FREQUENTLY ASKED QUESTIONS

FAQ

よくあるご質問

Shown in both Japanese and English. Click a question to expand its answer.

1Product Basics

Q1-1 What is Openloop?

Openloop is a hardware wallet and signer for crypto assets, planned and developed in Japan. It is built around a secure element (a dedicated chip) certified to EAL6+, the world’s highest class of security certification, and it keeps the entire lifecycle of your private keys — generation, storage, and signing — inside the device.

As a wallet, it packs in the latest technology. It supports Bitcoin, Ethereum, XRP, Solana, and TRON, along with 215 EVM networks and roughly 2,600 ERC-20 tokens (including stablecoins such as JPYC, USDC, and USDT). It supports all three connection methods — USB, BLE (Bluetooth), and Air Gap (QR code) — so you can work anywhere from fully online to completely offline, depending on your needs. Every transaction must be reviewed and confirmed on the device’s own screen before it is signed, so your assets stay safe even if your PC or smartphone is compromised.

On top of that, the same chip also runs FIDO2 passkeys (security key) and PIV (digital signatures and certificates), making Openloop a genuine three-in-one device.

Q1-2 What is a "hardware wallet"?

A hardware wallet is a dedicated device that generates and stores the “private keys” needed to move crypto assets, physically isolated from the internet. Even if your PC or smartphone is infected with a virus, the private keys themselves never leave the device, so your assets stay protected. Think of it as keeping your “bankbook and seal” locked away in a vault that is cut off from the network.

Q1-3 What is a "signer"?

A signer is a device that applies a cryptographic “signature” to a transaction (an action such as a transfer or a contract call) using a private key. Openloop doesn’t just store keys — it proves, as a cryptographic signature, that a human has given final approval to “go ahead and perform this action.” In an age where AI agents increasingly act on our behalf in economic activity, we place great importance on the principle that the final approval to move assets should be made by a human, on a physical device.

Q1-4 What exactly does "three-in-one" mean?

A single device provides the three functions below. All of them run on the same EAL6+ secure element and the same cryptographic engine.

Function Description
① Crypto wallet (signer) Storage and signing for BTC, ETH, and other crypto assets
② FIDO2 / CTAP2 passkeys Passwordless, phishing-resistant sign-in to Google, Microsoft, and more
③ PIV / PKCS#11 SSH authentication, PDF signing, GPG signing, TLS client authentication
Q1-5 What company makes it?

Openloop is developed by Haudi Crypto, Inc., a wholly owned subsidiary of Haudi, Inc., a company that works at the intersection of hardware and AI. Development is led by engineers with a proven track record in cryptographic communications dating back to the early days of the internet. A key strength is that the planning, design, and implementation are all carried out end-to-end in Japan.

About Haudi, Inc.

Guided by its motto — “Toward a world where technology lets everyone bring out their full potential” — Haudi is a deep-tech company that handles the full stack from hardware to AI in-house. It turns the environment into data with sensors, makes decisions with AI, and controls machinery — uniting this “sense, think, act” loop and implementing a Physical AI foundation across every field site, from factories and robots to facilities and stations.

Openloop (the crypto signer) is a “human-and-AI-connecting” piece of hardware born from that philosophy.

Q1-6 Is the firmware made in Japan?

Yes. The hardware planning and design, as well as the firmware (the device software), are all developed in Japan. Both the design and the source code are the work of engineers based in Japan.

Q1-7 Who is the developer?

Development is led by Kazunori Asada, an engineer with a proven track record in cryptographic communications, PKI, and key management dating back to the early days of the internet. He founded the information security company “Open Loop” (the product name “Openloop” traces its origin to that company).

Q1-8 Where is it manufactured?

Mass production (manufacturing) of the hardware takes place in China. However, the only operation performed at the factory is writing the signed firmware binary to the devicethe source code exists only in Japan (the factory cannot view or alter the source code). The firmware includes signature verification, so tampered firmware cannot be booted or installed. All planning, design, and firmware development (the source code) are carried out in Japan.

Q1-9 Can I use it without a smartphone or PC?

Initial setup (creating a wallet), checking your receiving address, and Air Gap signing via QR codes can all be done on Openloop alone. However, to actually broadcast a transaction to the blockchain, or to work with a wallet app or web service, you connect the device to a PC, smartphone, or supported app.


2Hardware and Device Specifications

Q2-1 How big is the device?

Approximately 54mm × 54mm × 15mm — a compact size that fits in the palm of your hand.

Q2-2 How much does it weigh?

Approximately 50g.

Q2-3 What are the display specs?

A 2.0-inch IPS LCD (320 × 240 pixel resolution) with a capacitive touchscreen. You review transaction details and addresses on the screen and operate the device by touch.

Q2-4 What are the camera specs?

The back of the device has a GC0308 (approx. 0.3-megapixel VGA sensor). It is used solely for reading QR codes (for Air Gap signing) and is actually operated at QVGA (320×240) size. It has no photo-taking or storage functions.

Q2-5 What secure element does it use?

It uses NXP’s SE050 (EAL6+ certified). EAL6+ is a world-class security certification, the same class used in credit card IC chips and passports. This secure element is used for key storage and signing (ECDSA / EdDSA / RSA), and private keys never leave the device.

Q2-6 What's inside (the processor)?

Espressif’s ESP32-S3 (dual-core, 240MHz). It has 512KB of SRAM plus 8MB of PSRAM for RAM, and 16MB of flash memory.

Q2-7 How is it charged?

It charges via USB Type-C. Standard USB-C cables and chargers work fine.

Q2-8 Does it use Wi-Fi?

No. For security reasons, Openloop never uses Wi-Fi (it is neither initialized nor started up). The device operates safely offline, cut off from any network.

Q2-9 What is the operating temperature range?

The operating temperature is 0–60°C. Note: Because the device contains a lithium-polymer battery, avoid using or charging it in high-temperature environments such as in direct sunlight or inside a car, or below freezing.

Q2-10 Is it waterproof or dustproof?

At this time we make no waterproof or dustproof claims. Please keep the device dry.

Q2-11 Does it make sounds? Can I turn them off?

The device provides audio feedback such as startup, click, success, error, and payment sounds. In the settings screen you can adjust the volume (0–100%) and turn the click sound on or off.

Q2-12 What languages are supported?

Japanese and English. You can switch between them at any time in the settings screen, and both the UI and the manual are available in each language.


3Power, Battery, and Sleep

Q3-1 How do I turn it on and off?

You use the device’s power button. When the device is off, press the power button to turn it on; while it’s running, press and hold the power button to turn it off.

Q3-2 What is the battery capacity?

A built-in lithium-polymer (Li-Po) battery with a capacity of approximately 450mAh.

Q3-3 How long does it run on battery?

Approximately 1 hour of continuous use. The device is designed primarily to be used while powered over USB; the battery is there for portability and short periods of standalone use.

Q3-4 How long does the battery last (when will it need replacing)?

Because Openloop is designed primarily for use with USB power, it goes through few charge-discharge cycles, so the battery degrades slowly. We expect it to remain usable for several years or more. That said, lithium-polymer batteries are consumables and gradually lose capacity over time (the exact number of years depends on usage).

Q3-5 What happens when the battery runs out?

When the charge drops below a certain level, the device displays a warning and shuts down safely. Your private keys and wallet data are stored encrypted in non-volatile memory, so no data is lost even if the battery runs out. Once you recharge, everything works as before.

Also, even with a dead (or worn-out) battery, you can keep using the device on USB power simply by connecting it via USB. The battery is only for portability; when connected via USB, the device operates regardless of battery level.

Q3-6 Can I use it while charging?

Yes. In fact, using it while powered over USB is the standard mode of operation. While connected via USB, the device charges and operates at the same time.

Q3-7 What happens if I connect USB while the device is off?

Charging begins. Connecting USB while the device is off will automatically turn it on.

Q3-8 Does it sleep after a period of inactivity? How long?

After 60 seconds of inactivity, the screen turns off and the device enters sleep. This 60-second timeout is the same whether it’s connected via USB or running on battery. Touching the screen wakes it (depending on your settings, it may ask for a PIN on wake).

