{
  "schemaVersion": 1,
  "article": {
    "wpId": 6034,
    "permalink": "/archives/6034",
    "sourceIssue": 176
  },
  "scope": {
    "checkedAt": "2026-08-31",
    "reviewBy": "2026-11-30",
    "evidenceMode": "official-source comparison only",
    "physicalDeviceVerification": "not performed",
    "downgradeReason": "No physical review units were available. The issue dependency requires unacquired models to remain official-spec comparisons and never be mixed with device-verified results.",
    "commercialRelationship": {
      "purchased": [],
      "loaned": [],
      "reviewUnits": [],
      "sponsors": [],
      "affiliatePrograms": [],
      "affiliateLinksInArticle": false
    }
  },
  "statusVocabulary": {
    "official_claim": "The vendor states the capability on an official product, support, changelog, or public-source page.",
    "public_source": "The vendor publishes relevant source code or a changelog in a public repository.",
    "not_device_verified": "The exact behavior was not reproduced on a physical unit by 3MIKAN.",
    "unverified": "No sufficiently specific official evidence was found for the exact comparison field."
  },
  "products": [
    {
      "brand": "Ledger",
      "model": "Ledger Flex",
      "officialStore": "https://shop.ledger.com/products/ledger-flex",
      "saleStatus": "officially offered on checkedAt",
      "physicalUnit": "not_acquired",
      "display": {
        "officialClaim": "2.84-inch 480x600 16-grayscale E Ink touchscreen controlled by the Secure Element",
        "status": "official_claim_not_device_verified"
      },
      "connection": ["USB-C", "Bluetooth", "NFC for supported Ledger features"],
      "secureElement": "ST33K1M5 family; CC EAL6+ claim on official specification",
      "sourceScope": "Ledger Wallet, SDK, embedded apps, and parts of Ledger OS are reviewable; low-level Secure Element firmware remains closed under NDA",
      "backup": ["24-word Secret Recovery Phrase", "Ledger Recovery Key on supported touchscreen devices", "optional Ledger Recover service is a separate choice"],
      "evm": {
        "ethereumSupport": "official_claim",
        "eip712": "official documentation states native EIP-712 support",
        "approveDisplay": "official design guideline shows decoded and blind-signing warning flows; exact app and dapp coverage varies",
        "deviceResult": "not_device_verified"
      },
      "firmware": {
        "installedVersion": null,
        "verification": "not_device_verified",
        "updatePath": "Ledger Wallet application"
      },
      "officialSources": [
        "https://shop.ledger.com/pages/ledger-flex",
        "https://www.ledger.com/academy/topics/ledgersolutions/is-ledger-open-source",
        "https://developers.ledger.com/docs/device-app/integration/design-guidelines/transactions",
        "https://www.ledger.com/blog/securing-message-signing"
      ]
    },
    {
      "brand": "Trezor",
      "model": "Trezor Safe 5",
      "officialStore": "https://trezor.io/trezor-safe-5",
      "saleStatus": "officially offered on checkedAt",
      "physicalUnit": "not_acquired",
      "display": {
        "officialClaim": "1.54-inch 240x240 color touchscreen with haptic feedback and on-device entry",
        "status": "official_claim_not_device_verified"
      },
      "connection": ["USB-C"],
      "secureElement": "OPTIGA Trust M (V3); EAL6+ claim; used for PIN enforcement, authenticity, and entropy contribution",
      "sourceScope": "official product states open-source security and design; firmware source and release history are public",
      "backup": ["SLIP39 20-word single-share", "SLIP39 multi-share", "BIP39 12 or 24 words", "passphrase"],
      "evm": {
        "ethereumSupport": "official_claim",
        "eip712": "public firmware changelog documents EIP-712 signing and display changes",
        "approveDisplay": "firmware 2.9.1 changelog documents provider contract address in ETH approve for supported models",
        "deviceResult": "not_device_verified"
      },
      "firmware": {
        "installedVersion": null,
        "latestListedForModelOnCheckedAt": "2.12.4",
        "verification": "official_changelog_only",
        "updatePath": "Trezor Suite"
      },
      "officialSources": [
        "https://trezor.io/trezor-safe-5",
        "https://trezor.io/learn/security-privacy/personal-security-standards/understanding-trezor-wallet-backups-12-20-or-24-words",
        "https://trezor.io/other/product-updates/trezor-firmware-changelog-all-versions-and-release-dates",
        "https://github.com/trezor/trezor-firmware/blob/main/core/CHANGELOG.md"
      ]
    },
    {
      "brand": "Keystone",
      "model": "Keystone 3 Pro",
