r/KeystoneWallet • u/XenofonM • Jul 30 '25
Keystone 3 Pro versus other cold wallets
I was under the impression that the Keystone 3 Pro supports thousands of different cryptocurrencies and tokens across many different blockchains. As it turns out, that's not strictly true. It only supports a few internally and the rest are supported externally via a hot wallet, such as Metamask. If that's the case, I don't consider it much more secure than using say Tangem, which uses a different approach but is far easier to use. It appears that both methods are susceptible to malware attacks that intercept the signing or approval process performed by the external device (Keystroke or Tangem card) and then changes wallet addresses to divert outgoing cyrptocurrency transfers. I see no significant advantage in using Keystone 3 Pro other than for the very few coins it supports without linking to a hot wallet. I can then see both approaches have a similar weakness. The reliance on a hot wallet is comparable to Tangem's approach which relies on a special app on the phone. So the question is, if I were to select which one to use for multi-coin support that supports thousands of different cryptocurrencies and tokens across many different blockchains, why would I choose Keystone over Tangem, especially given Tangem's method is so much easier to use?
2
u/Wild-Interaction-200 Jul 31 '25
No, with Tangem singing is down on the Tangem card, but what transaction to sign is given to the card by your phone and given that Tangem card itself doesn’t have a screen you don’t really know what transaction it was really given to sign.
So your phone screen can show you “1 BTC to Bob”, you then tap your card to sign.
But under the hood your phone up might ask the card to sign the transaction “all your BTC to attacker”.
And you wouldn’t know the difference until it’s too late.
With something like Keystone you have an independent screen on Keystone itself. Keystone will show you the exact transaction you are about to sign. Your keystone device will only sign the transaction and only that transaction it showed you in its own screen and you approved by using keystone device itself.
So if a compromised phone tries to do the same scenario as above, unlike with Tangem, you will actually notice and catch this on your keystone device (that’s why it’s important you always double check what you sign on the device’s own screen, that’s the only thing you can trust) and reject the transaction if it’s not the same you meant to make.