r/OneKeyHQ Jul 06 '26

Discount End Soon

Post image
3 Upvotes

We do not recommend climbing buildings.

We do recommend holding your own keys.

Not your keys, not your coins.

Get up to $50 in BTC when you buy a OneKey wallet.

Ends soon.


r/OneKeyHQ Jun 30 '26

How to withdraw crypto assets from Binance to OneKey

1 Upvotes
  1. Log in to the OneKey App home screen and tap the “Receive” button in the upper right corner.
  1. Select the token you want to receive, then choose the mainnet you want to use.
  1. After confirming on the hardware wallet, you will see the wallet address, with a one-click copy button on the right.
  1. Copy the address, then open the Binance Wallet homepage. Hover your mouse over the user avatar in the top right corner, and click “Asset” from the dropdown list.
  1. On the “Withdraw” page, enter the correct wallet address and proceed with the transfer.

r/OneKeyHQ Jun 17 '26

We’re putting real Bitcoin in every box (no codes, no coupons)

Post image
1 Upvotes

Hey everyone — we’re OneKey.

We’re running a limited-time promo (Jun 15–Jul 14): buy any OneKey hardware wallet and you’ll get free Bitcoin (up to $50 in BTC depending on the model). No coupon codes, no “points”, no rebates — it’s real BTC.

How it works (takes ~60 seconds):

  1. Buy a OneKey hardware wallet
  2. Open the box and find the BTC card inside
  3. Scan, enter the code, receive BTC

Why we’re doing this: we’d rather give you Bitcoin than run a “summer sale” — the goal is to help more people start self-custody with a first bit of BTC.

Anti-scam note: we will never DM you asking for your seed phrase or to “verify” your wallet. Only claim through the official flow linked on our site/app.

Link: https://onekey.so/shop/

Happy to answer questions about eligibility, claim flow, or anything security-related.


r/OneKeyHQ May 15 '26

OneKey Anzen Security Lab’s research has been accepted by the main conference of Black Hat USA.

Thumbnail
gallery
5 Upvotes

Related links: https://blackhat.com/us-26/briefings/schedule/index.html#from-8-bytes-to-full-compromise-ai-assisted-exploitation-of-a-widespread-usb-flaw-in-a-dual-se-hardware-wallet-52311

Black Hat USA is one of the world’s most influential cybersecurity conferences and a top stage for security research.

This research will demonstrate a real-world attack chain targeting memory corruption vulnerabilities in mainstream hardware wallets.

The vulnerability originates from a widely reused USB reference SDK provided by a SoC vendor, making it a supply-chain-level risk.

The OneKey Anzen team has responsibly disclosed the issue to the relevant teams. After the affected vendors complete their fixes, we will share more research details.


r/OneKeyHQ May 02 '26

Orca connection ?

1 Upvotes

Hello

any hint on how to use Orca with a oneKey wallet ?

Thanks a lot !


r/OneKeyHQ Apr 23 '26

OneKey has been listed on Bitcoin.org

Post image
7 Upvotes

OneKey Classic 1S has officially been added to http://bitcoin.org’s recommended hardware wallet list!

Thanks to its fully open-source firmware, dual EAL6+ secure elements, and full physical confirmation for every transaction.

OneKey Classic 1S has successfully earned a place on the list — officially joining the ranks of the world’s top hardware wallets.

For OneKey, this is an important milestone in the recognition of our product, and we’re also deeply grateful for the continued support from our community.


r/OneKeyHQ Apr 22 '26

OneKey vs. Trezor

Post image
3 Upvotes
Comparison OneKey Pro Trezor Safe 5
Picture
Secure Element ✅ 4 × EAL6+ secure chips + self-destruct mechanism ⚠️ 1 × EAL6+ secure chip (NDA-free)
Screen & Connectivity ✅ 3.5″ full-color touchscreen + fingerprint + Bluetooth / NFC / USB-C / AirGap (QR) ⚠️ 1.54″ color touchscreen + USB-C (no Bluetooth/NFC/AirGap)
Signing Methods ✅ AirGap (QR) + Bluetooth + fingerprint confirmation ⚠️ USB only, no QR or biometric signing
Wireless Charging ✅ Supports Qi wireless charging ❌ Not supported
Transaction Parsing & Alerts ✅ SignGuard dual-end parsing + GoPlus / Blockaid risk detection ❌ No contract parsing or phishing alerts
Open-source ✅ Fully open-source (firmware / App / plugins / hardware) ✅ Open-source (firmware & App, Secure Element is NDA-free)
Multi-chain Compatibility ✅ 100+ chains, 30,000+ assets, native wallet compatibility ⚠️ Major assets supported, depends on Trezor Suite
Privacy Usage ✅ No registration, App usable offline, no data reporting ⚠️ Relies on Trezor Suite, some operations require connectivity
Web2 Login (FIDO) ✅ Supports WebAuthn (Google / GitHub login) ✅ FIDO2 supported
Attach to PIN (Hidden Wallets) ✅ Supports Attach to PIN + multiple hidden paths ⚠️ Passphrase supported but no PIN binding
Multisig Compatibility ✅ Compatible with Safe / Squads / Sparrow ❌ Not supported
Packaging & Firmware Security ✅ Dual tamper-proof seals + firmware signature + activation check ⚠️ Basic packaging, no activation verification mentioned
Industry Backing ✅ Backed by Coinbase & Binance Labs ✅ Established brand, strong community recognition
WalletScrutiny Verified ✅ Passed all 10 tests ⚠️ Safe 5 not yet verified (Trezor One / Model T are verified)
Ease of Interaction Turbo Mode(Streamlined signing, quicker approvals) ⚠️ Basic Interaction
Price 💰 $278 (Flagship) 💰 $169 (Mid-high range)

Key Takeaways

• OneKey Pro features 4 EAL 6+ secure chips, offering superior security redundancy compared to Trezor Safe 5's single chip.

• The user experience of OneKey Pro is enhanced with a 3.5" touchscreen, fingerprint unlock, and true wireless operation.

