There are several open-source HSMs on the market.
Nitrokey
Nitrokey (formerly known as CryptoStick) sells the open-source NetHSM
The CryptoStick has been used by Mozilla since 2013.
Kryptor FPGA
Skudo OÜ sells an open-source HSM on an FPGA board
SmartCard-HSM
The SmartCard-HSM project claims to have "open source crypto middleware" but is probably not 100% open-source hardware
CrypTech Alpha
There was an open-source HSM launched in 2016 on CrowdSupply called the CrypTech Alpha, but it appears to no longer be available
Resources
- Ryan Lackey gave a talk Genuinely "Trusted Computing:" Free and Open Hardware Security Modules at ShmooCon 2014