Our wallet review process
We examine wallets starting at the code level and continue all the way up to the finished app that lives on your device. Provided below is an outline of each of these steps along with security tips for you and general test results.
Application build test result
imKey is only partially Open Source. According to its User Agreement:
Section 3.3.2 imKey software open source code may contain third-party-developed open source license and source code and the Company does not provide any guarantee for functions, non-existence of virus or vulnerabilities etc of such third-party-developed open source license and source code. Developer Users shall, at their sole discretion, decide the consequences of using imKey software open source code. Developer Users shall carefully read and then agree with relevant open source licenses and notices of the Company updated from time to time
Furthermore, this is what it has to say about its Secure Element chip:
Open source will bring immeasurable security risks and even threaten homeland security. Therefore, open source cannot be used as a criterion for judging whether a security chip is secure, and compared to open source, black box privacy is more conducive to ensuring its security.
A lot of security chip knowledge sounds rather obscure. In summary, it is recommended that when buying hardware wallets, try to buy products that use security chips and have security certification qualifications.
The device is paired via Bluetooth with the imKey Manager desktop software by connecting through USB. The imKey Manager desktop software is how the device’s firmware is updated.. It is also possible to pair with the
Private keys can be created offline - ✔️
The recovery phrase is generated in the hardware wallet after it is paired with the imToken app.
Private keys are not shared - ✔️
According to official documentation the private key is never shared and stays in the Secure Element chip of the hardware wallet.
Device displays receive address for confirmation - ✔️
Yes, the device displays the receiving address and is confirmed by pressing a button.
Reproducibility - ❌
The language on imKey’s website about whether the hardware wallet is open source or not is not clearly defined. There is also no link to any repository. This is also bolstered by the fact that the hardware wallet is paired with.
Tests performed by Daniel Andrei R. Garcia
Do your own research
In addition to reading our analysis, it is important to do your own checks. Before transferring any bitcoin to your wallet, look up reviews for the wallet you want to use. They should be easy to find. If they aren't, that itself is a reason to be extra careful.