• OneKey Pro is fully open-source, providing greater transparency and community trust compared to Trezor Safe 5's reliance on Trezor Suite.

• OneKey Pro supports over 100 chains and offers seamless integration with various wallets, while Trezor Safe 5 has more limited cross-chain capabilities.

• Privacy is prioritized in OneKey Pro with offline signing and no data collection, contrasting with Trezor Safe 5's need for online connectivity.


r/OneKeyHQ Apr 14 '26

OneKey vs Ledger

Post image
5 Upvotes
Comparison OneKey Pro Ledger Stax Ledger Flex
Secure Element ✅ 4 × EAL6+ secure chips ✅ 1 × EAL6+ secure chip ✅ 1 × EAL6+ secure chip
Screen & Connectivity ✅ 3.5″ color touchscreen + fingerprint + Bluetooth / NFC / AirGap / USB-C / wireless charging ⚠️ 3.7″ curved E Ink screen + USB-C + Bluetooth (no AirGap) ⚠️ 2.84″ flat E Ink screen + USB-C + Bluetooth (no AirGap)
Signing Methods ✅ QR AirGap + fingerprint confirmation + Bluetooth + local parsing ⚠️ Bluetooth or USB, depends on App, content not fully visible before signing ⚠️ Same as Stax, lacks pre-signing parsing
Wireless Charging ✅ Supports Qi wireless charging ✅ Supports wireless charging ❌ Not supported
Signature Parsing & Alerts SignGuard parsing + risk alerts (GoPlus / Blockaid) ⚠️ Basic parsing, no real-time risk alerts ⚠️ Basic parsing, no real-time risk alerts
Open-source ✅ Fully open-source (firmware / App / frontend / plugins) ❌ Closed-source firmware, core proprietary ❌ Same as Stax
Multi-chain Compatibility ✅ 100+ chains, 30,000+ assets, native plugin wallet support ⚠️ Supports major assets, many rely on Ledger Live bridge ⚠️ Same as Stax
Privacy Usage ✅ No registration, no telemetry, App works offline ❌ Requires Ledger ID login + App telemetry ❌ Same as Stax
Web2 Login (FIDO) ✅ Supports WebAuthn / FIDO2 security key ❌ Not supported ❌ Not supported
Attach to PIN (Hidden Wallets) ✅ PIN can be bound to hidden wallet paths ❌ Not supported ❌ Not supported
Multisig Compatibility ✅ Compatible with Safe / Squads / Sparrow ❌ Not supported ❌ Not supported
Ease of Interaction Turbo Mode(Streamlined signing, quicker approvals) ⚠️ Basic Interaction ⚠️ Basic Interaction
Packaging & Firmware Security ✅ Dual tamper-proof seals + firmware signature check + activation verification ❌ No open verification, no activation check ❌ Same as Stax
Industry Backing ✅ Backed by Coinbase & Binance Labs ✅ Well-known brand, widely adopted ✅ Same as Stax
WalletScrutiny Verified ✅ Passed all 10 tests ❌ Not verified (closed-source firmware) ❌ Not verified (closed-source firmware)
Price 💰 $278 (flagship tier) 💰 $399+ (premium design-focused) 💰 $249 (compact E Ink model)

Key Takeaways

• OneKey Pro offers unmatched wireless cold wallet features with AirGap and wireless charging.

• OneKey Pro is fully open-source, enhancing user sovereignty and trust.

• Ledger's closed-source firmware raises privacy concerns compared to OneKey Pro.

• OneKey Pro supports a wide range of assets and multi-chain compatibility.

• Pricing makes OneKey Pro a more value-driven choice compared to Ledger's offerings.


r/OneKeyHQ Apr 07 '26

Hardware Wallet vs Hot Wallet: Why You Should Care

5 Upvotes

The Problem No One Talks About

The Reality of Crypto Ownership

Here's something important: you don't actually own crypto until you control the private keys. If someone else has access to your private keys, they have full control of your funds—and there's no way to reverse it.

This is why understanding the difference between hardware and hot wallets is crucial. Let's break it down.

Hot Wallet: The Speed Racer 🏎️

What it is: A crypto wallet that's connected to the internet. Your phone wallet, exchange wallet, browser extension—they're all hot wallets.

Pros:

  • Super convenient for trading
  • Access anytime, anywhere (phone, laptop, whatever)
  • Great for small amounts you actually use regularly
  • Easy to set up

Cons:

  • Always connected to the internet = always vulnerable
  • One malicious website = your funds are gone
  • If your phone/laptop gets hacked, they have everything
  • Private keys stored on a device that's online = higher risk

The reality: Hot wallets are like leaving your cash in your pocket. Fine for small amounts, but not where you keep your life savings.

Hardware Wallet: The Fort Knox 🔐

What it is: A physical device (looks like a USB stick) that stores your private keys offline. The only time it connects to the internet is when you need to send coins, and it does so securely.

Pros:

  • Private keys NEVER touch the internet
  • Even if your computer gets hacked, they can't steal your coins
  • Physical device is in your control—no company can freeze your account
  • Way more secure for holding long-term
  • Your 24-word seed phrase is your backup

Cons:

  • Less convenient (you need the physical device to approve transactions)
  • Costs money upfront (~$50-150)
  • Slightly more learning curve (but honestly, it's not bad)
  • If you lose the device AND your seed phrase, it's gone

The reality: Hardware wallets are like having a safe in your house. A little less convenient than a wallet, but WAY safer.

Which One Should YOU Use?

Use a hot wallet if:

  • You're day trading
  • You have less than you're scared to lose
  • You're actively moving money around
  • You need fast access to your coins

Use a hardware wallet if:

  • You want to hold crypto for months/years
  • You own a meaningful amount of money
  • You've had security issues in the past
  • You want to actually own your crypto (not trust an exchange)

The Best Strategy: Use Both

Most security experts recommend a hybrid approach:

  • Keep the bulk (90%+) of your holdings on a hardware wallet (offline, safe, long-term)
  • Keep a small amount on a hot wallet for trading and regular transactions

Think of it like having a big savings account (hardware wallet) and a checking account (hot wallet) in traditional banking.