      "officialStore": "https://keyst.one/shop/products/keystone-3-pro",
      "saleStatus": "officially offered on checkedAt",
      "physicalUnit": "not_acquired",
      "display": {
        "officialClaim": "4-inch 480x800 color touchscreen with full-transaction-display claim",
        "status": "official_claim_not_device_verified"
      },
      "connection": ["air-gapped QR workflow", "USB-C for supported workflows and updates", "microSD firmware update"],
      "secureElement": "three Secure Element chips; product and support pages state EAL5+ for the security-chip architecture",
      "sourceScope": "official product and firmware pages state open-source firmware; Keystone 3 firmware repository is public",
      "backup": ["BIP39 recovery phrase", "SLIP39 Shamir backup", "passphrase", "multiple seed phrases"],
      "evm": {
        "ethereumSupport": "official_claim",
        "eip712": "public firmware changelog documents EIP-712 parsing and signing",
        "approveDisplay": "official pages claim EVM transaction parsing; exact field coverage is not device-verified",
        "deviceResult": "not_device_verified"
      },
      "firmware": {
        "installedVersion": null,
        "latestListedForModelOnCheckedAt": "3.0.4 multi-coin",
        "verification": "official_changelog_only",
        "updatePath": "WebUSB or microSD using the official firmware page and checksum"
      },
      "officialSources": [
        "https://keyst.one/shop/products/keystone-3-pro",
        "https://keyst.one/firmware",
        "https://github.com/KeystoneHQ/keystone3-firmware/blob/master/CHANGELOG.md",
        "https://support.keyst.one/advanced-features/passphrase"
      ]
    },
    {
      "brand": "OneKey",
      "model": "OneKey Pro",
      "officialStore": "https://onekey.so/products/onekey-pro/",
      "saleStatus": "officially offered on checkedAt",
      "physicalUnit": "not_acquired",
      "display": {
        "officialClaim": "3.5-inch 480x800 color touchscreen with human-readable clear-signing claim",
        "status": "official_claim_not_device_verified"
      },
      "connection": ["USB-C", "Bluetooth", "air-gapped QR mode", "NFC", "Qi2 charging"],
      "secureElement": "four EAL6+ Secure Elements claimed on the official product page",
      "sourceScope": "official product, security page, and public repository state that app and firmware source are public and builds can be verified",
      "backup": ["BIP39 recovery phrase", "SLIP39 support", "passphrase", "OneKey Lite encrypted backup option"],
      "evm": {
        "ethereumSupport": "official_claim",
        "eip712": "firmware 4.20.0 changelog documents an Ethereum sign-typed-data display fix",
        "approveDisplay": "firmware 4.15.0 changelog documents Approve transaction parsing improvements",
        "deviceResult": "not_device_verified"
      },
      "firmware": {
        "installedVersion": null,
        "latestListedForModelOnCheckedAt": "4.21.0",
        "verification": "official_changelog_only",
        "updatePath": "OneKey App or official firmware upgrade site"
      },
      "officialSources": [
        "https://onekey.so/products/onekey-pro/",
        "https://help.onekey.so/en/articles/11461394-onekey-pro-firmware-update-log",
        "https://help.onekey.so/en/articles/11461088-connect-to-onekey-app-via-qr-code-air-gap",
        "https://github.com/OneKeyHQ/firmware-pro"
      ]
    },
    {
      "brand": "CoolWallet",
      "model": "CoolWallet Pro",
      "officialStore": "https://www.coolwallet.io/products/coolwallet-pro/",
      "saleStatus": "officially offered and listed in stock on checkedAt",
      "physicalUnit": "not_acquired",
      "display": {
        "officialClaim": "card-size device with built-in display and physical confirmation button",
        "status": "official_claim_not_device_verified"
      },
      "connection": ["encrypted Bluetooth to CoolWallet App", "WalletConnect through the companion app", "QR exchange through supported MetaMask flow"],
      "secureElement": "CC EAL6+ Secure Element claim",
      "sourceScope": "vendor states the CoolWallet Pro Secure Element firmware source is public; full hardware and app reproducibility was not assessed",
      "backup": ["BIP39-compatible 12, 18, or 24 words", "card-generated numeric representation mapped to BIP39 words"],
      "evm": {
        "ethereumSupport": "official_claim",
        "eip712": "unverified",
        "approveDisplay": "unverified",
        "deviceResult": "not_device_verified"
      },
      "firmware": {
        "installedVersion": null,
        "verification": "not_device_verified",
        "updatePath": "CoolWallet App"
      },
      "officialSources": [
        "https://www.coolwallet.io/products/coolwallet-pro/",