Q3-9 Are there different types of sleep?

Yes. There are two types, depending on the power state.

State Sleep behavior BLE How to wake
Connected via USB Screen off only (does not enter deep sleep, in order to keep the USB connection alive) Active Touch
Running on battery Light sleep (CPU enters low-power mode, screen off, BLE advertising stopped) Paused Touch
Q3-10 Does it behave differently on USB versus on battery?

The depth of sleep differs. On USB, only the screen turns off, so the connection isn’t dropped. On battery, it enters light sleep to save power and pauses BLE advertising. The everyday feel of using the device is the same.

Q3-11 Can I still use BLE (Bluetooth) while it's asleep?
  • Sleep while connected via USB: BLE remains active. You can wake the device by acting from your app.
  • Light sleep on battery: BLE advertising is paused to save power. Touch the device to wake it, and BLE resumes.
Q3-12 Does it sleep while connected over BLE?

While connected to a host over BLE, the device does not sleep automatically (it stays on standby while maintaining the connection). Once the connection drops and inactivity continues, it enters sleep. Note: If the battery drops to a critical level, the device will save its data and shut down safely even while connected.

Q3-13 What happens if it's left idle even longer after sleeping?

On battery (not connected via USB), if sleep continues for 5 minutes, the device shuts down safely (auto shutdown). Likewise, if the battery drops to a critical level during sleep, it saves its data and then automatically powers off. In every case, your wallet data is preserved.


4Security

Q4-1 What is EAL6+? (About the certification the SE050 holds)

EAL6+ (Evaluation Assurance Level 6+) is one of the assurance levels defined by “Common Criteria (ISO/IEC 15408),” the international evaluation standard for IT security. There are seven assurance levels, EAL1 through EAL7; the higher the number, the more rigorously an independent evaluation body has verified that the design and implementation have been examined and can withstand attack. EAL6+ is a very high level, just below the highest, EAL7, and is a world-class standard adopted in credit card IC chips, passports, and government IC cards.

Openloop is built around NXP’s “SE050” secure element, which holds this EAL6+ certification, and it generates, stores, and signs with keys inside that chip.

Note: EAL6+ is a certification of the chip (the SE050) — not of the Openloop product as a whole.

Q4-2 What is the basis for saying the private keys can't leak?

Because the generation, storage, and signing of the private keys all take place entirely inside the device (everything from key generation and derivation through signing happens on-device), and there is, by design, no path for a private key to leave the device. All that is passed to your PC or smartphone is the “signed data.”

Q4-3 Is there any case where a private key leaves Openloop?

No. Private keys are generated and stored inside the device, and there is no path by which they can be exported. Even if the PC or smartphone you connect to is infected with malware, the private keys are protected.

Q4-4 What proprietary security enhancements does Openloop use?

In addition to the secure element, Openloop implements its own multi-layered defenses.

  • DualSecure (dual-key protection): The wallet’s source data (entropy) is encrypted so that it can only be decrypted when both the ESP32-side key and a key inside the SE050 secure element are present (AES-256-GCM). Extracting just one chip is not enough to decrypt it.
  • DualSecure for passkeys, too: The seed for FIDO2 passkeys is protected with the same DualSecure (ECDH + AES-GCM) and is hardware-bound to a non-extractable key inside the SE050. This is a seed independent of the wallet.
  • PIV is protected by the SE050 as well: PIV keys are generated and stored inside the SE050 secure element and never leave it.
  • Signing always inside the SE050: Signing is always performed inside the secure element (SE050). Frequently used signing keys are held on the device to speed up signing, but signing still takes place inside the SE050.
  • Deterministic signatures and true randomness: Bitcoin and Ethereum use RFC 6979-compliant deterministic ECDSA, and randomness comes from the SE050’s hardware random number generator (TRNG).
Q4-5 Which cryptographic algorithms are supported?
Purpose Algorithm
Signing (elliptic curve) ECDSA secp256k1 (BTC / ETH / XRP / TRON), ECDSA P-256 (PIV / passkey ES256), EdDSA Ed25519 (XRP / SOL / passkey)
Signing (RSA) RSA-2048 (PIV)
Hashing SHA-256, SHA-512
Encryption AES-256-GCM (DualSecure storage)
Key derivation ECDH-based key derivation, BIP32 / BIP39 / BIP44 / SLIP-0010
Random number generation SE050 TRNG (true random)
Firmware update signature verification RSA-3072 + SHA-256 (RSA-PSS)
Q4-6 How many digits is the PIN?

You can set a PIN of 4 to 6 digits. During setup you enter it twice for confirmation.

Q4-7 What happens if I enter the PIN wrong repeatedly?

The lockout time increases in stages, and after the specified number of consecutive failures (10), the device automatically resets to factory state (erasing all data). This is not a permanent lock.

Consecutive failures Behavior
0–2 None
3 30-second lockout
4 1-minute lockout
5 5-minute lockout
6–9 10-minute lockout
10 or more Automatic reset to factory state (all data erased)

Note: After a reset, you can restore your assets on another device from the recovery phrase you saved.

Q4-8 What if I forget my PIN?

The PIN itself cannot be recovered or looked up afterward. Perform a factory reset to return the device to factory state, then restore your assets from the recovery phrase you saved. As long as you have your recovery phrase, your assets are not lost.

Q4-9 What happens when I do a factory reset ("Reset to factory state")?

Running “Reset to factory state” from the settings screen erases all data on the device and returns it to its as-purchased condition. The following data is erased: - Wallet (the source data for your crypto asset keys and recovery phrase) - Passkeys (FIDO2 credentials) - PIV slots (keys and certificates) and the PIV PIN - Various settings and PINs

Your crypto assets themselves remain on the blockchain, so you can restore them on another device from the recovery phrase you saved. Passkeys and PIV keys cannot be restored, so re-register them with each service as needed.

Note: If you want to erase only part of the data, you can reset each function individually using “Delete Wallet,” “Reset Passkeys,” or “Reset PIV.”

Q4-10 What happens if I lose the device or it's stolen?

Because it is protected by a PIN, a third party cannot immediately access its contents (and after the specified number of failed PIN attempts, the device automatically resets to factory state and erases its data). Your assets can be restored on another device from the recovery phrase you saved during setup. As long as you keep your recovery phrase safe, your assets are not lost.

Q4-11 What happens if the device breaks?

Using your recovery phrase (BIP39-compliant), you can restore your assets on another Openloop, or on a compatible third-party wallet (such as Ledger). Your assets live on the blockchain, and the device is merely a “vault that protects the keys,” so as long as you have the phrase, recovery is possible.

Q4-12 What is a recovery phrase, and how many words does it support?

A recovery phrase is a sequence of words (a mnemonic) used to restore your wallet’s private keys. It complies with the international standard BIP39 and supports 12 or 24 words. Write it down on paper or similar, and store it safely offline.

Q4-13 Is there any chance Openloop signs something on its own?

No. Every signature is executed only after the details are shown on the device’s screen and the user physically presses the “Approve” button. Even if your PC or smartphone is compromised, the final approval requires an action on the device itself. Note: The one exception is the “silent signing” mode of the PIV feature, which uses PIN authentication over USB (for automation use cases such as CI/CD) and can skip the on-screen confirmation. See 8. PIV Features for details.

Q4-14 What happens if a fraudulent (unintended) transaction is sent to it?

Before signing, details such as the destination address, amount, and chain name are shown on the device’s screen. If the details differ from what you intended, you can choose “Reject” and no signature is made. In addition, malformed (invalid-format) data is validated and rejected by the firmware.

Q4-15 Are firmware updates safe?

During a firmware update (OTA), the device performs RSA-3072 signature verification plus SHA-256 hash verification to confirm the firmware is legitimate before applying it. If verification fails, the update is not applied and the current firmware is kept. Updates can be done over USB or BLE from the Openloop Connect app.

Q4-16 If the company (manufacturer) goes out of business, will it stop working?