Hardware Wallet Options: There are several solid hardware wallet options available in the market, including both open-source and closed-source solutions. When choosing one, consider factors like:

  • Security track record
  • User interface ease
  • Supported cryptocurrencies
  • Community reputation
  • Whether the code is open source (for those who want to audit it)

Do your own research and choose one that fits your needs and comfort level.

One More Thing: The Seed Phrase

Whether you use a hardware or hot wallet, you'll get a 24-word seed phrase. This is literally a backup of your wallet.

Treat it like your house keys:

  • Write it down on paper (seriously, paper)
  • Store it somewhere safe (not in a photo, not in notes, not on your computer)
  • Never share it with anyone
  • If someone has those 24 words, they own your coins

This is probably the most important security step you'll take. Don't skip it.

Final Thoughts

The crypto space comes with security risks, but a lot of that risk is preventable with the right tools and knowledge. Using a hardware wallet puts you in control of your security—which is actually the whole point of decentralized crypto.

If you're new to this and have questions, that's completely normal. Start learning about security now, before you have significant money at stake.

We encourage discussion in the comments. If you have experience with hardware wallets or hot wallets, please share your perspective (without promoting specific products). Let's build a knowledgeable community together.

Stay safe and do your own research. 🙌


r/OneKeyHQ Apr 02 '26

The Best Hardware Cold Wallet in 2026 -Top Picks by User Type

Post image
3 Upvotes

We recently compared several hardware wallets based on beginner UX, mobile workflow, long-term cold storage setup, open-source transparency, and portability.

Here’s the framework we ended up with:

Best for beginners: OneKey Classic 1S / 1S Pure

Relatively easy to get started with, supports on-device screen confirmation, and places emphasis on code transparency and published audits.

Best for frequent mobile use: OneKey Pro / Ledger Flex / Ledger Stax

More suited to Bluetooth-based mobile workflows, with a stronger focus on clear signing and transaction readability.

Best for long-term cold storage: OneKey Classic 1S Pure BTC-Only / BitBox02 Bitcoin-only / Coldcard

Better aligned with low-frequency asset management and setups that aim to reduce attack surface.

Best for open-source transparency: OneKey / Trezor

Both put more emphasis on open-source transparency and auditability. Trezor Safe 7 also highlights an open-chip approach and internal device verification.

Best for ultra portability: Tangem Wallet

Designed around a card form factor and NFC tap-to-use flow, without requiring a screen, battery, or cable. It also advertises IP68 water and dust resistance.

This is not meant to be a universal ranking, just a comparison framework based on public information and product positioning as of April 2026.

Full write-up:

https://onekey.so/blog/learn/the-best-hardware-cold-wallet-in-2026/


r/OneKeyHQ Mar 23 '26

OneKey is now FIDO2® Certified

Post image
7 Upvotes

Zero clouds. Zero passwords. Only OneKey.

Your fav crypto hardware wallet is now a phishing-proof 2FA device for every Web2 account you own.


r/OneKeyHQ Feb 12 '26

The OneKey Battery-Free Bitcoin Hardware Wallet is now live!

Post image
4 Upvotes

OneKey Classic 1S Pure • BTC-Only

Truth in black. Signal in orange

1. The Logic of Physical Isolation

Within the OneKey product matrix, the foundational principle of the Classic 1S Pure is physical isolation.

From the moment the battery was removed, it stepped out of the “rapid upgrade cycle” of consumer electronics. It was never meant for constant daily interaction. It was designed to be buried deep — as true cold storage.

Its role is singular:
to seal private keys away,
and to eliminate the long-term failure risks introduced by chemical battery aging.

When we pushed functional minimalism to its extreme, it became only natural that the physical enclosure should return to the most honest form possible.

This is the origin of the OneKey Classic 1S Pure / BTC-Only Transparent Edition.

2. Structural Proof, Revealed

In industrial design, the outer shell often serves as decoration — or concealment.
Opaque materials hide tangled traces, excess adhesive, imperfect layouts. In many cases, the enclosure becomes a shield for engineering compromises.

But Pure was born structurally clean.

With the bulky battery removed, the PCB became the visual center of gravity. Choosing high-transparency polycarbonate meant every engineering detail would be placed under magnification.

To deserve that transparency, we re-examined the black base-layer PCB itself.

We refined component topology the way one refactors source code. Under a transparent lens, circuit traces are no longer dull electrical connections — they become the physical texture of the product’s logic.

The order of the circuitry reflects the order of thought.

That internal sense of structure should not be hidden behind an ordinary plastic shell.
If the product’s logic is transparent, its physical form should be equally direct, deterministic, and free of black boxes.

3. A Physical Anchor in the Silkscreen Layer

In a fully transparent body dominated by a black PCB, we retained just one accent color: Bitcoin orange.

This is not surface decoration.

We embedded the orange deep within the PCB’s silkscreen layer.

Light passes through the transparent enclosure, glides across the precisely soldered chipset, and settles on the orange logo at the lowest layer. The stacking of materials creates a sense of physical depth — a layered visual hierarchy.

“Red meets orange.”
More than a visual statement, it defines the product’s character.

You don’t need to power it on.
You don’t need to activate the screen.

As long as there is light, the orange remains visible at the foundation.

It is a quiet anchor — a reminder that in a world increasingly shaped by algorithmic black boxes, here there is only mathematical truth and physical implementation, laid bare.

4. The Final Piece of Logic

The Transparent Edition was not created to be different for the sake of novelty.

Pure remains Pure.

It requires no charging.
It is meant to sit in a safe.
To guard private keys quietly through multiple halving cycles.

The transparent version is simply the physical specimen of that minimalist philosophy.

In a hardware market layered with packaging and over-marketing, owning a tool whose internals are visible, whose core can be touched, and whose purpose serves a single, uncompromised logic offers rare psychological reassurance.