        "https://www.coolwallet.io/pages/walletconnect",
        "https://www.coolwallet.io/blogs/blog/metamask-step-by-step-guides",
        "https://www.coolwallet.io/blogs/blog/coolwallet-will-open-source"
      ]
    }
  ],
  "testFixture": {
    "purpose": "Keep the request body and required trusted-display fields identical when physical units are later acquired.",
    "network": "local Anvil-compatible request data only; never broadcast",
    "chainId": 31337,
    "testAccount": "0xf39fd6e51aad88f6f4ce6ab8827279cfffb92266",
    "recipient": "0x000000000000000000000000000000000000b0b0",
    "tokenContract": "0x0000000000000000000000000000000000001000",
    "spender": "0x0000000000000000000000000000000000002000",
    "cases": [
      {
        "id": "receive-address",
        "request": "display the test account receive address",
        "requiredDeviceFields": ["full address or an unambiguous review path to every character"]
      },
      {
        "id": "native-transfer",
        "request": {"to": "0x000000000000000000000000000000000000b0b0", "valueWei": "1000000000000000"},
        "requiredDeviceFields": ["recipient", "amount", "chain or network identity", "fee or an explicit path to review it"]
      },
      {
        "id": "erc20-transfer",
        "request": {"contract": "0x0000000000000000000000000000000000001000", "method": "transfer(address,uint256)", "recipient": "0x000000000000000000000000000000000000b0b0", "rawAmount": "1000000"},
        "requiredDeviceFields": ["contract or independently verified token identity", "method or transfer intent", "recipient", "amount and decimals basis"]
      },
      {
        "id": "erc20-approve",
        "request": {"contract": "0x0000000000000000000000000000000000001000", "method": "approve(address,uint256)", "spender": "0x0000000000000000000000000000000000002000", "rawAmount": "1000000"},
        "requiredDeviceFields": ["token contract or independently verified token identity", "approve intent", "spender", "allowance amount", "unlimited-approval warning when applicable"]
      },
      {
        "id": "eip712-permit",
        "request": {"primaryType": "Permit", "domain": {"name": "Local Test Token", "version": "1", "chainId": 31337, "verifyingContract": "0x0000000000000000000000000000000000001000"}, "message": {"owner": "0xf39fd6e51aad88f6f4ce6ab8827279cfffb92266", "spender": "0x0000000000000000000000000000000000002000", "value": "1000000", "nonce": 0, "deadline": 1800000000}},
        "requiredDeviceFields": ["primary type or permit intent", "domain name", "chainId", "verifying contract", "owner/account", "spender", "value", "nonce", "deadline", "blind-signing warning for any hidden fields"]
      }
    ],
    "execution": [
      {"brand": "Ledger", "model": "Ledger Flex", "status": "not_run_no_device", "capture": null},
      {"brand": "Trezor", "model": "Trezor Safe 5", "status": "not_run_no_device", "capture": null},
      {"brand": "Keystone", "model": "Keystone 3 Pro", "status": "not_run_no_device", "capture": null},
      {"brand": "OneKey", "model": "OneKey Pro", "status": "not_run_no_device", "capture": null},
      {"brand": "CoolWallet", "model": "CoolWallet Pro", "status": "not_run_no_device", "capture": null}
    ]
  },
  "scorePolicy": {
    "eligibility": "A product receives a numeric score only after all five fixture cases are run on a physical unit and every capture is redacted and reviewed.",
    "weights": {
      "trustedDisplayAndSignatureFields": 30,
      "backupAndRecovery": 20,
      "connectionFit": 20,
      "sourceAndVerificationScope": 15,
      "walletAndEvmIntegration": 10,
      "firmwareUpdateEvidence": 5,
      "commission": 0
    },
    "formula": "sum(axisScoreFrom0To5 / 5 * axisWeight)",
    "hardExclusions": ["seed or passphrase exposed to a connected host", "no independent on-device confirmation", "unsupported required chain or wallet", "official support ended", "critical fixture case cannot be reviewed without blind signing"],
    "scores": [
      {"model": "Ledger Flex", "score": null, "reason": "not eligible: physical fixture not run"},
      {"model": "Trezor Safe 5", "score": null, "reason": "not eligible: physical fixture not run"},
      {"model": "Keystone 3 Pro", "score": null, "reason": "not eligible: physical fixture not run"},
      {"model": "OneKey Pro", "score": null, "reason": "not eligible: physical fixture not run"},
      {"model": "CoolWallet Pro", "score": null, "reason": "not eligible: physical fixture not run"}
    ]
  },
  "safety": {
    "bestOverallDeclared": false,
    "realDeviceResultClaimed": false,
    "mainnetAssetUsed": false,
    "seedStored": false,
    "privateKeyStored": false,
    "affiliateRankingInfluence": false
  }
}