No. Your assets are on the blockchain, and because the recovery phrase follows a standard specification, you can restore your assets even on a compatible third-party wallet. The design does not lock you in to any particular company.

Q4-17 Is it "absolutely secure"?

There is no such thing as “absolute” in security. Openloop is a product that pursues a “design in which private keys never leave the device” and a “design that minimizes attack risk.” At the same time, appropriate handling on your part — such as safely storing your recovery phrase — is also important.


5Crypto Wallet Features

Q5-1 Which tokens does Openloop support? How many? Please be specific.

First, it supports the five native currencies (BTC, ETH, XRP, SOL, TRX). In addition, it comes with the major ERC-20 tokens by market capitalization built in, and it automatically displays their names and symbols (auto-generated based on CoinGecko’s market-cap rankings). The total number of registered entries is approximately 2,600 (registrations spanning 129 mainnets; because the same token exists on multiple chains, this amounts to 926 distinct tokens). Stablecoins such as JPYC, USDC, and USDT are also supported.

Representative tokens shown from the start on the device’s “Currency / Network” screen: USDC, USDT, DAI, LINK, UNI, AAVE, ARB, JPYC

Built-in tokens (symbols; all 926, in alphabetical order):

0G, 1INCH, 1USDC, 4, A8, AB, ABT, ACE, ACH, ACRED, ACT, ACX, ADCO, ADI, ADS, AERGO, AERO, AEVO, AGENTFUN, AGETH, AGI, AGIX, AGLD, AIAT, AIC, AIDAUSDC, AIO, AIOZ, AITECH, AIX, AIXBT, ALCX, ALEO, ALI, ALICE, ALLO, ALT, AMP, AMPL, ANDY, ANIME, ANKR, ANKRETH, ANON, ANT, ANVL, ANYONE, APEPE, APEX, API3, APR, APU, AQT, ARKM, ASBNB, ASM, ASTER, ASTR, ASUSDF, AT, ATH, ATOM, ATOS, AUCTION, AUDIO, AUKI, AURORA, AUSD, AUX, AVA, AVAIL, AVAX, AVL, AVNT, AVUSD, AWE, AXL, AXS, B, B2, B2M, B3, BABYDOGE, BAL, BANANA, BANANAS31, BAND, BANK, BARD, BAT, BB, BBT, BBTC, BCAP, BDCA, BDX, BEAM, BEAT, BEST, BETA, BFC, BGB, BGSC, BIC, BICO, BIFI, BIGTIME, BIM, BIO, BITCOIN, BLAST, BLESS, BLUR, BMX, BNB, BNBX, BNKR, BNT, BOB, BOBA, BOLD, BONE, BONK, BORA, BORG, BOTX, BOUNTY, BPX, BRBTC, BRETT, BREV, BROCCOLI, BSC-USD, BSU, BTC, BTC.B, BTCLE, BTSE, BTT, BTU, BUIDL, BURN, BUSD, C98, CAKE, CAMP, CAPX, CARV, CAT, CAW, CBAT, CBBTC, CBETH, CBK, CBXRP, CDCBTC, CDCETH, CELO, CELR, CET, CETH, CFG, CGO, CGPT, CHEEMS, CHEX, CHR, CHZ, CJL, CLANKER, CLBTC, CLO, CMETH, COAI, COCA, COCO, COL, COLLECT, COMP, CONSCIOUS, COOKIE, CORE, CORGIAI, CORN, COTI, COW, CPOOL, CRCLON, CRCLX, CRO, CROSS, CRV, CRVUSD, CTC, CTM, CTSI, CUDOS, CULT, CUSD, CUSDO, CVC, CVX, CWBTC, CXO, CYBER, CYS, DAI.E, DBIT, DEGEN, DENT, DEP, DETH, DEV, DEXE, DG, DIA, DIAM, DKA, DLC, DN, DODO, DOGE, DOLA, DOLO, DOOD, DORA, DOT, DOVU, DREAMS, DRV, DSYNC, DUSD, DUSK, DXI, EARNAUSD, EBTC, EDGE, EDU, EEG, EETH, EGL1, EIGEN, EKUBO, EL, ELA, ELEPHANT, ELF, ELG, ELIZAOS, ELON, ENA, ENJ, ENS, EPIC, ERA, ES, ESPORTS, ETH+, ETHFI, ETHIX, ETHX, EUL, EURA, EURC, EURCV, EURE, EURS, EUSD, EUTBL, EVER, EWT, EZETH, F, FAI, FBTC, FCT, FDIT, FDUSD, FELY, FET, FEUSD, FF, FIUSD, FLIP, FLOCK, FLOKI, FLUID, FOLKS, FOOM, FORM, FORTH, FRAX, FRXETH, FRXUSD, FTN, FTRB, FUL, FUN, FWETH, FWSTETH, FXRP, FXSAVE, FXUSD, G, GAIX, GAL, GALA, GAMA, GAME, GCB, GEMS, GEOD, GFI, GHO, GIGGLE, GLIDR, GLM, GME, GMT, GMX, GNO, GNS, GODS, GOMINING, GOOGLON, GPS, GPT, GREEN, GRND, GRT, GT, GTBTC, GTUSDC, GUN, GUSD, GYD, H, HAIR, HANU, HBHYPE, HBUSDT, HEGIC, HEMI, HEZ, HFT, HLDR, HOLO, HOME, HONEY, HOT, HSK, HT, HTX, HUMA, HUNT, HYPER, IBERA, ICE, ICNT, ICP, ID, IDOL, ILV, IMX, IN, INC, INJ, INV, IOST, IOTX, IQ, IR, IRYS, IUSD, IVVON, IXS, IXT, JAAA, JASMY, JCT, JITOSOL, JOE, JRUSDE, JTRSY, JUP, KAITO, KARMA, KAVA, KBTC, KEEP, KERNEL, KGEN, KHYPE, KITE, KMHYPE, KNC, KNTQ, KOGE, KTA, KUJI, LA, LAVA, LBT, LBTC, LCX, LDO, LEO, LGCT, LHYPE, LIBERTY, LIGHT, LINEA, LION, LIQUIDETH, LISA, LISTA, LISUSD, LIT, LIUSD, LMTS, LMWR, LON, LPT, LQTY, LRC, LSETH, LSK, LUCIC, LUMIA, LUNA, LUSD, LYN, M, MAG7.SSI, MAGIC, MANA, MANTA, MANYU, MAPO, MAPOLLO, MASK, MATICX, MAV, MAX, MBG, MBOX, MBTC, MBX, MEDXT, MEME, MERL, META, METAL, METFI, METH, METIS, MF-ONE, MGO, MHYPER, MIM, MIMATIC, MINIDOGE, MIRA, MITO, MLK, MMEV, MMUI, MNEE, MNGO, MNT, MOC, MOCA, MOG, MORPHO, MOVE, MOVR, MPLX, MSETH, MSUSD, MSYRUPUSDP, MTBILL, MUBARAK, MUSD, MVL, MWETH, MWUSDC, MX, MXRP, MYX, NAORIS, NCT, NEAR, NEIRO, NEWT, NEXO, NFT, NIGHT, NIL, NILA, NIZA, NKYC, NMR, NOCK, NOM, NOW, NPC, NUMI, NVDAX, NVM, NXM, NXPC, NYM, OCEAN, OETH, OFT, OGN, OHM, OKB, OL, OLAS, OM, OMI, ONDO, OP, OPEN, ORBS, ORDER, OSAK, OSETH, OSMO, OUSG, OVER, PAAL, PARTI, PAXG, PBTC, PC0000023, PC0000031, PCOCK, PENDLE, PENGU, PEOPLE, PEPE, PGOLD, PHA, PHB, PIEVERSE, PINKSALE, PLAY, PLLD, PLUME, PM, PNKSTR, POKT, POL, POND, PONKE, PORTAL, POWER, POWR, PRDT, PRIME, PRO, PROM, PROVE, PSP, PTGC, PUFF, PUFFER, PUMPBTC, PUNDIX, PUPPIES, PURR, PUSD, PXETH, PYTH, PYUSD, PZETH, Q, QAI, QANX, QI, QKC, QNT, QQQON, QUIL, QUSDT, RAD, RAIL, RAIN, RARE, RAVE, RBTC, REACT, REAL, RECALL, RED, REI, REKT, RENDER, REQ, RESOLV, RETH, REUSD, REZ, RIF, RIO, RIVER, RLB, RLC, RLP, RLS, RLUSD, ROAM, ROCK.RETH, RON, ROSE, RPL, RSC, RSERG, RSETH, RSR, RSTETH, RSWETH, SAFE, SAHARA, SAI, SAND, SANTOS, SAPIEN, SATUSD, SAUCE, SAVAX, SAVUSD, SB, SCRVUSD, SD, SDAI, SDEX, SDL, SDOLA, SDT, SEDA, SENA, SETH, SFI, SFLR, SFP, SFRXETH, SFRXUSD, SHARP, SHFL, SHIB, SHX, SIGN, SIREN, SKL, SKY, SKYAI, SLP, SLVON, SNT, SNX, SOL, SOLO, SOLV, SOLVBTC, SOLVBTC.JUP, SOON, SOPH, SOSO, SPELL, SPK, SPKCC, SPX, SPYON, SQD, SRUSDE, SRX, SSV, ST0G, STABLE, STAVAX, STBL, STBTC, STCUSD, STEAKETH, STEAKUSDC, STETH, STG, STHYPE, STKAAVE, STO, STORJ, STRK, STRX, STUSDT, STXRP, SUPER, SUPEROETH, SURGE, SUSD, SUSD1+, SUSDA, SUSDAI, SUSDE, SUSDS, SUSHI, SUSN, SVL, SWETH, SWFTC, SX, SXP, SXT, SYND, SYRUP, SYRUPUSDC, SYRUPUSDT, SYZUSD, T, TAG, TAIKO, TBTC, TEL, TEMPLE, TETH, THALES, THBILL, THE, TIBBIR, TIG, TKX, TLTON, TOKEN, TON, TORN, TOSHI, TPT, TRAC, TRADOOR, TRB, TREE, TRIBE, TRUST, TSLAON, TSLAX, TST, TT, TURBO, TUSD, TWT, UAI, UB, UBTC, UDS, UFART, ULT, ULTIMA, UMA, UNIBTC, UNIETH, UNP, UPUMP, UQC, USD+, USD0, USD1, USDA, USDAI, USDB, USDC.E, USDC.N, USDD, USDE, USDF, USDG, USDH, USDKG, USDM, USDO, USDON, USDP, USDR, USDS, USDT0, USDTB, USDTE, USDX, USDY, USDZ, USELESS, USN, USOL, USR, USTB, USTBL, USUAL, USUALUSDC+, USUALX, USYC, UTY, UXPL, VANA, VANRY, VBETH, VBILL, VBUSDC, VBUSDT, VBWBTC, VCNT, VEE, VELO, VELVET, VHYPE, VIRTUAL, VKHYPE, VR, VSN, VSTR, VVS, VVV, VYUSD, W, WAETHUSDC, WAETHUSDT, WAETHWETH, WAPE, WAVAX, WAVES, WAXP, WBCH, WBETH, WBNB, WBT, WBTC, WBTC.E, WCORE, WCRO, WEETH, WEETHS, WELL, WETH, WFI, WFLR, WFRAX, WGLUE, WHITE, WHYPE, WIF, WILD, WKC, WLD, WLFI, WM, WMON, WMTX, WNXM, WOD, WOO, WPLS, WPOL, WRX, WSEI, WSGB, WSRUSD, WSTETH, WSTUSR, WTAO, WUSD, WVIC, WXPL, WXRP, WZEDX, XAI, XAN, XAUM, XAUT, XAUT0, XCM, XCN, XMW, XPIN, XPL, XPR, XSOLVBTC, XT, XUSD, XVS, XYO, YB, YEE, YFI, YGG, YNETHX, YOETH, YOUSD, YUSD, YZUSD, ZBT, ZCHF, ZEC, ZEDXION, ZEN, ZENT, ZETA, ZEUS, ZIG, ZIL, ZK, ZKC, ZKJ, ZKP, ZORA, ZRO, ZRX, 哈基米, 币安人生

