Own your keys on hardware you can read
1 · Order direct from the manufacturer. Never marketplaces, never resellers — supply-chain tampering is the one attack you can decline by habit.
2 · Your written 24 words are the floor at every rung. The device is a lock; the phrase is the door that survives every device.
3 · Verify what you receive: check the seal ritual the maker documents, and confirm firmware signatures on first boot. If a step feels skippable, that's the step.
The ladder at a glance
| $ | Rung | Device | Air-gap |
|---|---|---|---|
| $0 | Spare phone, optical | your own onboarding surface | screen ⇄ camera |
| ~$50 | Build-it-yourself | SeedSigner · Krux | QR only, stateless |
| $59–79 | First open commercial | Trezor Safe 3 | USB (not air-gapped) |
| $79–169 | Open budget / multi-chain | Jade Plus · Keystone 3 Pro | QR camera |
| $249 | The anchor | Trezor Safe 7 (bSAFE) | USB · BLE(Noise) · beam-capable |
| $349 | Premium open air-gap | Passport Prime | QR camera · microSD |
Trezor Safe 7
firmware openschematics publicauditable SE (TROPIC01)FIDO2not QR-air-gapped stockThree hardware layers — TROPIC01 (the first secure element outside researchers can audit), an EAL6+ SE, and an open MCU — plus a committed post-quantum path. The BNR fork (bSAFE 7) adds what the mission needs, including the optical beam. Trezor has shipped open firmware since the first generation; that track record is the product.
SeedSigner
fully openstateless — no secrets at restcommodity partsBitcoin-onlyA signer you assemble yourself from a Pi Zero, camera, and screen. It holds nothing when powered off — the seed enters per session by QR or dice. No customs form flags it, no company can stop making it, and building one teaches more than reading ten reviews. The rung that turns users into producers.
Krux
fully openruns on cheap K210 boardsBitcoin-onlySame philosophy as SeedSigner on different silicon — flash open firmware onto an off-the-shelf device with a camera and screen. A second independent implementation of the same idea is health, not redundancy.
Trezor Safe 3
firmware opensecure elementFIDO2USB onlyThe cheapest fully-open-firmware commercial signer — and because it speaks FIDO2, the same $59 object can be your passkey. The natural first step off the spare-phone rung.
Blockstream Jade / Jade Plus
fully open, board includedQR camera air-gapno SE — blind-oracle model (disclosed)BTC/Liquid onlyOpen to the last line, cheap, camera-based QR signing. Its twist: instead of a secure element, the key is sealed to a rate-limited oracle — run Blockstream's or your own. That dependency is honest and disclosed, and self-hosting the oracle fits a sovereign stack unusually well.
Keystone 3 Pro
app + SE firmware openQR/UR nativehardware partially openno FIDO2The pragmatic pick if you arrive holding many chains: broad support, BC-UR animated-QR signing with every major software wallet, and — rare anywhere — the secure-element firmware is published. Know its limits and it serves well.
Foundation Passport Prime
CERN-OHL-S open hardwareKeyOS: Rust microkernel, apps get child seedsQR + microSDFIDO2The most architecturally interesting open device shipping: a Rust microkernel OS where each sandboxed app receives a hardened child seed and can never touch the root. Open hardware under a real open-hardware license, not just published schematics. Priced for the committed.
BitBox02 · OneKey · Cypherock X1
open firmwareBitBox02: clean open firmware, USB-only — solid, adds no modality. OneKey: open multi-chain alternative. Cypherock X1: no seed phrase at all — the key is Shamir-split across NFC cards, a genuinely different recovery geometry worth studying.
Ledger — closed secure element, and the Recover service proved firmware can extract seed material to third-party custodians. Fails the sovereignty test at the architecture level, not the feature level.
Coldcard — battle-tested hardware, but the firmware license left OSI open source after the Passport fork dispute. Source-visible is not open; excluded on license, respected on engineering.
NGRAVE, Tangem, and card-style wallets — closed firmware and/or no display to verify what you sign. If you cannot read it and cannot see it, it is not yours.
the manufacturer shelves
Every card opens the manufacturer's own product page in a new window. We show, we never middleman.