Our assessment at a glance
Trezor effectively created the hardware-wallet category in 2014 and has maintained an entirely open-source firmware and app approach ever since. With the Safe 3, Safe 5 and Safe 7, that transparency is now paired with a certified EAL6+ Secure Element on every current model, addressing the biggest hardware criticism competitors previously raised. The August 2026 breach at a fulfilment partner remains an important recent negative, although Trezor says neither wallets nor devices were compromised.
What works particularly well
- Fully open-source firmware and companion app, independently reviewable on GitHub — the longest track record of any wallet on this site.
- Every current model (Safe 3, Safe 5, Safe 7) ships with a certified EAL6+ Secure Element, not just the flagship.
- Entry price of $59 (Safe 3) undercuts most certified-secure-element competitors, including OneKey's cheapest model.
- Shamir/Multi-share Backup support lets you split a recovery seed across multiple physical shares instead of one single point of failure.
- Over a decade of public, adversarial security research — including third-party lab attacks that led to real hardening — rather than a young, unproven design.
- Safe 7 adds a touchscreen, Bluetooth and wireless charging for buyers who want the convenience tier without leaving the Trezor lineup.
What to factor into your decision
- In August 2026, Trezor disclosed that its fulfilment partner ShipMonk was breached, exposing 80,689 customers' names, shipping addresses, emails and phone numbers.
- No Bluetooth or NFC on Safe 3/Safe 5 — Safe 7 is the only model with wireless connectivity, at a $249 starting price.
- Historically, older Trezor models lacked a certified secure element, which is why some reviewers still describe Trezor as "catching up" on this specific point even though current hardware has closed it.
- A 2020 lab attack (voltage glitching) demonstrated physical seed extraction from earlier Trezor hardware; mitigated since with passphrase support, but a reminder that physical possession is a real threat model.
- Trezor Suite's full functionality still leans on a desktop or Android connection; iOS support has historically lagged behind Ledger's and OneKey's mobile apps.
- As with any brand this size, Trezor has had more than one support-data-adjacent phishing wave aimed at its user base — this is the second one we're aware of, after an earlier one in 2020/2021.