Even for ERC-20 tokens not on the built-in list, signing is possible (in that case, instead of a name, the device shows “ERC-20 Token / Unknown Token” and prompts you to check the contract address). The bundled list is scheduled to be expanded via firmware updates.

Q5-2 Which networks (chains) does Openloop support? How many? Please be specific.

In addition to the five families — Bitcoin, Ethereum, XRP Ledger, Solana, and TRON — it provides broad support for EVM networks. A total of approximately 225 networks are built in (215 EVM networks = 129 mainnets + 86 testnets, plus Bitcoin ×2, Solana ×3, TRON ×3, and XRP Ledger ×2). Furthermore, signing is possible on any EVM network; unregistered chains are shown as “Chain ID: XXXXX.”

EVM mainnets (all 129):

Ethereum Mainnet, Optimism, Flare Network, Songbird, Elastos, KardiaChain, Cronos, Rootstock RSK, Telos, XDC Network, BNB Smart Chain, Syscoin NEVM, OKT Chain, Meter, Viction, Gnosis Chain, Velas, Fuse, Huobi ECO Chain, Unichain, Polygon, Monad, Sonic, Manta Pacific, HashKey Chain, Mint, X Layer, BitTorrent, opBNB, Lens, TAC, Fantom, Fraxtal, Kroma, Boba Network, Hedera, zkSync Era, PulseChain, Cronos zkEVM, SX Network, World Chain, Astar, Flow EVM, QL1, Bittensor EVM, Stable, HyperEVM, Conflux eSpace, Metis Andromeda, Polygon zkEVM, WEMIX, Core, Lisk, Moonbeam, Moonriver, Glue, Sei, Story, Gravity, Soneium, LightLink, Swellchain, Milkomeda C1, Ronin, Vanar, Kava, Goat, Abstract, Morph, Peaq, Botanix, SX Rollup, Merlin Chain, IoTeX, Mantle, Somnia, Superseed, Saga, DuckChain, Nibiru, ZetaChain, Cyber, Canto, Kaia, Base, IOTA EVM, Evmos, Plasma, SmartBCH, BEVM, Immutable zkEVM, 0G, Map Protocol, Oasis Sapphire, Mezo, ApeChain, Mode, Energi, EDU Chain, Arbitrum One, Arbitrum Nova, Celo, Etherlink, Hemi, Avalanche C-Chain, Zircuit, Sophon, Superposition, Ink, Linea, Henesys, Berachain, Blast, Zedxion, Plume, Taiko, Bitlayer, Scroll, Katana, XRPL EVM, Zora, Corn, Neon EVM, Degen, Ancient8, Aurora, Rari Chain, Harmony, SKALE Europa

EVM testnets (all 86):

Ethereum Sepolia, Ethereum Holesky, Optimism Sepolia, Arbitrum Sepolia, Base Sepolia, Polygon Amoy, zkSync Sepolia, Linea Sepolia, Scroll Sepolia, Polygon zkEVM Cardona, BNB Testnet, Avalanche Fuji, Fantom Testnet, Cronos Testnet, Flare Coston2, Songbird Coston, Rootstock Testnet, Telos Testnet, XDC Apothem, OKT Chain Testnet, Meter Testnet, Viction Testnet, Gnosis Chiado, Fuse Sparknet, Huobi ECO Testnet, opBNB Testnet, Fraxtal Testnet, Kroma Sepolia, Boba Sepolia, Hedera Testnet, PulseChain Testnet, Cronos zkEVM Testnet, Conflux eSpace Testnet, Metis Sepolia, WEMIX Testnet, Core Testnet, Lisk Sepolia, Moonbase Alpha, Soneium Minato, LightLink Pegasus, Ronin Saigon, Kava Testnet, Abstract Testnet, Morph Holesky, Merlin Testnet, IoTeX Testnet, Mantle Sepolia, ZetaChain Athens, Canto Testnet, Kaia Kairos, IOTA EVM Testnet, Evmos Testnet, SmartBCH Testnet, BEVM Testnet, Immutable zkEVM Testnet, Oasis Sapphire Testnet, ApeChain Curtis, Mode Sepolia, Energi Testnet, Celo Alfajores, Zircuit Testnet, Berachain Bartio, Blast Sepolia, Taiko Hekla, Bitlayer Testnet, Zora Sepolia, Neon EVM Devnet, Aurora Testnet, Harmony Testnet, Flow EVM Testnet, X Layer Testnet, BitTorrent Donau, Sonic Blaze, Lens Sepolia, World Chain Sepolia, Story Aeneid, Gravity Sepolia, Unichain Sepolia, Manta Pacific Sepolia, Mint Sepolia, HashKey Testnet, Etherlink Testnet, Hemi Sepolia, Ink Sepolia, Plume Testnet, XRPL EVM Devnet

