Skip to main content

Keystone Has Landed in Lace

Your Keys. Your Way.

Keystone Has Landed in Lace

There's a moment every self-custody user reaches: the point where "I should probably get a hardware wallet" turns into "which one?" It's not a small question. The answer shapes how you'll interact with your assets for years.

Today, that question got a new answer. Keystone is now supported in Lace!

Why This One Mattered

We track feature requests closely, and Keystone kept surfacing, not as a passing mention, but as a recurring, specific ask from people who already understood exactly why they wanted it. That's usually a sign worth paying attention to. When a community keeps naming the same device, it's telling you something about what they value that your current lineup doesn't cover yet.

What Keystone's users value, broadly, is distance. Not distance from their assets (the opposite, really), but distance between their private keys and anything with a network connection. No USB data connection, no Bluetooth, no WiFi, no NFC for signing. Just a screen, a camera, and a QR code doing the talking.

Air-Gapped, Practically Speaking

Here's the case for that approach, stripped of marketing language: every wire is a potential path in. USB and Bluetooth are convenient because they carry data automatically, but "automatically" cuts both ways. Once two devices are connected, the connection can carry more than either side necessarily intends. A QR code doesn't work that way. It's a one-way, human-mediated handoff. You scan it deliberately, it carries a fixed amount of data, and there's no live link left behind once the transfer is done.

That doesn't make Keystone bulletproof (nothing is), but it does mean the attack surface for a whole category of remote exploits simply isn't there. For a lot of people, that trade-off, a slightly more deliberate signing flow in exchange for that isolation, is worth making.On Seed Phrase Generation

Recent conversations across the hardware wallet industry have people paying closer attention to a question that used to sit quietly in the background: how is your seed phrase actually generated, and can you trust it? It's a fair question, and worth answering directly.

Keystone generates seed phrases using true random number generators built into three separate secure element chips, the same category of hardened hardware used in passports and bank cards, rather than relying on a single point of failure. But Keystone also doesn't ask you to simply trust that process if you'd rather not. Users who want to generate their own entropy can do so manually with physical dice rolls, verifiable step by step, instead of leaving generation entirely to the device. Which approach you use is your call, not something the device decides for you.

For a closer look at how this works, Keystone has published its own breakdown of the secure element architecture and a step-by-step guide to the dice roll method.

One Wallet, Many Philosophies

We now support Ledger, Trezor, SeedSigner, and Keystone.

Chain support varies by device, so check which assets each one covers before you buy, but look at those four next to each other and you'll notice they take very different approaches: different stances on open-source firmware, different levels of minimalism, different ways of connecting or staying disconnected. But underneath those differences, they all share the same underlying philosophy: keeping your assets safe is the priority, whichever path gets you there.

We're not going to tell you one of those is correct. That's the point. The right hardware wallet is the one that matches how you think about risk, convenience, and control, and those things are genuinely personal. Our job isn't to make that decision for you. Signing with an air-gapped device is more deliberate than plugging in a cable, and that's not a downside to smooth over. It's the trade-off Keystone users are choosing on purpose.

What This Is Actually Part Of

This launch sits inside Your Keys. Your Way, a commitment we keep coming back to because it keeps being true: self-custody isn't a single workflow that everyone should be squeezed into. It's a principle, you hold the keys, that supports a lot of different, equally valid ways of putting it into practice.

Keystone support doesn't close that chapter. It's one more device on a list we intend to keep growing, because "more choice" isn't a campaign slogan with an end date. It's just the direction we're headed.

Watch the Walkthrough

We've also put together a step-by-step video showing exactly how to pair your Keystone device with Lace and sign your first transaction. If you'd rather watch than read, that's the fastest way to get set up.

Get Your Hands on One

To mark the launch, we're giving away 5 hardware wallets in an exclusive Lace-branded design. Full giveaway entry details are on this blog here.

The same design is also listed on the Keystone website at a discount for our community. Use code ‘LACE’ to apply $50 off, from today until Tuesday 1st September. Once that window closes, the only way to get one will be through future giveaways.

When your device arrives, whether through the giveaway or the discount, check that the packaging is tamper-evident and generate your seed phrase on the device itself, never anywhere else.

Get Started

If you've been holding off on a hardware wallet until your preferred option showed up, or you already own a Keystone device and have been waiting for this exact update, it's here.

Keystone works in both the Lace browser extension and the Lace mobile app. Make sure your Keystone device is running firmware v3.0.4 or later, then update to the latest version of Lace and connect your device. If you're pairing via the extension, you'll need a webcam to scan the QR codes during setup and signing.

Your keys. Your way.

Still true, one more device later.


Team Lace