Keystone 3 Pro Setup Tutorial

Keystone 3 Pro Setup Tutorial

This is the full first-time setup for the Keystone 3 Pro, written the same way I walk through it on camera. Do this at home. Not on a livestream. Not with a webcam pointed at the seed screen.

Affiliate link if you want the current listing: Keystone 3 Pro

What you need before you start

  • The sealed Keystone 3 Pro box
  • The USB-C cable from the box (charging and firmware, not for signing)
  • A phone or computer with a working camera
  • A pen
  • Optional but smart: a FAT32 microSD card, 32 GB or 64 GB, max 512 GB. Not included in the box
  • Battery at least 20% before you touch firmware. Keystone now asks for about 40% on some SD updates

1. The package

Check the box before you open it. If the wrap is sliced or it looks resealed, stop and talk to the seller.

Official start page later is keyst.one/start. Device check is keyst.one/verify. Firmware is keyst.one/firmware. Bookmark those three. Nothing else.

Keystone 3 Pro retail box

Keystone 3 Pro retail box. Confirm the seal before you open it.

2. Unboxing

Inside you should have:

  • The Keystone 3 Pro
  • USB-C cable
  • Quick start guide
  • Seed phrase papers (six sheets)

No microSD card in the box. Power button on the right. USB-C on the bottom. microSD slot on the left. Camera on the back for QR codes. Fingerprint sensor on the unit. 4-inch touchscreen on the front.

Plug it in with the USB-C cable if the battery is low. Charge only. Do not approve USB data unless you are doing an official firmware update on purpose.

Keystone 3 Pro unboxing contents

In the box: Keystone 3 Pro, USB-C cable, quick start guide, and seed papers. Bring your own FAT32 microSD card if you want the offline firmware path.

3. Verify the device before you create a wallet

This is the step people skip and then worry about later. Do it first.

  1. Turn the Keystone on.
  2. On a computer, open keyst.one/verify only.
  3. On the site, choose scan QR code.
  4. Point the Keystone camera at the QR on the website.
  5. The Keystone shows a short verification code.
  6. Type that code back into the official page.

If it fails, stop. Do not create a seed on a unit that will not verify.

You can also check firmware later with a checksum on an SD update (Device Settings > About > Firmware > Via MicroSD Card > Show Checksum) and compare it to the hash on keyst.one/firmware.

Keystone 3 Pro device verification by scanning QR code

Official verify page only. Scan the site QR with the Keystone camera, then type the code from the device back into keyst.one/verify.

4. Update firmware before you deposit anything

Out of the box the unit may not be on current firmware. As of late 2026 the multi-coin line is around v3.0.4. If you are below v2.4.0, install 2.4.0 first. That build patched a USB SDK issue. Then step up to current.

Two paths:

USB (easier): keyst.one firmware / WebUSB page. Battery high enough. On the device: ... > Device Settings > About > Firmware Update > Via USB. Approve USB access when the device asks. Charge-only mode is the default for a reason.

microSD (air-gap style): Format the card FAT32. Download only keystone3.bin from the official firmware page. Put that one file in the root. No extra files. No keystone3(1).bin name. Insert the card on the left. ... > Device Settings > About > Firmware Update > Via MicroSD Card.

Pick a firmware branch before you live on the device:

  • Multi-coin: default. Most users.
  • Bitcoin-only: smaller attack surface if you only hold BTC.
  • Cypherpunk: BTC plus privacy coins such as ZEC and XMR.

You can switch branches later. You cannot roll a version backward. The updater will never ask for your seed. If a page does, close it.

5. Create the wallet and pick a backup method

On the Keystone tap Create New Wallet. Do not import a seed you generated on a website.

Set a password / PIN on the touchscreen. Name the wallet. Then you hit the backup screen. This is where Keystone is more flexible than a basic 24-word brick.

Options:

  • Standard seed: 12 or 24 words. 24 is what I use.
  • Shamir Backup (SLIP-39): split the secret into shares. You choose how many shares and how many you need to recover. Example: 3-of-5. Store the shares in different places.
  • Dice rolls: on firmware 1.2.6 or newer. At least 50 rolls. 99 rolls if you want the full 256-bit path. Then back up whatever seed that produces.

Write the words or Shamir shares on the paper from the box. No photo. No cloud. Confirm them on the screen in the right order.

This device can hold up to 3 separate seeds. Add more later from Device Settings > Wallet Settings > Add Wallet. Each wallet can have its own password.

Fingerprint is optional after the wallet exists. Enroll it in wallet settings. It can unlock and approve. It cannot replace the paper backup.

Keystone 3 Pro backup method selection screen

Create New Wallet, then pick standard 12/24 words, Shamir shares, or dice-roll entropy. Write it offline. Confirm the words on the 4-inch screen.

6. Connect software wallets

Keystone does not force you into one official portfolio app. You pick a software wallet and bind it with QR codes.

On the Keystone: tap ... > Connect Software Wallet > pick the app > a QR appears.

