Raspberry Pi projects that need real hardware-backed security now have a compact option in Zymbit's ZYMKEY 5, a mini-HAT security module that functions as a TPM equivalent for the Pi ecosystem. The module measures just 3.9 x 1.4 x 0.53 cm (1.5 x 0.55 x 0.21 inches), connects to the first ten pins of a Raspberry Pi GPIO header, and communicates over an encrypted I2C interface using ephemeral elliptic-curve keys. It supports the Raspberry Pi Zero, Pi 4 and 5, and Compute Module 4 and 5 platforms.
The headline upgrade over the previous ZYMKEY 4 is key storage capacity. Where the older module held just three private/public key pairs and three external public keys, the ZYMKEY 5 expands that to 512 private/public pairs and 128 external public keys, for a total of 640 slots. It supports secp256k1, Ed25519, X25519, ECDH, ECDSA, and AES-256, along with a hardware true random number generator. BIP32, BIP39, BIP44, and SLIP39 support also makes it relevant for cryptographic wallet applications.
On the Linux side, the ZYMKEY 5 integrates with dm-crypt and LUKS for root filesystem encryption, provides OpenSSL integration, and offers Python, C, and C++ APIs for building security functions into applications. Device recognition runs through zkifc, Zymbit's driver package, which added native ZYMKEY5 support in February 2026 alongside support for Debian 13 (Trixie), per the Zymbit documentation and its community forum. It also supports Zymbit Bootware and TLS client authentication for cloud services like AWS IoT, targeting unattended IoT deployments, industrial equipment, and edge devices that need to protect credentials and stored data. Bootware itself is mid-transition: a 2.0.0 beta adds Zymkey support on Pi 5 running Raspberry Pi OS Bookworm (64-bit) or Ubuntu 24.04.3 LTS Noble (64-bit), while the stable release remains 1.3.2 and Trixie, Bullseye, and Ubuntu Jammy aren't yet fully supported under the beta.
Physical security gets attention too. The module includes two independent perimeter-detection circuits that can monitor external tamper switches or conductive enclosures, with configurable responses ranging from notifications to cryptographic key destruction. A battery-backed real-time clock with 5ppm accuracy maintains RTC and tamper-detection functions even when the Pi is powered off. Compared to the ZYMKEY 4, the updated design swaps the micro-USB perimeter connector for a 12-pin JST connector and moves the RTC battery to an external two-pin JST receptacle, though the accelerometer has been removed.
The ZYMKEY 5 Developer Kit is listed at $79 (€73) and includes pre-release hardware, an I/O and perimeter breakout board with cable, and a battery. Production pricing drops to $49 (€45) per module in 20-packs and $42 (€39) per module in 200-packs.



