We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Keystone 3 Pro setup: step-by-step guide from unboxing to your first transaction
Keystone 3 Pro setup should start with verifying the device and checking a few basic security settings. In this guide, we walk through the entire process step by step, from inspecting the box to signing your first transaction. We based the instructions on Keystone’s official documentation and kept menu labels exactly as they appear on the device.
Keystone 3 Pro is designed primarily for air-gapped operation, without a network connection. The device does not connect to the internet, Wi-Fi, or Bluetooth, and the workflow in this guide transfers data between Keystone and software wallets with QR codes. Keystone 3 Pro also supports USB data transfer for compatible integrations. If you do not need it, you can disable it under [···] > [Device Settings] > [Connection] > [Data transfer with USB]. The USB port will then work for charging only.
The menu paths and firmware requirements in this guide were checked as of September 2026. Before updating, always confirm the current Latest Firmware on Keystone’s official firmware page.
Keystone 3 Pro setup: what you’ll need
Before you start, prepare the following:
How long does the setup take?
The total time depends on the firmware already installed and the update method you choose. Do not rush the initial setup. Give yourself enough uninterrupted time to verify the device, update the firmware, and record the seed phrase carefully.
Step 1. Unbox the device and inspect the packaging
Before opening the box, inspect it carefully. Genuine Keystone packaging is protected with shrink wrap and holographic seals across the seams. Torn wrap, resealed or damaged security seals, glue residue, or obvious wear can indicate that the box was opened before it reached you.
What comes with Keystone 3 Pro
Once the box is open, make sure the contents are complete:
A microSD card is not included and must be purchased separately if you plan to use that update method.
Step 2. Power on Keystone for the first time
Charge the device
Connect Keystone to a charger or laptop using the included USB-C cable. Firmware updates require at least 40% battery, so it is best to charge the device well above that threshold before you begin.
Use the included cable or another known-good USB-C cable. If the device does not charge, try a different cable and power adapter before assuming there is a problem with the wallet.
Turn the device on
Press and hold the side power button until the Keystone logo appears. The device will then enter the initial setup flow.
Choose the interface language
The first screen asks you to choose the interface language. Select English and tap the arrow to continue.
Step 3. Verify the device (Device Verification)
Device Verification helps confirm that your Keystone is genuine and can flag potential device or firmware issues after delivery. Keystone lets you skip this step, but we recommend completing it on every new device.
To verify the device:
Step 4. Update the firmware (Firmware Update)
A brand-new Keystone may still arrive with an older firmware version. Updates fix bugs and security issues and add support for new networks and features. Keystone allows you to skip this step, but we recommend checking the available firmware before creating a new wallet.
If you want a dedicated update walkthrough, see our step-by-step Keystone 3 Pro firmware update guide. It covers microSD, USB, and checksum verification in more detail.
Keystone’s official firmware page offers three branches: Multi-Coin, Bitcoin-Only, and Cypherpunk. Multi-Coin is marked as Default and is the right choice for most users. Bitcoin-Only is intended for Bitcoin-only use, while Cypherpunk covers BTC, Zcash, Monero, and other supported privacy-focused use cases. Unless you intentionally chose a different branch, use Multi-Coin during initial setup and install the current Latest Firmware.
Two ways to update
In this guide, microSD is the primary update method because Keystone does not need to be connected to the computer, preserving the air-gapped workflow.
Option 1: update with a microSD card
You will need:
Update procedure:
Option 2: update over USB
This method is available when the currently installed firmware is 1.0.4 or later. If the device is running an older version, the first update must be performed with a microSD card.
Step 5. Create a new wallet
You will now set an access code, name the wallet, and generate its seed phrase. If the device is lost, damaged, or reset, you will need the correctly recorded seed phrase to recover the wallet.
Create or import a wallet
After verification and the firmware update, the device offers two choices:
Set a PIN code
Keystone will ask you to set an access code. Its official documentation uses the term passcode: you can use a numeric PIN or a more complex password containing numbers, letters, and symbols. For simplicity, this guide uses a numeric PIN.
Do not use birthdays, simple sequences such as 123456 or 111111, or the PIN from a bank card. A random number you can reliably remember is a better choice. If you write the PIN down, store it separately from the seed phrase and in a different location.