On the phone or desktop wallet: hardware wallet / Keystone / scan that QR.

Common pairings:

  • MetaMask extension and MetaMask Mobile: EVM
  • Rabby: EVM
  • OKX Wallet: BTC + EVM
  • Sparrow or BlueWallet: Bitcoin
  • Solflare / Backpack / Jupiter: Solana
  • Keplr: Cosmos

One device, several apps. That is normal. There is no single screen that shows every chain perfectly.

Keystone 3 Pro software wallet support options

Connect Software Wallet on the Keystone, then scan that QR from MetaMask, Rabby, OKX, Sparrow, BlueWallet, Solflare, or Keplr.

7. Connect MetaMask

Extension

  1. Install MetaMask from metamask.io. Create a dummy hot wallet inside MetaMask so the Connect Hardware Wallet button appears. That dummy seed is not your Keystone seed.
  2. On the Keystone open the MetaMask tile so it shows a connection QR.
  3. In MetaMask: account menu > Connect hardware wallet > Keystone / QR.
  4. Scan the Keystone QR with the computer camera.
  5. Unlock the account you want. Account 1 is fine if this is a new seed.

Mobile

Same idea. MetaMask Mobile supports Keystone. Scan the Keystone QR from the app. Compare the address on MetaMask with the address on the Keystone screen before you send anything.

USB data signing is still in progress in Keystone docs. Treat QR as the real path.

Keystone 3 Pro connected to MetaMask

Keystone shows a MetaMask connection QR. In MetaMask use Connect hardware wallet and scan it. The dummy MetaMask seed is not your cold seed.

8. How a send actually works (QR both ways)

This is the whole product.

  1. Build the transaction in MetaMask, Rabby, OKX, or Sparrow.
  2. The software wallet shows an unsigned QR.
  3. Point the Keystone camera at that QR.
  4. Read the address, amount, and fee on the 4-inch screen. If it does not match what you typed, hit back.
  5. Approve with swipe, PIN, or fingerprint.
  6. The Keystone now shows a signed QR.
  7. Scan that QR back with the phone or webcam.
  8. The software wallet broadcasts.

No Bluetooth. No Wi-Fi. No NFC. USB is for power and firmware.

Lighting matters. If the scan hangs, change the angle, turn the brightness up, and do not cover the camera. Fat DeFi payloads can take longer or fail. Test a tiny send first.

Keystone 3 Pro scanning unsigned QR code from MetaMask

Phone or desktop shows the unsigned QR. Keystone camera scans it. After you approve, scan the signed QR back to MetaMask.

Keystone 3 Pro clear signing a transaction on screen

Clear signing on the 4-inch screen. Check destination and amount, then PIN or fingerprint. If the screen and the app disagree, do not approve.

9. Coins and networks

The marketing line is 5,500+ assets through 45+ software wallets. That means the connected app supports them, not that every token is decoded natively on the Keystone.

Documented chains include Bitcoin, Ethereum and other EVMs, Solana, XRP, Cardano, Tron, Litecoin, Bitcoin Cash, Aptos, Sui, Dash, Arweave, Stellar, Zcash, Cosmos, and TON.

Practical split:

  • BTC: Sparrow or BlueWallet
  • ETH / EVM DeFi: MetaMask or Rabby
  • SOL: Solflare or Backpack
  • Everything else: check Keystone’s supported wallets page before you move a stack

Keystone 3 Pro coin and network support

Coverage is wide through connected apps. Confirm your exact coin and software wallet on Keystone's supported list before the first real deposit.

10. Optional extras once a test send works

Second and third seeds: Device Settings > Wallet Settings > Add Wallet. Useful for a decoy wallet or a separate vault.

Passphrase wallet: available in settings. That is a hidden wallet on top of the seed. Forget the passphrase and those accounts are gone.

Fingerprint: enroll after the seed exists. Convenience, not backup.

Bitcoin-only firmware: switch if you do not want altcoin code on the device.

Charge habit: official pack is 1000 mAh. Use a boring 5V / 1A charger. Do not store it at 0%. The seed on paper is the wallet if the battery dies.

Do not buy used. Wipe and anti-tamper help. Used hardware wallets are still a bad idea.

Quick checklist

  • Box looked sealed
  • Device verified at keyst.one/verify
  • Firmware on v2.4.0 or newer, then current (3.0.x multi-coin unless you chose another branch)
  • New seed created on the device, not imported from a website
  • Backup written (24 words or Shamir shares), confirmed on screen, stored offline
  • Software wallet bound by QR
  • MetaMask address matches the Keystone address
  • Tiny test receive worked
  • Tiny test send showed the right destination on the 4-inch screen before I approved
  • No photo of the seed exists on this phone

If that list is done, the Keystone 3 Pro is set up. From here it is just: build tx on the phone, read it on the device, scan the signed QR back.

Full review with scores and trade-offs: Keystone 3 Pro Review.

Back to blog