Non-EVM networks: - Bitcoin (Mainnet / Testnet) - Solana (Mainnet / Devnet / Testnet) - TRON (Mainnet / Shasta / Nile) - XRP Ledger (Mainnet / Testnet)

Furthermore, you can sign on EVM networks that are not on the built-in list, too (in that case, instead of a network name, the device shows “Chain ID: XXXXX”). The bundled list is scheduled to be expanded via firmware updates.

Q5-3 Can I use stablecoins?

Yes. It supports major stablecoins including JPYC, USDC, and USDT. As stablecoins become social infrastructure for payments and business-to-business transactions, we place great importance on Openloop’s role as the device that provides the “final approval.”

Q5-4 Do you plan to support other currencies or networks?

Openloop is designed to keep evolving through firmware updates. However, when and what features (including supported currencies and networks) will be added is undecided. We cannot promise specific timing or content at this point, but we will consider your requests as we plan ahead.

Q5-5 Can I sign for currencies or networks not on the compatibility list? What does the screen show?

For EVM-family chains, you can sign even for networks or tokens that are not on the list (unregistered). - Unregistered EVM networks: You can sign. Instead of a network name, the device shows “Chain ID: XXXXX.” - Unregistered ERC-20 tokens: You can sign. Instead of a token name, the device shows “ERC-20 Token / Unknown Token” and prompts you to “check the contract.”

Note: Chains from an entirely different family than BTC, XRP, SOL, or TRON (for example, Cardano) are not supported. When we say “supports everything,” we mean EVM networks and ERC-20 tokens.

Q5-6 How do I add an unregistered EVM network or ERC-20 token?

No action is needed. Even when unregistered, they are identified by Chain ID or contract address and can be signed for as-is. There is no feature to manually register networks or tokens on the device. If you want the network name or token name to appear on the screen, we expand the built-in registry via firmware updates (currently 215 EVM networks / approximately 2,600 ERC-20 tokens are shown by name).

Q5-7 What types of signatures are supported?

The following are supported.

Signature type Supported currencies Purpose / format
Transaction signing BTC / ETH / XRP / SOL / TRX Signing transfers and operations. ETH supports both Legacy and EIP-1559 (Type 2). XRP supports both the secp256k1 and Ed25519 curves
Message signing ETH / BTC / SOL / TRX Login, proof of ownership, and so on. The format differs by chain (ETH: personal_sign (EIP-191) / BTC: BIP-137 / SOL: off-chain message / TRON: TIP-191). Note: XRP does not support message signing (transaction signing only)
Typed data signing (EIP-712) ETH Safe multisig, dApp approvals, and so on
PSBT signing (BIP-174) BTC Integration with Sparrow and others, multisig signing
Authorization signing (EIP-7702) ETH Smart account delegation and un-delegation
Batch signing (signAllTransactions) SOL Batch signing of multiple transactions

Note: Openloop is a device that performs the signing step. Broadcasting a signed transaction to the blockchain is handled by the wallet app you connect to.

Note: The above are crypto wallet signatures. Openloop also performs FIDO2 / passkey authentication signatures (ES256 / EdDSA — see “7. Security Key Features”) and PIV / PKCS#11 digital signatures (ECDSA P-256 / EdDSA / RSA-2048; SSH, PDF, GPG, and so on — see “8. PIV / PKCS#11 Features”).

Q5-8 Which Bitcoin script types are supported?

For single-signature (ordinary receiving addresses), the following three types are supported.

Type Script Address format
Native SegWit P2WPKH bc1q…
Legacy P2PKH 1…
Nested SegWit P2SH-P2WPKH 3…

It complies with standards such as BIP39 / 32 / 44 / 84 / 143 / 174.

Taproot (P2TR, addresses beginning with bc1p…) is not supported. You cannot receive or sign in the Taproot format, so please use one of the three address types above.

Q5-9 Does it support both of XRP's two curves (signature schemes)?

Both are supported. It supports both ECDSA secp256k1 and EdDSA Ed25519, which XRP Ledger supports, and it detects the scheme automatically from the address. You can also specify it explicitly with a Custom Path.

Q5-10 Does it support multisig?

Yes. For Bitcoin, it supports multisig in all formats — Native (P2WSH), Legacy (P2SH), and Nested (P2SH-P2WSH) — signed via PSBT with Sparrow Wallet and similar tools. For Ethereum, it supports Safe (Gnosis Safe) multisig via EIP-712 typed data signing.

Q5-11 Does it support MPC (multi-party computation)?

No — Openloop does not support MPC (Multi-Party Computation). MPC splits a private key into multiple “shares” kept in separate places and signs jointly without ever reassembling the key. Openloop takes a different approach: the private key is never split — it is generated, stored, and used for signing entirely inside the device, and it never leaves the device (an on-device, self-custody model). To distribute signing authority across several people or locations, use multisig (see Q5-10) rather than MPC: Openloop acts as one of the independent signers, keeping its private key inside the device.

Q5-12 Does it support ERC-20, ERC-721, and ERC-1155 (NFTs)? Can I use NFTs?

Yes, you can sign for all of these token operations. On the signature confirmation screen, it identifies and displays the operation.

Standard Description Example screen display
ERC-20 Token transfer / approval “ERC-20 Transfer” + amount, “Approve”
ERC-721 (NFT) NFT transfer / approval “NFT Transfer” + token ID
ERC-1155 Multi-token transfer “Multi Transfer”

For NFTs (ERC-721 / ERC-1155), as shown above, you can sign transfer and approval transactions, and the screen shows “NFT Transfer” or the token ID. However, it does not support displaying NFT images or metadata (clear signing). You review and sign a transfer or approval transaction by checking details such as the contract and token ID.

Q5-13 Does it support smart accounts (EIP-7702)?

Yes, it supports EIP-7702 (delegating code to an EOA, i.e., turning an account into a smart account). It can perform Authorization signing that specifies the delegate address, chain_id, and nonce, and it displays by name the major delegate contracts such as MetaMask, Coinbase, Uniswap, and OKX. For unregistered delegates it displays a warning, and it also warns about delegations that take effect on all chains (chain_id=0). Un-delegation (Revoke) is also supported.

Note: Because EIP-7702 (smart account delegation) is a new mechanism, it is currently intended for use with dApps and tools that support Openloop (it is not automatically available on every general-purpose dApp).

Q5-14 Can I use testnets?

Yes. It supports Bitcoin (Testnet), Solana (Devnet / Testnet), TRON (Shasta / Nile), XRP (Testnet), and various EVM testnets (86 networks).

Q5-15 Can I manage multiple accounts (addresses)?

Yes. It supports the BIP32 / BIP44 hierarchical structure and can derive multiple accounts and addresses per currency. Using the “Custom Path” feature on the Receive screen, you can also specify any derivation path you like.

Q5-16 How do I display a receiving address?

From the device’s menu, choose “Receive” and select a currency (Bitcoin, Ethereum, and so on), and that currency’s receiving address is shown on the device’s screen.

  • QR code display: With “Show QR,” you can display the address as a QR code. Scan it with a wallet on your smartphone or PC and use it directly as the transfer destination.
  • Specifying the derivation path (Custom Path): With the “Custom Path” feature, you can specify any BIP32 / BIP44 derivation path and display the corresponding address. Use this when you want to use multiple accounts or addresses within the same currency, or when you want to check the address of a specific path.