Name the wallet (Name Wallet)
After you set the access code, Keystone will ask you to name the wallet, for example Main Wallet or Trading 2026. The name is only there to help you tell wallets apart on the device. You can skip this step and rename the wallet later under [Device Settings] > [Wallet Settings]. Do not put personal or confidential information in the wallet name.
Generate and record the seed phrase
A seed phrase, also called a mnemonic phrase, is a sequence of words from the BIP39 word list from which the wallet can deterministically recover its cryptographic keys and addresses. If the device is lost, damaged, or destroyed, a correctly recorded seed phrase can restore access in a compatible wallet.
If someone gets the seed phrase for a standard wallet, they can restore that wallet without knowing the PIN for your Keystone. That is why a seed phrase should never be photographed or stored on an internet-connected device or service.
Store the seed phrase securely
The included Secret Recovery Sheet is fine as an initial backup, but paper is vulnerable to fire, water, fading, and physical damage. For long-term storage, consider a metal seed phrase backup:
Practical backup guidelines:
Step 6. Set up fingerprint unlock (optional)
The fingerprint sensor is located on the back of Keystone 3 Pro below the camera. According to Keystone’s documentation, you can enroll up to three fingerprints and choose what each fingerprint can be used for.
Add a fingerprint
Keystone’s documentation uses two slightly different labels for this section: [Fingerprints & Password] on the fingerprint page and [Fingerprint & Passcode] on the passcode-reset page. They refer to the same area under [Wallet Settings], so use the menu position as your reference if the wording differs.
Choose where the fingerprint can be used
After enrollment, Keystone opens Fingerprint Applicable Scenarios, where you can choose what the fingerprint is allowed to do:
We recommend leaving Transaction Signing disabled for fingerprint authentication. If you want to use biometrics, use it for device unlock and keep transaction signing behind the PIN. You can also choose not to use biometrics at all.
Step 7. Connect a software wallet
Keystone stores the private keys and signs transactions. To view balances, receive and send crypto, and use DeFi or NFTs, you pair it with a compatible software wallet. This guide uses QR-based connections; some Keystone 3 Pro integrations also support USB.
You have two main options: Keystone’s own Nexus app or third-party wallets such as OKX Wallet, MetaMask, and Rabby. We will start with Nexus.
Examples of compatible software wallets
For the current list of supported wallets, networks, and assets, see Keystone’s official compatibility list. Keystone updates this page as new integrations are added, so check it before relying on support for a specific asset or network.
Option 1: Keystone Nexus (official app)
Keystone Nexus is the official mobile companion app for Keystone 3 Pro on iOS and Android. It displays balances, prepares asset operations, and sends transaction data to Keystone for review and signing. The private keys remain on the hardware wallet.
Why start with Nexus?
How to connect Keystone to Nexus
Nexus receives the public data required to derive/display addresses and balances and then shows those assets on its home screen. Your private keys remain on Keystone: Nexus prepares transactions, while signing happens on the hardware wallet.
How to send a transaction through Nexus
Option 2: third-party wallets
Third-party wallets are useful when you need a specific DeFi protocol, NFT marketplace, or network feature. Compatible options include OKX Wallet, MetaMask, and Rabby. Below we use the mobile version of OKX Wallet as a practical example. Other wallets may use different menu labels, so check Keystone’s dedicated instructions for the app you choose.
How to connect OKX Wallet
The mobile version is used here as the example. Pairing is done with a QR code, and the private keys remain on Keystone.
After updating the firmware in Step 4, you do not need to separately check an older minimum-version requirement for OKX Wallet. Install OKX Wallet only from the App Store, Google Play, or the official OKX website.
Step 8. Receive cryptocurrency
Once a software wallet is connected, you can receive funds. Wallet addresses are deterministically derived from your keys, and you should verify the address on Keystone before using it.
How to get a receiving address
EVM addresses and networks
A single EVM address beginning with 0x can be used across multiple EVM-compatible networks, including Ethereum, BNB Chain, Polygon, Arbitrum, Optimism, and Avalanche C-Chain. The same address may appear on several networks, but balances and tokens on those networks remain separate.
Your funds exist on the network where they were sent. If someone sends you USDT on Polygon while your software wallet is currently showing Ethereum, you need to switch to Polygon to see that balance.
Bitcoin uses separate address formats: bc1q… for Native SegWit, bc1p… for Taproot, addresses beginning with 3… for P2SH/Nested SegWit, and addresses beginning with 1… for Legacy. You cannot send BTC to an ETH address or ETH to a Bitcoin address.
