Hardware review — KeepKey

KeepKey review: historically important, no longer competitive

We review this device so you don't buy it. The KeepKey mattered a decade ago and has been overtaken on every axis that counts: no secure element, no meaningful development, narrow asset support and no local supply. If you own one, here is how to move on.

  • None Secure element in the device
  • Stalled Firmware development since ShapeShift wind-down
  • Narrow Supported asset range
  • Not stocked No reliable NZ availability

At a glance

BB 4.6/10

A historically important device with no secure element and no meaningful roadmap — we do not recommend it for new buyers.

Best for: Nobody buying new in 2026  ·  Maker: KeepKey / ShapeShift

Why we review a device we tell you not to buy

Two reasons. First, KeepKey devices are still listed, still discussed in older articles, and still turn up cheaply on marketplaces, so people searching for a review deserve a straight answer rather than a page optimised to sell them something. Second, a lot of New Zealanders bought one in 2017 or 2018, put crypto on it, and have not thought about it since. Those people need to know what has changed.

The short version: the KeepKey has no secure element, and its firmware development has effectively stopped. Neither of those was unusual when it launched — the original Trezor had no secure element either, and the trade-off was well understood. What is different now is that Trezor responded by building the Safe line with EAL6+ certified silicon, and Ledger built a chip-first architecture from the start, while KeepKey stayed where it was.

In hardware security, standing still is going backwards. Attacks improve, research accumulates, and a product with no active development is a product whose eventual vulnerability will never be fixed. That is the whole argument, and it is sufficient.

Specifications

Maker KeepKey / ShapeShift
Price US$49 when stocked
Form factor Large-screen USB device with a single button
Secure element None
Source code Open, but with very little recent activity
Connection USB
Asset support Limited relative to current devices
Backup BIP39 recovery phrase — portable to any modern wallet
Staking No
Development status Minimal since the ShapeShift restructure
NZ availability Not reliably stocked
Last verified September 2026

What "no secure element" actually means for you

This deserves a proper explanation rather than a scary phrase, because the practical risk is narrower than it sounds and it is worth knowing which risk you are carrying.

A secure element is a chip specifically designed to resist physical attack — probing, power analysis, glitching, laser fault injection — and certified to a Common Criteria assurance level for that resistance. When a wallet has one, extracting the seed requires laboratory equipment, expertise and often destroying the device in the process. When a wallet does not, the seed sits in a general-purpose microcontroller that was designed to run code cheaply rather than to keep secrets under attack.

Against remote threats, this makes no difference at all. Malware on your laptop cannot reach the key on a KeepKey any more than it can reach one on a Trezor Safe 5, because the key never crosses the cable in either case. Your KeepKey is genuinely cold storage.

Where it matters is physical possession. If someone steals the device — a burglary, a lost bag, a targeted theft after your address appeared in a vendor data breach — a device with no secure element is a substantially easier target. Researchers demonstrated exactly this against early Trezor models, which is why the Safe line exists. A PIN helps, but not against a determined attacker with the hardware in front of them.

The compounding problem: no development

A hardware wallet with an active maintainer is a product that gets better. Firmware gets patched, new attacks get mitigated, coin support is added, and companion software keeps working as operating systems change. A wallet with a stalled roadmap has none of that. Whatever weaknesses it has today are the weaknesses it will have in 2031, and the software you use to talk to it will slowly stop working as platforms move on.

The balance sheet

What we like, and what we don't

Strengths

What it does well

  • Genuinely large, clear screen — better for reading a full address than several current devices
  • Standard BIP39 recovery phrase, so migrating away is straightforward
  • Simple, single-button operation that is hard to misunderstand
  • Historically significant: it was one of the three devices that established this product category
  • Cheap when you can find one
Weaknesses

What we hold against it

  • No secure element — the seed sits in a general-purpose microcontroller with no dedicated physical protection
  • Firmware development has effectively stalled, so a future vulnerability would likely never be patched
  • Narrow asset support compared with every actively developed competitor
  • No reliable New Zealand supply, so buying one usually means an overseas marketplace — which is the worst way to buy any hardware wallet
  • Companion software has not kept pace with Ledger Live, Trezor Suite or BitBoxApp
  • No staking, no air-gap option, no passphrase sophistication, no multisig story worth the name

How to migrate off a KeepKey properly

If you own one with funds on it, there is no emergency. Do this carefully rather than quickly.