Always verify the receiving address visually on the Openloop device’s own screen. Even if the address displayed on your PC or smartphone has been altered by malware, the address shown on the device’s screen is the correct one.

Q5-17 Since Openloop is a new wallet, aren't there too few supported apps (companion wallets), making it not very useful until it becomes popular?

Not at all. Openloop includes a “compatibility mode,” so it works with many existing apps from day one.

  • When used over USB or BLE, it operates as Ledger-compatible. This means it works as-is with many wallet apps that support Ledger (MetaMask, Rabby, Safe, Solflare, and so on).
  • When used with Air Gap (QR codes), it uses the same format as Keystone (BBQr / UR-family animated QR). This means it also works with many Air Gap wallets that support Keystone.
  • In addition, it has official WalletConnect support (it is registered in WalletConnect’s official Wallet Guide). This lets you connect to many dApps that support WalletConnect through the companion app “Openloop Connect.”

In other words, Openloop is designed so that, without waiting for its own app to become popular, it can plug straight into the huge existing ecosystems (Ledger-compatible, Keystone-compatible, and WalletConnect).

Q5-18 Which wallet apps (companion wallets) can it work with?

It can work with the following apps by currency (implementing the Ledger-compatible protocol).

Currency Supported companion wallets Connection method
BTC Sparrow Wallet USB / Air Gap (QR)
ETH / EVM MetaMask, Rabby Wallet, Trust Wallet USB / BLE / Air Gap (QR)
ETH / EVM Safe USB / Air Gap (QR)
XRP XRP Toolkit USB / Air Gap (QR)
SOL Solflare USB / BLE / Air Gap (QR)
TRX TronScan USB / BLE

Note: Because Air Gap (QR code) uses a Keystone-compatible format, it works with wallets that support Keystone (Sparrow, MetaMask, Rabby, Safe, XRP Toolkit, Solflare, Trust Wallet, and so on). Note: TRON does not support Air Gap (QR) and is used over USB / BLE. Note: Ledger Live is not supported (because of its device authentication check).

Q5-19 Can you give an example of how to connect (the connection steps) with a companion wallet?

Here are examples of typical connection steps (for details, refer to each app’s manual and to the user manual).

  • MetaMask (Ethereum, USB / BLE / Air Gap): In MetaMask, go to “Account” → “Connect hardware wallet” → choose Openloop from the list, and pair over USB or BLE. Air Gap connection via QR (Keystone-compatible) is also possible.
  • Sparrow Wallet (Bitcoin, USB / Air Gap): In Sparrow, choose “Connect Hardware Wallet” → connect over USB, or with Air Gap read/display Openloop’s QR to sign.
  • Solflare (Solana, USB / BLE / Air Gap): In Solflare, choose “Hardware wallet” → connect Openloop as Ledger-compatible (Air Gap connection via QR is also supported).
  • Safe (Ethereum multisig, USB / Air Gap): Connect Openloop to Safe as a signer (Ledger-compatible, or via QR Air Gap) and approve with EIP-712.

In every case, the final approval of the signature is done by reviewing the details on the Openloop device’s own screen and pressing the button.

Differences in operation by connection method: - When linking via Air Gap (QR), you use “Wallet Linkage” in the device’s wallet menu. On this screen, you display a QR (account information) for the partner app to read, and subsequent signing is exchanged via QR as well. - When linking via USB / BLE, you don’t need to use the “Wallet Linkage” screen. Simply connect the cable or pair over BLE, and you can link with just the app’s “Connect hardware wallet” action.

Q5-20 Can I migrate (switch over) from Ledger?

Because the recovery phrase (BIP39) is compatible, you can migrate your wallet (your assets). Enter the phrase you used on Ledger into Openloop and you can access the same assets; conversely, you can restore an Openloop phrase on Ledger or similar devices. However, Openloop does not behave exactly like Ledger (its supported apps, features, and operation are unique to Openloop). Please think of “migration” here as meaning “you can manage the same assets on Openloop.”

Q5-21 Can I use it with Ledger Live?

No. Ledger Live performs a genuine-device authentication check, so it does not work with Openloop. For Ethereum, use MetaMask, Rabby, or Safe; for Bitcoin, use Sparrow Wallet; and so on — please use the companion wallets described in this document. Note that because the recovery phrase is Ledger-compatible, mutual restoration of assets is possible.

Q5-22 Does it support WalletConnect?

Yes, it supports WalletConnect v2. Through the companion app “Openloop Connect,” you can connect to 600+ dApps. The supported chains are the four families — Ethereum / EVM, Bitcoin, Solana, and TRON — and transaction signing, message signing, and batch signing are all possible.

Q5-23 What do I need to connect via WalletConnect?

You need the Openloop device and the companion app “Openloop Connect” (on a PC or smartphone). Connect the device and the app over USB or BLE, then read the WalletConnect QR code shown by the dApp with the app to connect.

Q5-24 Can I use dApps (decentralized apps) safely?

Yes. For operations coming from a dApp, too, you review the signature details on the Openloop device’s own screen before approving. Your private keys are protected inside the device and never leave it, so you’re protected from harm by phishing sites and malware.


6Connection Methods (USB / BLE / Air Gap)

Q6-1 Which connection methods (transports) are supported?

All three connection methods are supported.

Connection method Characteristics
USB (Type-C) Fast and stable. Ideal for direct connection to a PC
BLE (Bluetooth 5.0) Wireless. Convenient for connecting to a smartphone
Air Gap (QR code) Fully offline signing. The highest level of isolation
Q6-2 Can I turn USB / BLE / Air Gap off individually?
  • USB and BLE can be turned on and off individually from the settings screen.
  • Air Gap (QR) reads data with the camera without using any wireless, so there is no concept of disabling it — it is always available.

By enabling only the connection methods you need, you can shrink the attack surface even further.

Q6-3 What communication method does USB use?

USB HID (Human Interface Device). No dedicated driver installation is required, and it is recognized directly by supported apps and browsers (such as WebHID).

Q6-4 When using BLE, how many hosts can it pair with?

It pairs (bonds) with one host. To re-pair with a different host, first remove the existing pairing, then pair again.

Q6-5 How do I pair over BLE?

It uses secure pairing via Secure Connections (LE SC): you confirm and approve the 6-digit code (Numeric Comparison) shown on the device’s screen. Communication is encrypted with AES-CCM (128-bit).

Q6-6 Does BLE disconnect automatically if unused for a while?

Yes. After 60 seconds of no communication, it disconnects automatically. This is a specification for power saving and security.

Q6-7 What is Air Gap?

Air Gap is a method of exchanging signing data using QR codes only, without using any physical or wireless connection such as USB or Bluetooth. Because it is completely cut off from any network, it achieves the highest level of isolation. Openloop reads a signing request QR with its camera and, after signing, displays the signed data as a QR.

Q6-8 What is the format of the QR (animated QR) used for Air Gap?

It supports multiple standard formats. The output format can be switched in the settings.

Format Description Recommended use
BBQr ZLIB compression, multi-frame Sparrow Wallet (recommended)
UR (Fountain codes) Blockchain Commons standard UR-compatible apps

On the input side, it accepts BBQr and UR-encoded signing requests (PSBT / ETH / SOL / XRP) (Base64 is not supported).

Q6-9 Which apps can it work with? (By connection method)
  • USB: Sparrow, MetaMask (PC), Safe, Rabby, XRP Toolkit, Solflare, TronScan, and more
  • BLE: MetaMask Mobile, Rabby (mobile), Solflare, and more
  • Air Gap (QR): Sparrow (Bitcoin), MetaMask, Rabby, Safe, XRP Toolkit, Solflare, Trust Wallet, and more (because it uses the Keystone-compatible format, it works with Keystone-compatible wallets)

7Security Key Features (FIDO2 Passkeys)

Q7-1 What is the passkey feature?

The passkey feature lets you use Openloop as a FIDO2 / CTAP2-compliant security key. You can sign in to Google, Microsoft, and various web services without a password, with phishing resistance. A single device provides both crypto asset storage and protection for your everyday web logins.