Step 9. Send your first transaction
In this guide, sending is handled with QR codes: the software wallet builds the transaction, Keystone reviews and signs it, and the signed transaction is returned to the software wallet for broadcasting. Your private keys never leave Keystone.
The complete sending flow
After broadcasting, track the transaction status in your software wallet or a blockchain explorer.
What to check when signing smart-contract transactions
A simple transfer makes the recipient and amount easy to inspect. In DeFi, however, a transaction may call a smart contract for actions such as swap, staking, or approve. Keystone decodes supported transactions so it can show human-readable signing details instead of only raw transaction data.
Before signing, check:
What to do after setup
A few practices are worth keeping as ongoing habits:
Troubleshooting common problems
USDT is in the wallet, but you cannot send it
Check the balance of the network’s native coin. USDT transfer fees are not paid in USDT; they are paid in the blockchain’s native asset, such as ETH on Ethereum, TRX on Tron, or BNB on BNB Chain. If that balance is zero, add enough of the native coin to cover the network fee and try again.
For more detail on choosing a network and keeping the correct native coin for fees, see our Lwallet guide to using USDT with a hardware wallet.
The device will not turn on
Connect the device to power and let it charge before trying again. If the included cable does not work, test another known-good USB-C cable and power adapter. If that does not help, contact the seller or Keystone Support.
Firmware will not update from microSD
Check these items in order:
Keystone will not scan a QR code
Increase the screen brightness and hold Keystone so the entire QR code fits inside the camera frame. Adjust the distance or angle slightly if necessary, and wipe the rear camera lens with a soft, dry cloth. If the QR code is animated, keep the camera steady until the device reads the full sequence.
The software wallet cannot find Keystone
Update the app to the latest version. On Keystone, open [···] > [Connect Software Wallet] again, choose the required wallet, and repeat the pairing process in the app. Make sure camera permission is enabled and scan a freshly generated QR code from Keystone.
You forgot the PIN
Resetting a forgotten passcode requires seed phrase verification. Keystone’s official documentation gives the path [···] > [Device Settings] > [Wallet Settings] > [Fingerprint & Passcode] > [Reset Passcode] > [Forgot Passcode]. The exact on-screen location can vary with device state and firmware version, so use the [Forgot Passcode] label and the prompts shown by the device as your guide.
The transaction QR code is too large for Keystone
Complex transactions contain more data, so the QR may be split across multiple animated frames. This is normal: keep Keystone steady and wait until it reads the full sequence. If scanning does not start, increase the phone screen brightness and make sure Keystone’s camera lens is clean.
The device appears stuck during a firmware update
Do not power the device off during an update. If the progress indicator does not change for an unusually long time, compare your steps with Keystone’s official firmware update instructions and contact Keystone Support. Do not interrupt the update at random.
Where to buy Keystone 3 Pro
A hardware wallet is best purchased directly from the manufacturer or from an authorized reseller. This reduces the risk of receiving a device of unknown origin that may already have been opened or tampered with before sale.
You can order Keystone 3 Pro from Keystone’s official store or buy it from us at Lwallet. We are also listed in Keystone’s official authorized reseller directory for Ukraine.
We supply genuine Keystone devices in Ukraine and can help with setup and everyday use.
Setup complete: what’s next?
Once your Keystone 3 Pro setup is complete, make sure you have:
Features worth exploring later:
Related Posts
Ledger Flex setup: step-by-step guide from unboxing to your first transaction
Ledger Flex setup is best done step by step, from checking the box contents to completing your first test transaction. If you have just received a Ledger Flex, this guide will walk you through installing Ledger Wallet, running Genuine Check, creating a new wallet, writing down your Secret Recovery Phrase, and setting up your recovery …
Best Hardware Wallets in 2026: Which One Should You Choose?
If you’re comparing the best hardware wallets in 2026, the first question is what you actually need one for. When crypto is held on an exchange, the exchange controls the private keys — not you. In February 2025, Bybit was hacked for roughly $1.4 billion. Before that came FTX, Celsius, Mt. Gox, and other platforms …
How to Stake Solana on Ledger Nano X
Which Hardware Wallet Should You Choose for Storing USDC?
If you hold USDC and don’t want to live with the thought that an exchange could freeze your account, suspend withdrawals, or face liquidity issues — a hardware wallet removes that uncertainty. This article is for those who want to store stablecoins under their own control: without exchange risks and without relying …