms and protocols • Wallet developers integrating specialized security mechanisms to protect private keys and sensitive data • Educators teaching the fundamentals of cryptography and blockchain with programmable hardware ForgeBox is built for exactly this. Powered by the Keystone 3 hardware wallet architecture, ForgeBox features: • 🛡️ Three secure elements • 🔌 USB-C + QR code connectivity • 🔓 Fully open-source Whether you’re doing research, building products, or teaching, ForgeBox provides a powerful and flexible platform for secure experimentation. What can you build with ForgeBox? •🤖 Agents: secure private data storage and isolated execution container for agents like #OpenClaw 🦞 •🔐 Your own HSM: generate, store, and use keys for encryption, decryption, and signing •⛓️ Blockchain protocols: test new cryptographic primitives and build secure key-management solutions • 🎓 Education: teach crypto with hardware that actually runs it • …and much more, defined by the community With ForgeBox, the possibilities are open-ended. Pre-orders are open. If you’re a developer, DM me — let’s build something interesting together 🚀.
13
1,578
Once you choose Keystone 3 Pro, you will never turn back 🔥 Thank you for this, @0xQuit 💙
Replying to @midtrader
tbh probably going to get a @KeystoneWallet to use as my daily driver
6
1
38
4,439
Most people never verify their signing device's firmware before updating. Here's how: 1️⃣ Load firmware onto an SD card 2️⃣ Settings → About → Firmware → Via MicroSD → Update → Show Checksum 3️⃣ Match the hash against the SHA-256 Checksum on GitHub Don't trust. VERIFY.
2
5
38
2,264
When Solana hit $8, most hardware wallets were looking the other way. We shipped @SolflareWallet integration instead. Air-gapped, QR-only. Bear market, didn't matter. That was three years ago. Here's everything that followed: @Backpack: QR and USB signing across extension and mobile. @JupiterExchange: Day 1 support on Keystone 3 Pro. @multisig Squads: clear-signing for on-chain treasury management. @SolanaFndn: native hardware wallet support coming to the Solana CLI. Along the way, @toly co-signed what we were building. When the founder of the chain you bet on tells you you're on the right track, you don't second-guess it. 500B+ total transactions. $3T+ DEX volume. $900M+ in ETF inflows. Solana grew into all of that. We were just early enough to be ready 🔧 Three years in and still shipping. What do you want us to build next for Solana? Drop your feedback below 👇
1
20
1,919
If you hold $ZEC, here's the only plan worth knowing👇 Under 0.5 ZEC? @zodl_app does the job. 0.5+ ZEC? Keystone + @zodl_app, fully shielded & secure. Hot wallets are for exposure. Hardware wallets are for ownership. Don't just hold ZEC. Shield it 🛡️
If you hold $ZEC, here's the only plan worth knowing👇 Under 1 ZEC? @zodl_app does the job. 1+ ZEC? Keystone + @zodl_app, fully shielded. Hot wallets are for exposure. Hardware wallets are for ownership. Don't just hold ZEC. Shield it 🛡️
3
2
29
3,186
Happy 9th Birthday, Cardano 💙
Nine years ago today, Cardano minted its first block. A global community has been building this blockchain ever since. Some are in this video, and many more are reading this. This celebration is yours. Happy 9th birthday, Cardano.
1
3
50
2,796
Still searching for the right signing device for @Cardano? Keystone 3 Pro checks every box 🫡 → Works with Eternl, Vespr & more → Cardano-CLI support → Clear-signing upgrades → Community-loved 💙 Drop this on a friend who needs to see it 👇
2
512
Still searching for the right signing device for @Cardano? Keystone 3 Pro checks every box 🫡 → Works with Eternl, Vespr & more → Cardano-CLI support → Clear-signing upgrades → Community-loved 💙 Drop this on a friend who needs to see it 👇
Your @Cardano experience just got clearer 🤩 Keystone V3.1.0 lets you see exactly what you're signing. Update your Keystone 3 Pro, pair with @eternlwallet or @vesprwallet, and sign with confidence. Got a Cardano friend signing blind? Tag them 👇
5
9
56
5,764
One thing most passphrase users miss: your wallet has a Master Fingerprint (MFP). Since Keystone never stores your passphrase, this ID confirms you're in the right wallet. Managing multiple passphrase wallets? Tell them apart by MFP. If it matches, you're in the right place.
6
2
55
4,663
⚠️ In May 2024, someone lost 1155 WBTC in one of the most regrettable ways possible: By copying an address from the transaction history. A scammer had already slipped a look-alike address into that history. One wrong copy-paste, one confirmation, and it was over. On-chain transactions don't have an undo button. This is called address poisoning, and it works because most people only glance at the first and last few characters before sending. That's the whole attack. What actually keeps you safe: → Never pull an address from your transaction history. Go back to the original source every time. → Check the full address. Every character. → Keystone paired with Rabby & MetaMask will flag any new address before you sign. That warning exists for a reason. Keystone 3 Pro shows the complete address on its air-gapped screen so you can verify exactly what you're signing before anything moves. 1155 WBTC lost over a 10-second shortcut. Learn the lesson now before it costs you.