Q7-2 Which specifications does it comply with?

It complies with CTAP2 (advertising FIDO_2_0 / FIDO_2_1) and also provides backward compatibility with U2F (FIDO U2F V2, CTAP1). The signature algorithms supported are ES256 (P-256) and EdDSA (Ed25519).

Q7-3 Is it FIDO Certified?

At this time, it has not obtained official certification from the FIDO Alliance (FIDO2 Certified). It is a CTAP2 / WebAuthn implementation that follows the specifications, but official certification and AAGUID registration are still at the stage of being considered for the future.

Q7-4 How many passkeys can it store?

It can store up to 100 passkeys (Discoverable Credentials) on the device. List display (with virtual scrolling), individual deletion, and a full reset are all possible.

Q7-5 Does it support both Resident and Non-resident (server-side) keys?

Both are supported. - Resident keys (Discoverable Credentials): Stored on the device (up to 100) and let you log in without entering a username. - Non-resident keys: Not stored on the device; they are derived on demand at signing time from information held by the web service (the RP). They are not subject to the storage-count limit.

Q7-6 Can I erase stored passkeys?

Yes. You can delete them individually from the settings screen, and a full reset is also possible. The RP name and username appear in the list, so you can select and delete the ones you want.

Q7-7 Can I reset just the passkey feature?

Yes. Using “Reset Passkeys” in the settings screen, you can delete only the stored passkeys. This does not affect your wallet (crypto assets) or PIV. Individual deletion and delete-all (“Delete All”) are both supported.

Q7-8 If I delete or reset my wallet, what happens to my passkeys?

Performing “Reset to factory state” erases everything, including passkeys and PIV. On the other hand, “Delete Wallet” is a feature that targets the wallet (crypto assets); passkeys and PIV are each managed and reset independently. If you want to erase only passkeys, use “Reset Passkeys.”

Q7-9 What happens if I exceed 100?

Once you reach the storage limit (100), registering a new passkey returns an error. Delete unneeded passkeys to make room, and you can register again.

Q7-10 Besides USB, can I use passkeys over BLE too?

Yes. You can use passkeys over both USB (CTAPHID) and BLE. When using BLE, it goes through the Openloop Connect app.

Q7-11 What do I need to use passkeys over BLE?

You need to install the Openloop Connect mobile app and to pair with and select the Openloop device over BLE. On the OS side, you enable Openloop Connect as a credential provider. - iOS: “Settings” → “General” → “AutoFill & Passwords,” and turn “Openloop Connect” ON - Android: “Settings” → “Passwords & accounts” → “Additional services,” and turn “Openloop Connect” ON

“Openloop Connect” then appears on the OS login screen, and the actual communication takes place over BLE (via the credential provider = Openloop Connect) (iOS 17 or later / Android 14 or later).

Q7-12 When using passkeys over BLE, how do I switch which Openloop device is used?

Within the Openloop Connect app, select and switch which device to use from among your paired devices. On mobile, tap the “Change” link on the main screen to open the device selection modal, where you can pick from your registered devices with a radio button (you can also switch from the “Switch device” button on each device’s detail screen). On desktop, you switch simply by connecting the device you want to use over USB.

Q7-13 Can I register the same web service with both USB and BLE?

For most services, a single registration lets you use the same passkey over both USB and BLE (confirmed with Monex, JAL, Microsoft, SBI VC Trade, and others). However, some services (a notable example being Google) strictly distinguish by transport, so a passkey registered over USB is not visible from the BLE path (and vice versa); to use both, you need to register twice — once over USB and once over BLE (in that case, Openloop issues a separate credential ID per transport, and the server registers them as two independent passkeys). Also, on Apple’s own sites (Apple ID, iCloud, and so on), you cannot use third-party passkey providers, so it cannot be used there. For details, see the “Security Key Guide.”

Q7-14 How is it different from other security keys (such as YubiKey)?

Keys like YubiKey are for authentication only, whereas Openloop, in addition to its security key features, packs in a full-fledged crypto wallet. Also, because it has a display and touch operation, you can review and approve the RP name and username on the screen during registration and authentication — another difference.

Q7-15 Which browsers and platforms can I use it on?
  • USB connection: Windows (Chrome / Edge / Firefox), macOS (Chrome and others). It works via the OS’s standard FIDO authentication stack.
  • BLE connection: iOS 17 or later (Safari, via credential provider), Android 14 or later (Chrome / Edge, via credential provider).

8PIV / PKCS#11 Features

Q8-1 What is the PIV feature?

The PIV feature lets you use Openloop like a PIV (Personal Identity Verification)-compliant smart card. Via the PKCS#11 library, you can use it for SSH authentication, digital signing of PDFs, GPG signing, TLS client certificate authentication, and more.

Q8-2 Which specifications does it comply with?

It complies with PIV (a NIST SP 800-73-compatible subset). Communication is over USB HID (with APDU framing).

Q8-3 How many slots are there?

There are 4 slots.

Slot Purpose
9A Authentication
9C Digital Signature
9D Key Management
9E Card Authentication
Q8-4 Which cryptographic algorithms are supported?

ECDSA P-256, Ed25519, and RSA-2048 are supported.

Q8-5 What certificate formats can be stored?

Standard X.509 certificates (DER format) can be stored in each slot (up to 2048 bytes per slot).

Q8-6 If I delete or reset my wallet, what happens to the slot contents?

Performing “Reset to factory state” erases the PIV slots (keys and certificates), the PIV PIN, and passkeys — all of it. If you want to erase only PIV, use “Reset PIV.”

Q8-7 How do I erase the contents (keys and certificates) of the PIV slots?
  • To erase all at once: Use “Reset PIV” in the settings screen to delete the keys and certificates in all 4 slots along with the PIV PIN (“Reset to factory state” also erases everything).
  • To erase or replace individual slots: Use a PKCS#11 tool (such as pkcs11-tool) to generate, import, or delete keys and certificates from the host (PC) side.
Q8-8 Can I reset just the PIV feature?

Yes. Using “Reset PIV” in the settings screen, you can delete all PIV keys, certificates, and PINs. This does not affect your wallet (crypto assets) or passkeys.

Q8-9 When PIV signing, is on-screen approval always required?

It depends on the connection method and how the PIN is sent. For interactive use, on-screen approval on the device is required, but for automation use cases you can also choose “silent signing,” which skips the on-screen confirmation (see below).

Q8-10 What is the "USB PIN"?

It is the PIN for PIV (6 to 8 ASCII digits). If you authenticate this PIN in advance over USB, subsequent signing can be executed without on-screen confirmation (= silent signing). The PIN is hashed with SHA-256 for storage and is not kept in plaintext.

Q8-11 When registering, changing, or deleting the USB PIN, is on-screen confirmation on the device required?

Yes. When a request to set, change, or delete the PIN is sent over USB, a confirmation dialog (for example, “Allow the request to set the PIV PIN?”) appears on the device’s screen, and nothing is executed unless the user approves it. By design, managing the PIN itself always requires approval on the device in your hands.

Q8-12 What is "silent signing"?

Silent signing is the behavior of signing without showing an approval dialog on the device’s screen. It is a feature for use cases such as CI/CD and server automation, where a person cannot approve each operation individually.

Q8-13 When is silent signing on or off?
Condition Signing behavior Main use
PIN authenticated over USB Silent signing (no on-screen confirmation) Automation / CI/CD
PIN not sent On-screen confirmation (approve on the device) Interactive use

In other words, when you have sent and authenticated the PIN over USB, signing is silent; when you have not sent the PIN, approval on the device’s screen is required.

Q8-14 What are some examples of applications that can do PKCS#11 signing with Openloop?

You can use it with PKCS#11-compatible applications such as the following.

  • SSH authentication (specifying the key with ssh -I)
  • GPG signing (via gnupg-pkcs11-scd)
  • Digital signing of PDFs (Adobe Acrobat, pyHanko, and so on)
  • Firefox client certificate authentication
  • pkcs11-tool and other general-purpose tools

The PKCS#11 library is available for macOS / Windows / Linux (.dylib / .dll / .so).