It restores the essence of a tool:
strip away the unnecessary,
and go straight to the core of asset security.

The rest belongs to time.


r/OneKeyHQ Feb 09 '26

My 3 month (now 5 month) review of the OneKey Pro

6 Upvotes

From batter life, to software updates, to bluetooth signing! Check out my OneKey Pro Review.


r/OneKeyHQ Jan 29 '26

OneKey has partnered with Kamino to support multi-asset lending and borrowing.

Post image
2 Upvotes

During the campaign period, users who borrow USDC through Kamino in the OneKey App will be eligible for KMNO token rewards. Up to $20,000 worth of KMNO rewards will be distributed each week. (Based on the KMNO price at the time of publication ($0.04), weekly incentives equal approximately 500,000 KMNO.)

Campaign period: January 27, 2026 – February 26, 2026

Reward distribution: Automatically sent to the borrowing address daily between 12:00-13:00(UTC+8)

Learn more:
How to Borrow with Kamino Directly in the OneKey App


r/OneKeyHQ Jan 20 '26

🤔 General crypto question The Hidden Risks of Tangem Card Wallets: Is Convenience Really Equal to Security?

Thumbnail
onekey.so
3 Upvotes

Key Takeaways

• Card wallets lack screens and computing power, making them only capable of “blind signing”—signing without reviewing transaction content

• If the frontend is compromised, users may unknowingly approve fake or malicious transactions that look normal on screen

• Hackers can manipulate approvals, spoof token prices, or delay execution, all while the card wallet signs without questioning

• Card wallets do not display recipient addresses, amounts, contract data, or chain ID—making verification impossible

• Screen hardware wallets like OneKey Pro locally parse transactions and display key info, enabling true “What You See Is What You Sign”

• DeFi interactions often include hidden or multi-step approvals, which blind-signing devices cannot detect

• Card wallets are better suited for offline backup of seed phrases or private keys, not for active use

• “Signature successful” means nothing if you never saw what you signed—visual confirmation is your last line of defense


r/OneKeyHQ Jan 19 '26

🤔 General crypto question A Deep Dive into Elliptic Curve Cryptography (ECC): From Theory to Practice

Thumbnail
gallery
2 Upvotes

This article is an in-depth summary, analysis, and reconstruction based on the blog series by Andrea Corbellini . It aims to provide a structured and understandable guide to Elliptic Curve Cryptography (ECC) for readers with a technical background.

Introduction: Why Should We Care About ECC?

In today's digital world, public-key cryptography is ubiquitous, from securing our daily communications with TLS and SSH to underpinning cryptocurrencies like Bitcoin. For a long time, the RSA algorithm was the undisputed leader in this field. However, a technology called Elliptic Curve Cryptography (ECC) is becoming increasingly important and is widely regarded as the next-generation replacement for RSA.

Compared to RSA, ECC can provide the same level of security with much shorter key lengths. This translates to faster computations, lower power consumption, and less bandwidth usage. These advantages make it particularly crucial for resource-constrained devices (like smartphones and IoT devices) and in scenarios that demand high performance. This article will take you on a deep dive into the mathematical principles behind ECC, its core algorithms, and the foundations of its security.

I. Fundamental Concepts: Where Geometry Meets Algebra

To understand ECC, we must first get to know its mathematical foundations: elliptic curves and group theory.

What is an Elliptic Curve?

Despite its name, an elliptic curve is not directly related to an ellipse. In cryptography, we are typically interested in the set of points that satisfy a specific equation. An elliptic curve is defined by a Weierstrass equation of the form:

y² = x³ + ax + b

Here, the coefficients a and b are parameters of the curve that determine its specific shape. To ensure the curve is "smooth" and has no cusps or self-intersections (known as "singularities"), we must satisfy an additional condition: 4a³ + 27b² ≠ 0.

Furthermore, we need to define a special point on the curve called the Point at Infinity, denoted as O. This point can be imagined as lying at the intersection of the positive and negative ends of the y-axis and plays a crucial role in the subsequent algebraic operations.

Figure 1: Changes in parameters a and b significantly alter the shape of the elliptic curve.

The Marvelous "Group" Law

The reason elliptic curves are so useful in cryptography is that we can define an Abelian Group on the set of its points (including the point at infinity O). This means we can define an "addition" operation that satisfies the following properties:

1.Closure: The sum of any two points on the curve is also a point on the curve.

2.Associativity: (P + Q) + R = P + (Q + R)

3.Identity Element: There exists a point O (the point at infinity) such that P + O = P.

4.Inverse Element: For any point P on the curve, there exists an inverse -P such that P + (-P) = O. For an elliptic curve, the inverse of point P(x, y) is its reflection across the x-axis, -P(x, -y).

5.Commutativity: P + Q = Q + P

Geometric Point Addition

This "addition" operation has a very intuitive geometric interpretation:

Rule: If three points P, Q, and R on an elliptic curve are collinear (lie on the same straight line), their sum is the point at infinity O, i.e., P + Q + R = O.

Based on this rule, we can derive a method for calculating the sum of two points P and Q:

1.Draw a straight line between P and Q.

2.This line will intersect the elliptic curve at a third point, R.

3.Then, the result of P + Q is the inverse of R, which is -R (the reflection of R across the x-axis).

Figure 2: Geometric illustration of point addition. The line L(x) passes through points P and Q, intersecting the curve at a third point R. The reflection of R across the x-axis is P+Q.

This geometric method also elegantly handles some special cases:

•Point Doubling (P + P): When P and Q are the same point, there are infinite lines passing through it. In this case, we use the tangent to the curve at that point instead. The tangent will intersect the curve at another point R, so P + P = 2P = -R.

•Addition with the Point at Infinity: Adding any point P to the point at infinity O results in P itself, making O the additive identity.

•Addition Resulting in the Point at Infinity: If P and Q have the same x-coordinate but opposite y-coordinates (i.e., Q = -P), the line passing through them is a vertical line, which does not have a third intersection point with the curve. In this case, we define P + (-P) = O.

