Foundation Passport is built on a single distinguishing principle: everything in the security-critical path is publicly readable code. The PCB hardware schematics are on GitHub. The device firmware is on GitHub. The Envoy companion app is on GitHub. A technically capable person can review every line of code in the key generation, address derivation, and transaction signing path, verify the hardware design against the manufactured device, and compile the firmware independently. No other major hardware wallet achieves this level of coverage. Ledger's secure element firmware is proprietary. Trezor's ATECC608A includes proprietary components. ColdCard's hardware designs are not fully published. Passport has no proprietary component in any security-critical path.
Foundation Passport is the answer for a Bitcoin holder whose security requirement is knowing — not trusting — that the device performs exactly as claimed. Full open-source coverage means the security properties are independently verifiable rather than manufacturer-asserted. The Bitcoin security community reviews the code continuously. For holders with significant on-chain positions who require the highest available assurance of signing device integrity, Passport is the only major hardware wallet that provides it. Bitok Arena's read: the open-source premium matters proportionally to the position size at risk.
Foundation Passport supports Native SegWit (bc1q) and Taproot (bc1p) addresses — the formats used across on-chain Bitcoin transactions. The USB-C port handles firmware updates only — no transaction data passes through it. The air-gap is hardware-enforced through QR code signing exclusively: transaction data moves between the signing device and companion software via QR codes scanned by Passport's built-in camera, not through any cable connection. Compatible companion apps are Envoy (Foundation's open-source mobile app for iOS and Android) and Sparrow Wallet on desktop.
The Open-Source Architecture in Practice
Foundation's design philosophy rejects the secure element approach used by Ledger and Trezor's premium models. A secure element provides hardware tamper resistance but requires accepting proprietary firmware that cannot be independently verified. Foundation argues that a well-implemented open-source signing environment on an open-source microcontroller is more trustworthy than unauditable closed hardware — and that the security audit the open-source approach enables compensates for the absence of a secure element's tamper resistance. The Bitcoin security community has not reached consensus on this trade-off, but both positions have credible technical defenders.
Bitok Arena reviewed Foundation Passport's technical specifications and open-source coverage as they apply to daily on-chain Bitcoin transaction signing.
Open-source coverage — hardware PCB schematics: publicly available on Foundation GitHub; device firmware: fully open source, Bitcoin-only; Envoy companion app: fully open source; scope of independent auditability: complete for all security-critical code paths. Other major hardware wallets: Ledger SE firmware proprietary; Trezor ATECC608A proprietary; ColdCard hardware design not fully published.
Technical specifications — address formats: bc1q (Native SegWit) and bc1p (Taproot); air-gap method: QR code only (no USB transaction data); built-in camera for QR scanning; Passport Batch 2 price approximately $199; Passport Prime approximately $249; 2.7-inch color display (Batch 2).
Security review record — Bitcoin security researchers have published findings on Passport firmware through public disclosure process; identified issues have been patched in subsequent firmware releases; ongoing public review is active. Public disclosure creates accountability not available with proprietary firmware.
The daily workflow with Passport uses Sparrow Wallet on desktop or Envoy on mobile. Pairing is a one-time setup using Passport's output descriptor QR — after which Sparrow manages the watch-only account with access to the public key and address history but not the private key. For each on-chain transaction: create the transaction in Sparrow, export the unsigned PSBT as an animated QR, scan with Passport's camera, verify the destination address on Passport's display character by character, enter the Passport PIN to approve, Passport displays the signed transaction as QR, scan back into Sparrow with the computer camera, broadcast. Total per-transaction time approximately 5 to 7 minutes from transaction creation to broadcast.
Address Verification: The Most Critical Daily Step
Regardless of which hardware wallet is used, address verification on the device's own display is the step that matters most for secure on-chain Bitcoin transactions. Clipboard-hijacking malware that substitutes a different destination address between the user copying an address and Sparrow displaying it will be caught by this step — the hardware wallet's display shows the actual destination the transaction will be signed for, derived directly from the PSBT, not from what the companion app shows on screen. For daily on-chain Bitcoin transactions, this verification is the primary defense against the most common attack vector.
Bitok Arena evaluated the address verification quality and workflow implications across Foundation Passport and comparable hardware wallets.
Foundation Passport (Batch 2) — 2.7-inch color display; full bc1q address (42 characters) visible in a single view or with minimal scrolling; address verification comfortable for character-by-character review; built-in camera makes QR workflow cable-free.
Workflow time comparison for on-chain transaction signing — Ledger Nano X (USB, Sparrow): approximately 3–4 minutes; ColdCard Q (QR, Sparrow): approximately 5–6 minutes; Foundation Passport (QR, Sparrow): approximately 5–7 minutes; extra 1–2 minutes versus Ledger is the QR workflow cost for hardware air-gap signers.
For participants who require full open-source auditability over the fastest possible daily workflow, the 1–2 minute premium is the accepted trade-off. For participants who prioritize daily signing speed over audit completeness, Ledger's USB workflow is faster.
Foundation Passport is the appropriate choice for on-chain Bitcoin participants who hold significant positions and require the highest available assurance of signing device integrity. The fully open-source architecture means the security properties are verifiable rather than claimed — and the ongoing Bitcoin security community review means any vulnerabilities in the code are publicly disclosed and addressed, creating accountability that proprietary firmware cannot provide. For participants who hold smaller positions or who are comfortable with the established manufacturer trust models, Ledger or ColdCard provide adequate security at lower cost with slightly less QR friction. Neither choice changes the on-chain transaction the wallet produces — the bc1q address generated and the Bitcoin transaction signed are identical regardless of which device holds the key.
Bitok Arena's review of Foundation Passport for daily on-chain Bitcoin transaction signing: it is the only major hardware wallet with complete open-source coverage across hardware, firmware, and companion app. The security community reviews it continuously and findings are publicly disclosed. For Bitcoin holders who require knowing rather than trusting that their signing device performs as claimed, no other device currently provides this. The workflow is QR-based, requiring 5–7 minutes per transaction — 1–2 minutes more than a USB-based alternative. That is the cost of the open-source air-gap. Whether it is worth it scales with the position being protected.
The device generates the bc1q address, holds the private key in publicly audited code, signs the transaction with that key, and returns the signed transaction via QR to the companion software for broadcast. Every step in this path is readable code. The signing device whose operation can be independently verified rather than taken on trust is the one appropriate for the participants to whom that assurance matters most.
Bitok Arena's Foundation Passport review: the only major hardware wallet with fully open-source hardware schematics, firmware, and companion app. QR-based air-gap signing exclusively — no USB transaction data path. Compatible with Sparrow Wallet and Envoy app. Address support: bc1q and bc1p. Price: approximately $199 (Batch 2) to $249 (Prime). Workflow: 5–7 minutes per on-chain transaction. The premium over faster USB-based alternatives buys complete open-source auditability and continuous Bitcoin security community review. The position size that justifies that premium is a decision each participant makes based on what they are protecting.