Deone Vault

Deone's Vault and Physical Key, Explained

A cold storage product accessed only through a dedicated NFC hardware device. No app-only access, no cloud recovery. Here's the full spec sheet, what happens when you lose a device, and what this setup doesn't protect against.

Back to the Deone overview

Independent overview. Not affiliated with WeFi or Deone.

Deone Vault cold storage accessed through a dedicated NFC Physical Key hardware device
This website is an independent informational resource. For official information, please visit: wefi.co

What It Is

A custody product, separate from the card

The Vault is Deone's self-custody cold storage product. It has nothing to do with the tokenized payment card. Access runs through a separate piece of hardware called the Physical Key, an NFC card-shaped device that pairs with the Deone App. Deone's materials state that neither Deone nor any third party can access what's stored inside without the Physical Key present. This is built to hold assets long-term, not to process everyday transactions.

  • Available from Prestige tier: one Physical Key included

  • Executive tier ships two Physical Keys, meant as an independent backup you can store in a different location

  • Setup takes a few minutes: tap the Physical Key to your phone once to activate

  • The device resets after 3 incorrect PIN attempts; your recovery phrase is the only way back in after that

Technical Specifications

The full spec sheet

This is the complete technical table from Deone's product materials. Two entries are worth reading closely before the rest of the page: the key standard and the certification level.

PropertySpecification
Material0.3mm treated stainless steel
ConnectivityPassive NFC, no battery required
Key generationTrue Random Number Generator (TRNG)
Key standardEIP-2333
Recovery phrase standardBIP-39 mnemonic, 24 words
PIN storageOn the device only, never in the app or on the phone
Failed PIN attempts before wipe3
Secure element certificationCC EAL6+
Additional certificationsFIDO2 Certified (Level 3), SOC 2 Type II Audited

CC EAL6+ is a higher assurance level than the CC EAL5+ certification on Deone's payment card. It rates the hardware itself, not Deone's app, backend, or account-recovery process.

Why EIP-2333, specifically

EIP-2333 (and its companion EIP-2334) is a real Ethereum standard, confirmed on Ethereum's own EIPs repository. It defines key derivation for BLS12-381 signatures, the scheme used for Ethereum validator and staking keys. Most consumer hardware wallets use BIP-32 or BIP-44 instead, which is the more common derivation path for everyday crypto storage. Deone's materials don't explain why a payment and custody product uses a staking-oriented key standard rather than the more typical BIP-32/BIP-44 path. It may be a deliberate choice tied to future staking support, or the term may simply be listed without a specific reason behind it. Either way, it's not explained publicly, and it's worth asking about directly if key-standard compatibility matters to you.

Setup & Recovery

What happens when something goes wrong

The Vault uses what Deone calls split-knowledge architecture: the app and the Physical Key both have to be present to access funds. Losing one piece doesn't automatically lock you out, but which piece you lose changes what you need to do next.

You lose your phone, but still have the Physical Key

Reinstall the Deone App on a new phone and pair it with your existing Physical Key. The Key itself holds no phone-specific data.

You lose the Physical Key, but still have your phone and recovery phrase

Deone's materials describe the 24-word BIP-39 recovery phrase as the way back into a Vault. A lost Physical Key on its own isn't an automatic lockout if you have the phrase, though Deone's public materials don't spell out the exact replacement-device process.

You enter the wrong PIN three times

The device wipes itself. Deone describes the recovery phrase as the only way to restore access after that point.

You're on Executive tier and lose one of two Physical Keys

The second Key, stored separately as Deone recommends, still works on its own. This is the specific reason Executive ships two devices instead of one.

You lose the Physical Key and the recovery phrase together

Deone's materials don't publish a recovery path for this case. Treat the recovery phrase as being at least as critical to protect as the Physical Key itself, not a secondary backup you can be casual about.

Deone Physical Key with recovery phrase card in the setup stand

The Honest Limit

What the Vault doesn't protect against

Deone's marketing draws a comparison to USB-based hardware wallets, framing factory-locked firmware as eliminating a vulnerability those devices carry. That's a real, specific advantage: a device whose firmware can't be modified after manufacturing closes off one class of attack that USB-connected devices can be exposed to through firmware updates. It is not the same as saying the Vault has no attack surface at all. The risks that remain are ordinary rather than exotic: someone gets physical possession of the device, or a backup gets mishandled somewhere along the way. Plain human error covers most of what's left. No certification or clever hardware design removes any of that.

  • Physical theft of the device and knowledge of the PIN together would compromise the Vault. The 3-attempt wipe limits guessing, not theft of a device where the PIN is already known

  • Deone doesn't document a recovery path for losing the recovery phrase and the Physical Key at the same time

  • Coercion (someone forcing you to tap the Key and enter your PIN) isn't something hardware certifications address, on this device or any other

  • The two-device setup on Executive tier only helps if the devices are actually stored apart. Keeping both Physical Keys in the same house defeats the point of having two

This is a structural read of Deone's own published materials, not an independent security audit. DeoFin has not tested the Physical Key or the Vault directly.

Frequently Asked Questions

A self-custody cold storage product, separate from Deone's payment card. It's accessed through a dedicated NFC hardware device called the Physical Key rather than through the app alone.
One with Prestige tier, two with Executive tier. Deone recommends storing the second Executive device in a different physical location as an independent backup.
It's a real Ethereum standard for deriving BLS12-381 keys, most commonly used for validator and staking keys rather than everyday wallet storage. Most consumer hardware wallets use BIP-32/BIP-44 instead. Deone's materials don't explain the choice, so treat it as an open question rather than a settled technical detail.
No. It's a higher rating than the EAL5+ on Deone's card, and it rates the secure element hardware specifically. It doesn't cover Deone's app, backend, or account-recovery process.
Deone describes your 24-word BIP-39 recovery phrase as the way back in. Deone's public materials don't detail the exact replacement-device process, so treat the recovery phrase as critical to protect on its own.
Deone's materials claim this eliminates a firmware-update vulnerability present in USB-based hardware wallets generally, without naming specific competing products. That's a real category of risk that factory-locked firmware does close off. It doesn't mean the Vault has no attack surface. Physical theft and mishandled backups stay risks no matter how the firmware is designed, and so does plain human error.
The Vault's secure element is certified to CC EAL6+, one level above the card's CC EAL5+. The Vault also carries FIDO2 (Level 3) and SOC 2 Type II certifications that the card's materials don't cite.

See the full Deone breakdown

Membership tiers, legal structure, the tokenized card, and Cloud Mining: the complete picture on the Deone hub page.

Back to Deone overview

Independent overview. Not affiliated with WeFi or Deone.

Last updated

July 2026

DeoFin is an independent informational resource. Not affiliated with WeFi Technologies Ltd. or Deone. Nothing on this site constitutes financial or security advice. Product and technical details sourced from Deone's public materials and Ethereum's public EIP repository, and may change without notice — verify through official channels before making decisions.