To facilitate users, security researchers, and third-party organizations in understanding the security audit scope of the OneKey hardware wallet, this document lists publicly verifiable firmware versions, fixed versions, and corresponding audit reports.
Among them, the main control firmware (MCU) and Bluetooth firmware are maintained in an open-source manner and can be verified through the corresponding versions on GitHub; the security chip (SE) firmware has completed security auditing, but due to involving the chip manufacturer's intellectual property, the related source code and firmware documentation cannot be made public.
OneKey Pro
Main Control Firmware
Audited Version
Repository:
firmware-proRelease Version:
v4.10.0Commit:
6a387f588b29885b6adebd994df417be090c210c
Fixed Version
Warehouse:
firmware-proRelease Version:
v4.11.0Commit:
a969ccccb950c36bea613a65f28bad620753e99d
Audit Report
OneKey Pro Main Control Firmware Audit Report (please replace with the corresponding report link or attachment)
Bluetooth Firmware
Audit Version
Warehouse:
bluetooth-firmware-proRelease Version:
v2.3.2
Full Audit Report:SlowMist Audit Report - OneKey Pro_en-us.pdf
OneKey Classic 1S
Main Control Firmware
Audit Version
Repository:
firmware-classic1sAudit Branch:
slowmist_auditCommit:
66e7fee2d00ea22616a9a488266c472abeafc6d3
Fixed Version
Warehouse:
firmware-classic1sCommit:
46b864f8d22713a4b27bf7d04dadc2d0430110c2
Full Audit Report:SlowMist Audit Report - OneKey Classic 1s_en-us.pdf