Q8-15 Can the PIV feature be used on mobile (smartphones)?

No. PIV / PKCS#11 is for USB connection (PC) only, supporting macOS, Windows, and Linux. Openloop Connect’s PIV relay feature is also desktop only. It cannot be used on mobile.


9Openloop Connect (Companion App)

Q9-1 What is Openloop Connect?

Openloop Connect is the official companion app used together with the Openloop device. It handles the “bridge to PCs, smartphones, and the web” that the device cannot do on its own — firmware updates, dApp connections via WalletConnect, providing BLE passkeys, relaying PKCS#11 / the SDK, and more.

Q9-2 Which platforms does it run on?
  • Mobile: iOS / Android (app)
  • Desktop: macOS / Windows / Linux
Q9-3 What features does Openloop Connect have?

The main features are as follows.

Feature Description
Firmware update (OTA) Securely update the device’s firmware over USB / BLE
WalletConnect relay Relay that connects a dApp and the device
Credential provider Provide passkeys to the OS over BLE (mobile)
WebSocket relay (LocalWS) Connect a browser web app and the device (SDK integration; Desktop / Android)
Safari Web Extension Connect to the device over BLE from iOS Safari (iOS only)
PIV relay Connect a PC app and the device’s PIV / PKCS#11
BLE pairing management Connect to and select the device
Q9-4 What is the WalletConnect relay feature?

It is a feature that receives WalletConnect requests issued by a dApp and relays operations that require a signature to the Openloop device. When you review and approve the details on the device, the signature result is returned to the dApp.

Q9-5 What is WalletConnect?

WalletConnect is an industry-standard connection protocol for securely linking a wallet and a dApp (decentralized app). You connect via a QR code or link shown on the dApp side, and approve the signature in your wallet. Openloop supports WalletConnect v2 through Openloop Connect.

Q9-6 What is the credential provider feature?

It is a feature that registers Openloop with your smartphone’s OS as a passkey provider (credential provider). This lets you use Openloop’s passkeys over BLE right from the login screen of a web service.

Q9-7 What is the WebSocket relay (LocalWS) feature?

On a PC or Android, it is a feature that connects a browser web app (an app that uses the Openloop Web SDK) and the device through a local WebSocket. This lets a web app send signing requests to the device.

Q9-8 What is the Safari Web Extension feature?

It is a Safari extension included in the iOS version of Openloop Connect. It lets you communicate directly with the Openloop device over BLE from Safari on your iPhone. Because on iOS every browser is WebKit-based and local WebSocket cannot be used, this is an iOS-only connection method that works around that limitation. Openloop Connect acts as the extension’s “container app,” and once you enable the extension, you can use Openloop from Safari even without launching the Connect app.

Q9-9 How do I get the Safari Web Extension working?

For iOS privacy protection, two steps of configuration are required (step 1 alone does not work). 1. Enable the extension: Go to “Settings” → “Safari” → “Extensions” → choose “Openloop Connect,” turn “Allow Extension” ON, and set “All Websites” to “Allow.” 2. Allow it per site: Open the dApp in Safari, tap the “アあ” (page settings) icon on the left of the address bar → “Manage Website Settings” → “Openloop Connect” → choose “Always Allow,” and reload the page.

Note: Per-site permission may be required for each dApp you use.

Q9-10 What is the PIV relay feature?

It is a feature that relays so that applications on your PC (SSH, PDF signing tools, and so on) can use Openloop’s PIV feature via the PKCS#11 library.

Q9-11 With the WalletConnect relay, which dApps can I use?

You can use 600+ dApps that support WalletConnect v2. The supported chains are the four families — Ethereum / EVM, Bitcoin, Solana, and TRON.

Q9-12 With the WalletConnect relay, what if I don't want to relay to Openloop?

If the device is not connected, no relaying occurs. Also, even if a request comes in, if you choose “Reject” on the Openloop Connect screen, no signature is executed (and nothing is executed unless you approve on the device side as well).

Q9-13 What if I don't want to use the WebSocket relay or the PIV relay?

These relay features run as a local server inside Openloop Connect (desktop). If you don’t use them, you can turn them off with the “Local WebSocket Server” and “PKCS#11 Cryptographic Module” switches in the app’s settings.

Q9-14 How do I get the credential provider feature working?
  1. Install the Openloop Connect mobile app.
  2. Pair with the Openloop device over BLE.
  3. In the OS settings, enable Openloop Connect as a credential provider.
    • iOS: “Settings” → “General” → “AutoFill & Passwords” → turn “Openloop Connect” ON
    • Android: “Settings” → “Passwords & accounts” → “Additional services” → turn “Openloop Connect” ON
Q9-15 When using the PIV relay, where is the PKCS#11 library (dynamic library) that I configure on the app side?

Specify Openloop’s PKCS#11 module libopenloop-pkcs11 (macOS: .dylib / Windows: .dll / Linux: .so) in the target app’s PKCS#11 settings. The library is bundled with Openloop Connect (desktop). The default paths are as follows.

  • macOS: /Applications/Openloop Connect.app/Contents/Resources/pkcs11/libopenloop-pkcs11.dylib
  • Windows: <install location>\resources\pkcs11\libopenloop-pkcs11.dll
  • Linux: <install location>/resources/pkcs11/libopenloop-pkcs11.so

For details, see the “Security Key Guide.”


10Purchasing, Support, and Warranty

Q10-1 Where can I buy it?

The manufacturer’s suggested retail price is 49,800 yen (excluding tax). It is sold at our official online store, openloop.official.ec.

(Early sales on CAMPFIRE ended in June 2026, and sales have now moved to the official online store.)

Q10-2 Can businesses buy in bulk?

Yes, we welcome inquiries from businesses. After hearing your desired quantity and intended use, our team will get in touch.

Q10-3 What is the warranty period and coverage?

The warranty period is 6 months from purchase. The warranty covers only natural failures under normal use (initial defects and manufacturing flaws). Drops, water damage, modification, disassembly, misuse, use of unofficial firmware, and battery aging (a consumable), among others, are not covered.

Q10-4 How do I get it repaired if it breaks?

Please contact us (Haudi Crypto, Inc.) (support@crypto.haudi.jp). Note: Because your assets can be restored from your recovery phrase, even if the device fails, your assets are not lost as long as you have the phrase.

Q10-5 If I suffer a loss while using it (e.g., losing crypto assets), will I be compensated?

We do not provide compensation for losses of crypto assets. Openloop is a self-custody product in which you manage your own private keys, and we never take custody of your assets. Under the End User License Agreement (EULA), we are not liable for the loss, theft, or misdirected transfer of crypto assets, or any other damages, arising from the use of or defects in this product, except in cases of willful misconduct or gross negligence (the total amount of damages is capped at the purchase price). - Managing your recovery phrase is your responsibility (losses due to loss or leakage are not covered). - Damages due to errors in the destination address, defects in smart contracts, defects in dApps or third-party services, price fluctuations, and the like are also not covered. - For details, please review the product’s End User License Agreement (EULA).

Q10-6 Is personal information or transaction data collected?

No. We do not collect or transmit your private keys, recovery phrase, or transaction data. This product is designed to operate offline and does not communicate with our servers.

Q10-7 Can I install unofficial firmware?

No. During a firmware update, Openloop performs signature verification (RSA-3072 + SHA-256) and rejects any firmware without a valid official signature (including unofficial or tampered firmware). This prevents attacks such as malicious firmware attempting to steal your private keys. As a result, only official firmware (via Openloop Connect) can be applied — unofficial firmware simply cannot be installed in the first place.

Q10-8 Is support available in Japanese?

Yes. We provide domestic support in Japanese. There’s no need to worry about English-centric support the way there can be with overseas products.

Q10-9 Is there an SDK for developers?

Yes. We provide the Openloop Web SDK, which enables integration in proprietary modes (WebHID / LocalWebSocket / WalletConnect). For details, please refer to the developer documentation.

Still need help? Please contact us.

Contact