3
4
57
4,372
Hey @Zcash maxis, a friendly reminder: Shield your zcash:native with @zodl_app + Keystone 3 Pro and keep your on-chain privacy where it belongs. You're welcome 🤝
Get you a @KeystoneWallet - get you more Zcash $ZEC and shield dafuq out of it Government and Scammers do not need to know what you got
7
3
60
3,982
RAT malware drained $235K in crypto across hundreds of wallets, all in under 48 hours. The attack vector? Your device. Credential harvesting. Clipboard monitoring. Session hijacking. Once a RAT owns your machine, what you see on screen and what actually gets signed can be two very different things. That's the real trap. You think you're approving a legit transaction. The RAT has already swapped the destination. Stay ahead of it: 🔹 Never download from unverified sources 🔹 Keep your OS and browser updated 🔹 Run endpoint security software 🔹 Use a hardware key for MFA, not SMS And for your crypto, use a hardware wallet with clear signing. Keystone shows every transaction detail on the device itself, offline, before you sign. Actual recipient, amount, contract call, all verified on hardware the malware can't touch. You see what you sign. You sign what you see.
Clear-signing on Keystone 3 Pro just leveled up 🔥 ABI library V3.0.3 is live: ↳ Added 15,107 new contracts from ETH & BSC ↳ See exactly what you're signing before you sign it Special thanks to @BlockSecTeam for helping us on this! Update now — blind signing ends here 🛡️
3
5
37
3,301
GM Keystone fam 🌞 Using your Keystone out in public? Randomized PIN pad in settings keeps shoulder surfers guessing 😵‍💫 Or just use the fingerprint sensor to unlock and sign txns without a PIN at all ✨ Your Keystone. Your crypto. Your rules 💪
Security sharpened. Capability expanded. 🔥 With the latest V-2.2.14, Keystone adds: ‣ BSC transfers + swaps in the Nexus app ‣ A scrambled PIN pad to confuse prying eyes Update today, and tell us what you want for the next update.
6
5
66
5,465
⚠️ A malicious app just read crypto wallets it was never supposed to touch. It didn't fake anything. It didn't trick anyone into entering their seed phrase. It just exploited an iOS vulnerability and pulled the data directly from other apps on the same phone. SlowMist and OKX confirmed it: FomoPepe versions 1.1-1.2 contained a kernel exploit that escapes the app sandbox and reads straight from your Keychain. The wallet app was real. The user did nothing wrong. Didn't matter. This is the problem with storing keys on a smartphone. You're not just trusting your wallet app. You're trusting every other app on the device, every system vulnerability, and every future exploit nobody has found yet. Updating iOS helps. But you're always one step behind. There's only one way to stay ahead: never keep your keys on your phone. 🔐 A hardware wallet generates and stores your seed phrase offline. What's never in that environment can never be taken from it.
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2. A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️ Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version. ‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️ If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device. 🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed. The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands. Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk. If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately: 1️⃣ Check your accounts and assets for any unusual activity. 2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase. 3️⃣ Move your assets to the new account as soon as possible. 4️⃣ Update your device to the latest available iOS version. 5️⃣ Do not continue using or reinstalling FomoPeek. 6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
7
22
108
16,258
Your @Cardano experience just got clearer 🤩 Keystone V3.1.0 lets you see exactly what you're signing. Update your Keystone 3 Pro, pair with @eternlwallet or @vesprwallet, and sign with confidence. Got a Cardano friend signing blind? Tag them 👇
14
30
167
9,272
Keystone Hardware Wallet retweeted
Clear signing with @KeystoneWallet on @iota is amazing 🤩
Sign your next @IOTA txn with absolute confidence 💪 Our latest update, V-3.1.0, brings transaction parsing so you can verify transfer and staking details right on your Keystone screen. See "Unknown Transaction"? You still get the raw data right on screen to verify what you're signing. Update your Keystone now, sync with @Nightly_app, and sign with clarity. Share this with iota:native maxis in your circle.
12
74
2,128
Sign your next @IOTA txn with absolute confidence 💪 Our latest update, V-3.1.0, brings transaction parsing so you can verify transfer and staking details right on your Keystone screen. See "Unknown Transaction"? You still get the raw data right on screen to verify what you're signing. Update your Keystone now, sync with @Nightly_app, and sign with clarity. Share this with iota:native maxis in your circle.
1
21
95
6,259
You asked & we delivered 🙌 With V-3.1.0, Keystone now defaults to sub-account path-based addresses instead of account-based paths for Solana. Here's how it improves compatibility with popular Solana wallets: → Addresses match during pairing → Easier recovery & migration Combined with our existing Solana wallet & CLI support, this is another step toward a smoother Solana experience on Keystone. Got feedback or suggestions to improve it further? Drop them below ⬇️
2
22
2,221
HP's security team just flagged an attack specifically targeting crypto users. Here's how it works: 🔴 Malware disguised as an "AI Crypto Trading Agent" spreads through search results and ads. 🔴 Once installed, it scans your Chromium browser for wallet extensions (MetaMask, OKX Wallet, Phantom, and others). 🔴 When it finds one, it kills the browser process, swaps in a fake extension, and replaces the real one. When you reopen your browser, everything looks normal. But the moment you enter your password to unlock your wallet, it goes straight to the attacker, along with your local wallet data. That's enough for a full takeover. A few things worth doing: 🔵 Don't download AI agents or trading bots from random search results. If you use a specific tool, get it directly from the official site. 🔵 Keep a separate browser profile for anything crypto-related. 🔵 Store large holdings in a hardware wallet. Even if your hot wallet gets compromised, your funds stay safe.
HP says a fake AI crypto-trading tool delivered malware that replaced browser wallet extensions with credential-stealing copies. The campaign targeted wallets including MetaMask, Phantom, Coinbase Wallet, Trust Wallet and OKX Wallet after users ran the counterfeit software. cryptoslate.com/hp-says-fake…
2
5
46
4,447