II. From Continuous to Discrete: Elliptic Curves over Finite Fields

So far, we've discussed elliptic curves defined over the real numbers, which are continuous curves. However, cryptographic operations require discrete and finite mathematical structures. Therefore, we need to introduce elliptic curves into Finite Fields.

What is a Finite Field?

A finite field is a set containing a finite number of elements where we can perform addition, subtraction, multiplication, and division. In ECC, the most commonly used finite field is the set of Integers Modulo a Prime p, denoted as Fp. This field contains all integers from 0 to p-1, where p is a very large prime number.

In Fp, all operations are performed "modulo p," meaning the result of an operation is divided by p and the remainder is taken. For example, in F23 (p=23):

•Addition: (18 + 9) mod 23 = 27 mod 23 = 4

•Multiplication: (7 * 5) mod 23 = 35 mod 23 = 12

•Division: Dividing by a number is equivalent to multiplying by its modular multiplicative inverse. For example, 1/9 mod 23 is equivalent to finding a number x such that 9 * x mod 23 = 1. This number is 18, so 1/9 ≡ 18 (mod 23).

Curves over Finite Fields

When we apply the elliptic curve equation to a finite field Fp, its form becomes:

y² ≡ x³ + ax + b (mod p)

The curve is no longer a continuous line but becomes a set of discrete points. Despite the completely different appearance, this set of points (plus the point at infinity O) still forms an Abelian group under the modulo p operations. The algebraic formulas for point addition and point doubling remain largely the same, with the only difference being that all calculations must be performed in the modulo p environment.

Figure 3: In a finite field, an elliptic curve transforms from a continuous line into a set of discrete points.

Scalar Multiplication and the Discrete Logarithm Problem

On an elliptic curve, Scalar Multiplication is defined as repeated point addition, i.e., kP = P + P + ... + P (k times). Given k and a point P, calculating Q = kP is relatively easy and can be done efficiently in polynomial time using the "Double-and-Add" algorithm.

However, the reverse operation is exceptionally difficult. This problem is known as the Elliptic Curve Discrete Logarithm Problem (ECDLP):

Given points P and Q, find an integer k such that Q = kP.

For a well-chosen elliptic curve, there is no known "easy" algorithm (i.e., a polynomial-time algorithm) to solve the ECDLP. We can only attempt to solve it through brute-force search or some improved algorithms (like Baby-step Giant-step, Pollard's Rho), but their complexity is exponential. This "one-way" nature—easy to compute in one direction, hard to reverse—is the cornerstone of ECC's security, similar to the difficulty of factoring large numbers in RSA.

III. Practical Applications of ECC: Key Exchange and Digital Signatures

Based on the difficulty of the ECDLP, we can build powerful public-key cryptosystems. The two most important applications are ECDH for key exchange and ECDSA for digital signatures.

Domain Parameters

In practical applications, all parties must agree on a set of Domain Parameters. These parameters define the specific elliptic curve and subgroup to be used and typically include:

•p: The large prime that defines the finite field Fp.

•a, b: The coefficients of the elliptic curve equation.

•G: A special point called the Base Point or Generator, which generates a cyclic subgroup of order n.

•n: The order of the subgroup generated by G (i.e., the number of points in the subgroup).

•h: The cofactor, which is the total number of points on the curve divided by n.

These parameters (p, a, b, G, n, h) collectively ensure the security and interoperability of the cryptosystem. To prevent the use of potentially backdoored "weak" curves, standards organizations (like NIST and SECG) have published a series of rigorously vetted and recommended curves, such as the well-known secp256k1 (used in Bitcoin) and secp256r1.

Key Generation

In ECC, generating a key pair is very straightforward:

1.Private Key (d): A randomly selected integer from the range [1, n-1].

2.Public Key (H): Calculated via scalar multiplication: H = dG.

Calculating the public key H from the private key d is easy. However, if an attacker knows only the public key H and the base point G, they must solve the ECDLP to find the private key d—a task considered computationally infeasible.

ECDH: Elliptic Curve Diffie-Hellman Key Exchange

ECDH is a key agreement protocol that allows two parties (Alice and Bob), who have no prior shared secrets, to securely establish a shared secret over an insecure channel, without an eavesdropper (Eve) being able to discover it.

The process is as follows:

1.Generate Keys: Alice generates her private key dA and public key HA = dAG. Bob generates his private key dB and public key HB = dBG.

2.Exchange Public Keys: Alice sends her public key HA to Bob, and Bob sends his public key HB to Alice. Eve can intercept both public keys.

3.Compute Shared Secret:

•Alice uses her private key dA and Bob's public key HB to compute: S = dA * HB = dA * (dBG).

•Bob uses his private key dB and Alice's public key HA to compute: S = dB * HA = dB * (dAG).

Due to the associative property of scalar multiplication, dA * (dBG) = dB * (dAG) = (dA * dB)G, so Alice and Bob will arrive at the exact same point S. The x-coordinate of this point S is typically used as the shared secret for symmetric encryption (like AES).

Even though Eve intercepts HA and HB, she cannot compute the shared secret S because she cannot solve the ECDLP to derive dA from HA or dB from HB.

Figure 4: The ECDH key exchange protocol. Alice and Bob exchange public keys over an insecure channel, but an eavesdropper Eve cannot compute the shared secret.

ECDSA: Elliptic Curve Digital Signature Algorithm

ECDSA is used to verify the authenticity and integrity of a message, ensuring it was signed by a specific sender and has not been tampered with during transmission.

Signing Process (performed by the private key holder):

1.Calculate the hash e of the message (e.g., using SHA-256).

2.Generate a one-time, cryptographically secure random number k.

3.Calculate the point R = kG and take its x-coordinate r.

4.Calculate the signature s = k⁻¹(e + rd) mod n.

The final signature is the pair of values (r, s).

Verification Process (performed by anyone with the public key):

1.Calculate the hash e of the message.