Buy a modern device from a source you can verify. A Ledger Nano S Plus is NZ$99 from GROOV in Christchurch or around NZ$95 to NZ$120 from PB Tech and Mighty Ape. A Trezor Safe 3 is US$79 direct. Either is a substantial upgrade. Do not buy second-hand.

Set the new device up with a brand new recovery phrase. This is important and it is the step people get wrong. Do not import your old KeepKey phrase into the new device. That phrase has lived on an unmaintained device for years, its exposure history is unknown, and you have a clean opportunity to start fresh. Let the new device generate its own seed.

Write the new phrase down, twice, then wipe and restore to prove it works. Before you move a single dollar. Our cold storage guide walks through this properly.

Send a small test transaction from the KeepKey to the new wallet. Confirm it arrives and appears at the address you expected. Then move the balance. Note that this is a transaction between two wallets you control, so it is not a disposal for New Zealand tax purposes — but record the date, amounts, addresses and network fee anyway, because you may later need to demonstrate that it was an internal transfer rather than a sale. See our tax guide. General information, not tax advice.

Keep the KeepKey and its phrase until you are certain. Once the new wallet has been holding your funds without incident for a few weeks and you have verified the restore, you can retire the old device. Destroy the old recovery phrase properly — it still controls any address you forgot about.

Credit where it is due

It would be easy to be dismissive, and that would misrepresent the history. When the KeepKey launched, the idea that a normal person should hold their own private keys on a dedicated device was novel and slightly eccentric. There were three products that made the case, and this was one of them.

Its large screen was a genuinely good decision that the industry took years to appreciate. We now argue on nearly every page of this site that verifying an address on a device's own display is the single most valuable thing a hardware wallet does, and that screen size is therefore a security feature rather than a comfort. KeepKey worked that out in 2015. Reading a full Bitcoin address on one is still easier than doing it on a Trezor Safe 3.

That is not enough to recommend it in 2026, and it does not need to be. Products get superseded; that is how the field improves. The right response to owning an obsolete security device is not loyalty, it is a calm migration to something maintained.

Our view

The most dangerous hardware wallet is not a badly designed one. It is a well-designed one that stopped being maintained, sitting in a drawer, owned by someone who assumes that because it worked in 2018 it is still the state of the art. If you have a KeepKey, or an original Trezor One, or any device you have not thought about in five years, this is your reminder that hardware security is a subscription paid in attention rather than money.

KeepKey FAQ

KeepKey — questions New Zealanders ask

Should I buy a KeepKey in 2026?

No. We are not usually this blunt, but there is no version of this decision that works out well. The KeepKey has no secure element, its development has effectively stalled since the ShapeShift wind-down, asset support is narrow, and it is not reliably stocked anywhere in New Zealand. A Ledger Nano S Plus costs NZ$99 domestically with a CC EAL6+ certified chip and active firmware development. There is no scenario in which the KeepKey is the better purchase.

I already own a KeepKey. Do I need to move my funds?

Not in a panic, but yes, plan a migration. Your keys are not in immediate danger from any published attack, and against remote threats a KeepKey is still cold storage. The problems are the absence of a secure element if your device is ever physically stolen, and the lack of active firmware development, which means a future flaw would likely never be fixed. Buy a modern device, set it up properly, verify it restores from its own new recovery phrase, then move your funds and keep the old device until you are satisfied.

Is KeepKey still supported?

Nominally, in the sense that the software still exists and the devices still function. Meaningfully, no — development has been minimal since ShapeShift restructured, and the pace of firmware updates, coin support and integration work is nowhere near what the active manufacturers deliver. In hardware security, a product that has stopped moving is a product whose known-unknowns will never be addressed.

Can I move my KeepKey wallet to a Trezor or Ledger?

Yes, and it is straightforward, because KeepKey uses the standard BIP39 recovery phrase. Your twelve or twenty-four words will restore in a Trezor, a Ledger, a BitBox or free software — the coins were never on the device, only the key that proves they are yours. That said, we would generate a new wallet on the new device and send the funds across as a transaction rather than importing the old phrase, because a phrase that has existed on an unmaintained device for years is a phrase with unknown exposure history.

Next in this cluster

Keep reading