Foundation Passport Review: The Open-Source Case for On-Chain Transactions Entry
Foundation Passport is built on a single distinguishing principle: everything in the security-critical path is publicly readable code. The PCB hardware schematics are on GitHub. The device firmware is on GitHub. The Envoy companion app is on GitHub. A technically capable person can review every line of code in the key generation, address derivation, and transaction signing path, verify the hardware design against the manufactured device, and compile the firmware independently. No other major hardware wallet achieves this level of coverage. Ledger's secure element firmware is proprietary. Trezor's ATECC608A includes proprietary components. ColdCard's hardware designs are not fully published. Passport has no proprietary component in any security-critical path.
Foundation Passport is the answer for a Bitcoin holder whose security requirement is knowing — not trusting — that the device performs exactly as claimed. Full open-source coverage means the security properties are independently verifiable rather than manufacturer-asserted. The Bitcoin security community reviews the code continuously. For holders with significant on-chain positions who require the highest available assurance of signing device integrity, Passport is the only major hardware wallet that provides it. Bitok Arena's read: the open-source premium matters proportionally to the position size at risk.
Foundation Passport supports Native SegWit (bc1q) and Taproot (bc1p) addresses — the formats used across on-chain Bitcoin transactions. The USB-C port handles firmware updates only — no transaction data passes through it. The air-gap is hardware-enforced through QR code signing exclusively: transaction data moves between the signing device and companion software via QR codes scanned by Passport's built-in camera, not through any cable connection. Compatible companion apps are Envoy (Foundation's open-source mobile app for iOS and Android) and Sparrow Wallet on desktop.