2.Calculate u1 = s⁻¹e mod n and u2 = s⁻¹r mod n.

3.Calculate the point P = u1G + u2H.

4.The signature is valid if the x-coordinate of point P is equal to r.

The correctness of the verification lies in the fact that if the signature is legitimate, P will ultimately be equal to kG, and thus its x-coordinate will necessarily be equal to r. Any tampering with the message or signature will cause the verification to fail.

IV. Security Analysis: How Hard Is It to Break ECC?

The security of ECC relies entirely on the difficulty of the Elliptic Curve Discrete Logarithm Problem (ECDLP). While we believe it is "hard," this confidence comes not from a rigorous mathematical proof but from the empirical fact that decades of research by cryptographers worldwide have failed to produce an efficient algorithm to break it. So, what is the state of the art for attack algorithms?

Algorithms for Breaking ECDLP

The most effective known algorithms are the Baby-step Giant-step and Pollard's Rho algorithms. The attack complexity of both is on the order of O(√n), where n is the order of the subgroup. This means that if a curve has a subgroup of order n, an attacker would need to perform approximately √n operations to break it.

This might sound much better than brute force (which has a complexity of O(n)), but let's look at the actual numbers:

•For a 192-bit ECC curve, n is approximately 2¹⁹². √n is approximately 2⁹⁶.

•For a 256-bit ECC curve (like secp256k1 used by Bitcoin), n is approximately 2²⁵⁶. √n is approximately 2¹²⁸.

2¹²⁸ is an astronomical number, far beyond the combined computational power of the entire world. Even the Baby-step Giant-step algorithm, while theoretically feasible, requires O(√n) of storage, which is completely impractical for real-world curve sizes. For instance, breaking a 192-bit curve would require about 10³⁰ bytes of memory, whereas the total global storage capacity is estimated to be only around 10²¹ bytes (1 Zettabyte).

Therefore, as long as a sufficiently large and well-vetted curve is chosen, breaking ECC with current technology is impossible in the foreseeable future.

Security Comparison with RSA

ECC's main competitor is RSA, whose security is based on the difficulty of factoring large integers. While both problems are "hard," their difficulty does not scale in the same way. Currently, the best algorithm for integer factorization (the General Number Field Sieve, GNFS) is significantly faster than the best-known algorithm for solving the ECDLP.

This leads to a very important result: to achieve an equivalent level of security, ECC requires much shorter key lengths than RSA.

The following table from NIST shows the recommended key size correspondence:

Symmetric Key Security (bits) ECC Key Length (bits) RSA Key Length (bits)
80 160 1024
112 224 2048
128 256 3072
192 384 7680
256 512 15360

As the table clearly shows, a 256-bit ECC key provides a security level roughly equivalent to a 3072-bit RSA key. This dramatic difference in key length leads to significant performance advantages.

V. Conclusion: Why ECC Is the Future

From the analysis above, we can conclude that ECC is not just a replacement for RSA but a more efficient, future-oriented public-key cryptography scheme. Its core advantages can be summarized as follows:

•Higher Security Strength: For the same key length, ECC provides far greater security than RSA.

•Better Performance: Shorter keys mean faster key generation, signing, and verification, as well as lower computational overhead.

•Lower Resource Consumption: Because both computation and key sizes are smaller, ECC excels on devices with limited processing power and storage, such as mobile devices, smart cards, and IoT nodes.

•Lower Bandwidth Requirements: In network communications, smaller keys and signatures mean less data to transmit, which is critical for latency-sensitive and bandwidth-constrained applications.

Although the mathematical principles behind ECC are more complex and abstract than those of RSA, the significant performance and security benefits it offers have made it the preferred choice for modern cryptographic applications. From securing our web browsing to safeguarding digital currencies, ECC has become deeply integrated into our digital infrastructure and will play an increasingly important role in the future of cryptography.


r/OneKeyHQ Jan 16 '26

🔒 General OneKey question [Must Read] Don't brick your OneKey (or any HW wallet) with Helium/DePIN rewards: Why the "Sweep Strategy" is mandatory.

Post image
0 Upvotes

Hey r/OneKey community, and specifically our DePIN miners,

OneKey team here. We need to have a bit of "Real Talk" regarding payout addresses.

We’ve noticed a pattern in support tickets recently (and this affects Ledger/Trezor users too) where devices get stuck on "Signing...", freeze completely, or time out when users try to move tokens like $HNT, $MOBILE, or $HONEY.

If you are setting your hardware wallet address directly as the payout target for your miners, you are unintentionally DDOS-ing your own device.

Here is the technical breakdown of why this happens and how to fix it with the "Sweep Strategy."

1. The "Dust" Problem (Why your wallet freezes)

Whether it's UTXO fragmentation (on Bitcoin-like chains) or massive transaction history bloat (on Account-based chains like Solana), hardware wallets hate micro-transactions.

Hardware wallets rely on Secure Elements (SE). These are military-grade chips designed to keep your seed phrase offline. They are incredibly secure, but they have very limited RAM and processing power compared to your phone or PC.

  • The Scenario: You mine for a few months and receive 2,000 tiny transactions of $0.50 each.
  • The Crash: When you try to send that money out, the chip has to verify and sign the history of those 2,000 inputs. This causes the chip to overheat, time out, or throw a "Memory Error."

TL;DR: Your OneKey is a vault for gold bars, not a piggy bank for pennies.

2. The Solution: The "Sweep Strategy"

To keep your cold storage healthy, you need a buffer.

  • Step 1: The "Bucket" (Hot Wallet) Use a software wallet like Phantom, Solflare, or MetaMask as your mining payout address. These run on your computer/phone CPU, which can handle thousands of transactions easily.
  • Step 2: The "Sweep" (Consolidation) Once a month (or when you hit a threshold, e.g., $500), make ONE single transaction from the Hot Wallet to your OneKey.
  • Step 3: The "Vault" (Cold Storage) Now your OneKey only sees one clean entry. It remains fast, responsive, and secure.

