01
Wallet security model
KeepKey Wallet is standalone self-custody software. Wallet secrets are protected locally using Android security and transaction signing is designed to happen on the device. KeepKey does not operate a hosted wallet account and cannot recover a lost recovery phrase.
This release is a software wallet and does not connect to a KeepKey hardware device. A rooted, compromised or unlocked phone can defeat software protections. Keep Android and the App updated, use a strong device lock, and keep recovery material offline.
02
Report a vulnerability privately
Send security reports to security@keepkey.com with [VULNERABILITY] and KeepKey Walletin the subject. Include the affected App version, device and Android version; a clear description; reproducible steps; impact; and any suggested mitigation.
KeepKey Security
Please report privately before public disclosure.
03
Responsible testing
Use only accounts, wallets, devices and funds that you own or have explicit permission to test. Do not access other people’s information, degrade services, use social engineering, perform denial-of-service testing, or move assets that are not yours. Stop and report if you encounter sensitive data.
We will make a good-faith effort to acknowledge useful reports and coordinate remediation and disclosure. This page does not promise a bounty or waive rights for activity that is unlawful, harmful, outside this scope or not conducted in good faith.
04
If you think your wallet is at risk
Disconnect the device from networks, use a trusted clean wallet to move assets if safe to do so, revoke suspicious dApp approvals, and replace exposed recovery material with a new wallet. Blockchain transactions cannot generally be reversed by KeepKey.
Never send a recovery phrase, private key, App passcode or backup password in a security or support report.