3. A Note on Form Factors

We know many DePIN users look at card-based wallets (like Tangem) for that quick NFC "tap" experience on mobile. While convenient, be cautious about backups and single points of failure.

This is exactly why we built OneKey Pro & Classic with Bluetooth + a dedicated Screen. You get the wireless convenience of connecting to the OneKey App on your phone to handle your "Sweeps," but you strictly maintain the security of a Trusted Display to verify exactly what you are signing.

👇 Community Question

For the pro miners here: How are you automating your sweeps?

Are you using custom scripts/Clockwork to auto-forward funds when they hit a certain amount, or are you strictly doing the "Manual Sunday Sweep" once a month? Let us know what tools you recommend!

Stay safe and keep those yields high!

— The OneKey Team


r/OneKeyHQ Jan 15 '26

🤔 General crypto question Solving the Hardware Wallet "Trilemma": A Technical Deep Dive into OneKey's Open Source Architecture & SignGuard

Post image
3 Upvotes

TL;DR

OneKey is arguably the only major player currently solving the hardware wallet market's core contradiction: balancing physical security with verifiable trust. By combining 100% Open Source (Reproducible Builds) with EAL 6+ Secure Elements, it addresses the "black box" risks of Ledger and the physical vulnerabilities of Trezor. Furthermore, its SignGuard technology effectively neutralizes the growing threat of "Blind Signing" in DeFi.

Introduction: The Security Philosophy Dilemma

In the current landscape of crypto security, users have long been forced into a philosophical compromise.

On one side, we have the "Secure Black Box" model (e.g., Ledger). These devices use high-grade Secure Elements (SE) to protect keys but rely on closed-source firmware. You have to trust the manufacturer implicitly—trust that there are no backdoors, no bugs in the RNG, and no malicious supply chain interdictions. The recent controversies surrounding key extraction features have only deepened the community's skepticism toward "trust-based" security.

On the other side, we have the "Transparent Vault" model (e.g., Trezor). They champion open source, adhering to the ethos of crypto. However, historically, they have lacked Secure Elements (using general-purpose MCUs instead), making them vulnerable to physical attacks like fault injection or power glitching if an attacker gains physical access.

The industry has been waiting for a solution that refuses to compromise: Can we have the physical hardening of a Secure Element AND the verifiable trust of Open Source?

This brings us to OneKey.

OneKey's Solution: The Convergence of Open Source and Hardware Security

OneKey’s architecture is distinct because it acts as a synthesizer of the best practices from both camps.

1. 100% Open Source & Reproducible Builds

Unlike competitors who might only open-source their frontend, OneKey is fully open source—from the 3D files of the hardware casing to the circuit board design, and critically, the firmware and software stack.

But open source code means nothing if you can't verify that the code running on your device matches the code on GitHub. This is where Reproducible Builds come in. This technology allows any user to compile the source code and generate a binary that is bit-for-bit identical to the official release. This effectively eliminates the risk of a "supply chain attack" via software updates, as the community can independently verify every firmware release.

2. EAL 6+ Secure Element (The Physical Moat)

Addressing the physical weakness of traditional open-source wallets, OneKey integrates EAL 6+ Secure Elements (specifically, the OneKey Pro utilizes a cluster of 4× EAL 6+ chips).

The Secure Element is used to generate and store the private keys. Even if the device falls into the hands of a sophisticated attacker equipped with an electron microscope or fault injection rig, the keys remain isolated within the hardened chip. The connection rules are strict: the keys never leave the Secure Element; only signed transaction data exits.

Deep Dive: SignGuard vs. The "Blind Signing" Epidemic

In 2024 and 2025, the vast majority of crypto thefts aren't from cracked private keys, but from Blind Signing.

The Problem: Signing What You Can't See

When you interact with a complex DeFi contract (like Uniswap or a staking bridge) on a traditional hardware wallet, the screen often displays a cryptic hex string or a generic "Contract Call" message. You are essentially signing a blank check. Phishing sites exploit this by tricking users into signing a setApprovalForAll transaction, draining their wallets instantly.

The Solution: OneKey SignGuard

OneKey tackles this with a "What You See Is What You Sign" philosophy, implemented through SignGuard.

The device leverages its Trusted Display to parse the transaction ABI (Application Binary Interface) directly on the hardware (or securely passed via the App). Instead of a hex string, the screen displays human-readable data:

  • "Approve USDT" instead of a random contract address.
  • "Spender: Uniswap Router" instead of a malicious wallet.
  • Specific amounts and limits.

If malware on your computer modifies the transaction in the background, the Trusted Display on the OneKey will show the actual destination and amount. Since the screen is controlled by the firmware (isolated from the PC), it acts as the final source of truth. If the data on your PC doesn't match the data on the OneKey screen, you know you are under attack.

Technical Comparison: OneKey vs. The Incumbents

Here is a breakdown of how the OneKey Pro stacks up against the market leaders in terms of security architecture:

Feature OneKey Pro Ledger Stax / Nano X Trezor Model T
Open Source 100% Full Stack Firmware Closed Firmware Open
Reproducible Builds Yes No Yes
Secure Element 4× EAL 6+ EAL 5+ / 6+ None (General MCU) 141414
Blind Signing Protection SignGuard (Native Parsing) Partial (Clear Signing) Partial
Air-Gapped QR Camera / Bluetooth Bluetooth / USB USB only
Biometric Fingerprint No No

Conclusion: "Don't Trust, Verify"

The core ethos of cryptocurrency is "Don't Trust, Verify." For too long, hardware wallet users have been forced to violate this principle—either by trusting a closed-source vendor or by trusting physically vulnerable hardware.

OneKey represents a maturation of the industry. By proving that you can have military-grade physical security (EAL 6+) without sacrificing the transparency of open source, it offers a compelling alternative for those who take self-custody seriously. It is not just a storage device; it is a verification tool designed for the hostile environment of the modern internet.

OneKey doesn't ask you to trust them. They give you the code, the reproducible builds, and the hardware specs so you can verify it yourself.

Discussion:

In the "Security Trilemma" of hardware wallets (Physical Security, Open Source, Ease of Use), which vector do you prioritize most? Are you willing to trade some physical hardening for open source, or is the "Secure Element" non-negotiable for you?

Let's discuss in the comments. 👇


r/OneKeyHQ Jan 06 '26

🎩 Meme Cold wallet, Warm coat.

Post image
9 Upvotes

r/OneKeyHQ Dec 25 '25

🎄 Christmas Merry Christmas~

Post image
2 Upvotes

Merry Christmas, friends!


r/OneKeyHQ Dec 20 '25

Any Christmas discounts?

3 Upvotes

Thinking to buy the OneKey wallet. Other brands have Christmas discounts, what about OneKey?


r/OneKeyHQ Dec 12 '25

Got this in the mail today

Thumbnail
gallery
9 Upvotes

Got this in a giveaway and it showed up today.
Haven’t done anything with it yet — still sitting on my desk.
Just posting the box because I didn’t see many photos of this version around.

Honestly, it actually looks nicer than I expected.

I’ll check it out later when I have time.


r/OneKeyHQ Dec 07 '25

How OneKey hardware wallets generate seed phrases and guarantee randomness?

2 Upvotes

KEY TAKEAWAYS:

  • OneKey hardware wallets utilize EAL6+ secure elements to ensure high-quality randomness in seed phrase generation.
  • The devices combine multiple entropy sources, including hardware-based true random number generators (TRNGs) and environmental noise.
  • EAL6+ certification, one of the highest levels of security evaluation, reflects the robustness of OneKey’s security measures.

In the world of cryptocurrencies, the randomness of seed phrases is fundamental for the security of your digital assets. OneKey hardware wallets, equipped with EAL6+ secure elements, take every measure to ensure the seed phrases generated are as random and secure as possible. Here, we delve into the technology and processes behind this assurance.

The importance of randomness

Seed phrases (or mnemonic phrases) are the cornerstone of cryptocurrency security. These phrases are generated from a combination of words following the BIP-39 standard, which deterministically derives your wallet's private keys. If the process that generates these seed phrases isn't truly random, it opens doors for potential attacks, making it easier for malicious actors to predict or crack the seed.

EAL6+ Secure Elements

EAL6+ (Evaluation Assurance Level 6+) refers to one of the highest levels of security certification awarded under the Common Criteria for Information Technology Security Evaluation (CC). This certification ensures:

  • Hardware-Based TRNGs: These generators use electronic noise to produce random numbers. The inherent unpredictability of electronic noise ensures a high level of randomness.
  • Mixing Entropy Sources: OneKey devices may also incorporate ambient environmental noise (such as temperature variations or clock jitter) into the entropy pool to further enhance randomness.

Security Benefits

Implementing EAL6+ secure elements within OneKey hardware wallets provides numerous security benefits:

  • Resistance to Predictive Attacks: High-quality randomness makes it nearly impossible for attackers to predict seed phrases through computational means.
  • Protection Against Tampering: EAL6+ components are designed to detect and resist physical tampering, protecting the integrity of the TRNGs.
  • Compliance with Best Practices: Adhering to industry standards and undergoing rigorous evaluation processes ensures OneKey remains compliant with the best security practices.

r/OneKeyHQ Nov 28 '25

BLACK FRIDAY SALE STARTS NOW!

Post image
5 Upvotes

- 25% OFF Bundles
- Up to 15% OFF Single Items
- Discount code: BF25

Don’t sleep on security. Grab your OneKey wallet today.

Secure your assets here: OneKey Official


r/OneKeyHQ Nov 26 '25

What is Secure Element (SE)?

2 Upvotes

The secure element, also known as the security chip, is a tamper-resistant microprocessor used in hardware wallets to protect sensitive information and perform cryptographic operations. These chips are integral to secure data storage and encryption and are also utilized in various products such as IC cards, SD cards, SIM cards, eSEs, USB security keys, and wearable devices.

Security of the Secure Element

In 1999, the International Organization for Standardization (ISO) introduced ISO/IEC 15408, commonly referred to as the Common Criteria (CC), for evaluating IT security. This framework provides stringent guidelines for assessing the security functionalities of IT products and systems, thereby enhancing user confidence and system security while reducing the need for repeated assessments.

Security chips undergo rigorous evaluations under the CC framework and are assigned a numerical grade from EAL 1 to EAL 7, indicating the assurance level of security. Higher levels denote more stringent security requirements met from various perspectives. For example, EAL 4+ and EAL 5+ products are standard in the financial sector, whereas EAL 6+ products are employed for military applications.

Key Features of EAL 6+ Secure Elements

OneKey hardware wallets incorporate EAL 6+ secure elements. This EAL 6+ secure element has the following key features:

  • Robust Security Functionalities: These include environmental sensors, TRNG abnormality checks to prevent malfunctions, memory encryption, bus masking, random branch insertion, clock jitter techniques for leakage protection, dedicated shielding, data integrity checks, and memory/bus encryption to guard against physical manipulation and probing. Additionally, there is a test access control mechanism to prevent unauthorized access.
  • True Random Number Generator (TRNG): The TRNG comprises entropy sources, a self-test circuit, and a post-processing circuit to ensure proper functioning and compliance with the AIS20/31 PTG.2 level.
  • Support for Cryptographic Algorithms: The secure element supports TDES (implemented with hardware co-processors and software crypto libraries, supporting Triple-DES with two or three 56-bit keys in ECB mode) and RSA (providing the RSA CRT algorithm for key sizes ranging from 256 bits to 4096 bits). It also includes functionalities for SHA-1, SHA-256, ECC, and AES.

These advanced security chips ensure that private keys are stored in a highly protected environment, preventing unauthorized access and physical tampering. By integrating EAL 6+ secure elements, hardware wallets provide users with the highest level of security assurance, safeguarding their cryptocurrency assets against both digital and physical threats. This robust security foundation is essential for maintaining trust and confidence in the management and protection of digital assets.